Effective: 13 August 2026
Last updated: 13 August 2026
Operator: David Jameson trading as DeskJockey Digital
Address: Office 15396, 182–184 High Street North, East Ham, London, E6 2JA
Contact: hello@deskjockeydigital.co.uk
Governing law: England & Wales
This Cookie Policy explains how Oriva uses cookies and similar technologies (such as local storage) on oriva.dev, and the equivalent on-device storage used by the Oriva iOS and Android apps. It should be read alongside our Privacy Policy.
In the native iOS and Android apps, Oriva does not set browser cookies. The same categories of state described below (auth session, guest world, preferences, consent) are held instead in the app's own sandboxed storage on your device, are only accessed by Oriva, and are removed when you delete the app, sign out, or delete your account.
1. What are cookies?
Cookies are small text files that websites place on your device to remember information about you. "Similar technologies" include local storage and session storage, which serve comparable purposes. In this policy, "cookies" refers to all of these.
2. Categories of storage we use
Essential
Required for Oriva to function. These keep you signed in, hold guest world data until you create an account, and remember one-off interface state such as the splash screen and soft-wall dialog. The Service cannot operate without them and they do not require your consent.
Functional
Remember small comforts, such as whether you’ve seen the “add to home screen” prompt or the one-time share intro. Optional.
Analytics
Product analytics and error monitoring through PostHog, using its EU-hosted endpoint. PostHog is not initialised and captures nothing at all until you turn Analytics on. Once it is on, PostHog records the named product events we send deliberately, in-app page views, its configured autocapture interaction signals (such as clicks on elements and the page they happened on), and error/exception reports. It sets its own first-party storage (for example a ph_* distinct-id entry) and, when you are signed in, links events to your Oriva user ID and email address. Session recording (session replay) is off, and IP data is discarded by our PostHog project configuration rather than retained against your events. If you turn Analytics off again, capture stops and the PostHog identity is reset. Optional.
Marketing
Covers two things. First, optional first-touch attribution for referral links: if a friend shares Oriva with you using a personal link, we remember that on your device for 90 days so we can credit them if you later create an account. Second, your marketing email choice, which controls whether we subscribe you in Loops and add you to our “Oriva Users” mailing list. We do not use advertising or cross-site tracking cookies.
3. Specific technologies currently in use
- Authentication session (localStorage, key
sb-*-auth-token) — keeps you signed in and refreshes your session. Essential. - Guest world data (localStorage,
oriva.guestWorld.v2) — stores the countries and memories you add before creating an account, so nothing is lost when you sign up. Essential. - Splash shown flag (sessionStorage,
oriva.splash.shown) — suppresses the intro splash for the rest of the tab session. Essential. - Soft-wall dialog state (sessionStorage,
oriva-softwall-title) — remembers which sign-up prompt to show. Essential. - Sidebar layout (cookie,
sidebar_state, 7 days) — remembers whether the navigation sidebar is expanded. Essential. - Install-prompt engagement (localStorage,
oriva.install.*) — tracks in-app activity so we only invite you to install Oriva once you’re getting value from it, and respects a dismissal for 30 days. Functional. - Share intro seen (localStorage,
oriva.shareIntroSeen) — hides the one-time share explainer after you’ve seen it. Functional. - PostHog analytics storage (first-party localStorage/cookie,
ph_*) — set by PostHog only after Analytics consent, to associate events from the same browser. Analytics. - Referral attribution (localStorage,
oriva_growth_ref,oriva_growth_share,oriva_growth_ts, 90 days) — first-touch attribution for personal share links. Marketing. - Consent choice (localStorage,
oriva.consent.v1) — remembers your cookie preferences on this device, and your marketing choice is also stored on your account once you sign in. Essential.
4. Third-party technologies
- Lovable Cloud (Supabase) — the Supabase client library sets the authentication token described above in localStorage. No third-party cookies are set on your device by Supabase.
- PostHog — product analytics and error monitoring via
eu.i.posthog.com. Consent-gated; not loaded at all without Analytics consent. - Loops — our marketing and lifecycle email provider. Loops does not run any script or set any storage in the app; it receives contact and event data from our servers.
- Photon (Komoot) — receives your place-search text server-side to return search results. No client-side storage.
- OpenFreeMap vector tiles — the World map view requests vector base-map tiles from
tiles.openfreemap.orgas you pan and zoom. Tile requests include your IP address and the tile coordinates being requested. The tile server does not set cookies and does not identify you as an Oriva user. - jsDelivr — public CDN that serves world-atlas map geometry files used to draw the map. Requests include your IP address.
- Google Fonts & Google Identity — we load the Inter and Instrument Serif web fonts from
fonts.googleapis.com/fonts.gstatic.com. If you choose to sign in with Google, Google’s Identity Services script is loaded on demand to complete the OAuth flow. Neither font requests nor the on-demand Google Identity script set Oriva-scoped cookies; Google may set its own cookies under its own privacy notice. - Outbound social links — clicking our Instagram or TikTok footer links takes you to those platforms, which set their own cookies under their own policies.
Oriva does not use advertising networks, cross-site trackers, session-replay, fingerprinting, or data brokers, and the iOS app contains no advertising identifier or App Tracking Transparency implementation. If we introduce any of these, we will list them here and load them only after you have granted the appropriate consent.
The embedded live preview on our landing page loads Oriva inside a phone-shaped iframe. Inside that frame the cookie banner is intentionally suppressed — the banner belongs to the outer marketing site, not the demo — and no consent is inferred from anything you do inside the preview.
5. Your choices
You can accept all, reject non-essential, or manage each category individually from the cookie banner shown on first visit, or at any time from your browser via the “Manage cookie preferences” option. You can also clear all Oriva storage through your browser settings; note that blocking essential items will sign you out and prevent Oriva from working.
6. Changes
We may update this Cookie Policy as the product evolves. When we add a new technology, we will list it above and, where required, request your consent before it loads. We will update the “Effective” date at the top of this page.
7. Manage your preferences
to review or change your choices at any time.
8. Contact
Questions can be sent to hello@deskjockeydigital.co.uk.