Cookie Policy
Last updated: May 25, 2026
Contents
1. What cookies are
A “cookie” is a small text file that a website places on your device when you visit it. Cookies let the site remember information about your visit — your sign-in state, your preferences, which page you came from — across page loads and return visits. We also use “local storage” and “session storage,” which are similar browser APIs that hold data on your device. For shorthand we’ll call all of these “cookies” in this policy.
We use cookies on hardiktrehan.com and on the HT Hub sub-site. This policy explains what we set, why, and how to turn it off. It supplements our Privacy Policy.
2. Categories we use
- Essential — required for the Site to work (sign-in, security).
- Functional — remember your preferences and game state.
- Analytics — aggregate usage measurement (Google Analytics 4).
- Payment / fraud — set by Stripe on the checkout flow.
- Third-party embeds — set by YouTube / Spotify / etc. when those players load on a page.
We do not use third-party advertising cookies on the website. (Our mobile apps are a separate story — see section 8.)
3. Essential cookies
These keep you signed in, remember which Firebase Auth session is active, and protect against cross-site request forgery. Without them, things like the HT Hub leaderboard, the AI tools, and the billing pages cannot function for signed-in users. Common names: Firebase ID-token cookies, __Host-flowState-style short-lived cookies issued by Firebase Auth. These are first-party, HTTP-only where the API allows it, and expire when you sign out or when the token does.
Because they are necessary to provide the service you asked for, we don’t ask consent for these under GDPR — they are exempted from consent under the ePrivacy Directive’s “strictly necessary” carve-out.
4. Functional cookies & local storage
We store the following in your browser’s local storage so the Site works smoothly across reloads:
- Game progress and scores for offline / unsigned play.
- Your AI Battle Arena history cache.
- UI preferences (sound on/off, last-used model, leaderboard visibility toggle).
- Astrology birth-data — only stored locally unless you opt to save a reading.
- Service-worker version info for the progressive-web-app shell.
These live on your device and are not sent to our servers unless you sign in and explicitly opt into a cloud feature (e.g. public leaderboard). Clear them anytime with your browser’s “Clear site data” option.
5. Analytics (Google Analytics 4)
We use Google Analytics 4 (the _ga and _ga_* cookies) to measure aggregate traffic, pinpoint broken pages, and understand which features are actually used. GA4 collects pseudonymized identifiers, IP address (truncated for EU visitors), browser type, page paths, referrers, approximate location, and event counts. We do not use GA4 for cross-site advertising or remarketing.
You can opt out site-wide by installing the Google Analytics opt-out browser add-on or by blocking analytics cookies in your browser. We honor the Global Privacy Control (GPC) signal as a request not to share data — which is moot for us because we don’t sell or share data with advertisers in the first place.
6. Payment / fraud-prevention cookies (Stripe)
When you initiate a checkout for a subscription or credit pack, Stripe sets its own cookies (such as __stripe_mid and __stripe_sid) on the checkout page to detect fraud and remember your session. We do not control these cookies; see Stripe’s Cookies Policy for details.
7. Third-party cookies set by embeds
Some pages embed third-party players (YouTube videos, Spotify tracks, etc.). When those embeds load, the third party may set its own cookies on your device. We use the privacy-extended versions of embeds where the provider offers them (e.g. youtube-nocookie.com for YouTube), which delay tracking until you actually interact with the player.
8. Mobile apps
Our mobile apps (e.g. Stage Rush on Google Play) do not use browser cookies but do use the Google Mobile Ads SDK, which sets advertising identifiers on your device. See section 1h of the Privacy Policy and Google’s advertising policies. You can reset your advertising ID in your device’s privacy settings.
9. How to control cookies
- Block or delete all cookies in your browser settings — but the Site won’t work signed-in if you block essentials.
- Use private / incognito mode, which clears cookies when the window closes.
- Install a tracker-blocking extension (uBlock Origin, Privacy Badger). We don’t set any trackers beyond GA4, but extensions add a layer of defense for third-party embeds.
- Opt out of GA4 specifically with the Google Analytics opt-out add-on.
- Clear local storage from your browser’s “Clear site data” option to reset game progress, history, and preferences.
10. Updates to this policy
We may update this policy when we add or remove cookies. The “Last updated” date above reflects the most recent change. Material changes will be summarized at the top of the page for at least 30 days.
11. Contact
Questions about cookies? Email legal@hardiktrehan.com.

















