Cookie and Tracker Policy
Last updated: 26/05/2026
Version: 1.0
1. Introduction
This policy is established in accordance with Article 82 of the French Act No. 78-17 of 6 January 1978 (Data Protection Act) and the guidelines of the French data protection authority (CNIL) on cookies and similar trackers.
Since the HollyFriends mobile application is not a website, the term "cookies" is used here, by extension, to refer to all trackers that may be placed or read on the User's device (secure local storage, technical identifiers, authentication tokens).
2. Trackers Used by the Application
2.1 Strictly Necessary Trackers (Exempt from Consent)
In accordance with Article 82 of the French Data Protection Act and CNIL doctrine, trackers whose sole purpose is to enable or facilitate electronic communication, or that are strictly necessary for the provision of a service explicitly requested by the User, are exempt from consent.
The Application uses only the following trackers, all strictly necessary:
| Tracker | Purpose | Issuer | Duration |
|---|---|---|---|
| Supabase session token | Maintaining authentication | Supabase | Session duration + refresh token (up to 1 year if autoRefresh active) |
| Secure storage (Expo SecureStore / iOS Keychain / Android Keystore) | Secure storage of authentication token | Application | Until logout or deletion |
| Local preferences (AsyncStorage / Web localStorage) | Storing non-sensitive UI preferences | Application | Until manually deleted |
No consent banner is required for these trackers.
2.2 Advertising, Third-Party Analytics or Non-Exempt Audience Measurement Trackers
The Application does not use any trackers of this type.
Specifically, the Application does not contain:
- any third-party behavioural analytics tools (Google Analytics, Mixpanel, Amplitude, etc.);
- any advertising SDKs (Meta Audience Network, AdMob, etc.);
- any marketing pixels or tags;
- any advertising or profiling cookies.
3. Device Advertising Identifiers
The Application does not read or transmit the device's advertising identifier (IDFA on iOS, AAID on Android). Accordingly, no App Tracking Transparency (ATT) prompt is displayed on iOS.
4. Push Notifications
Push notifications rely on a device token issued by Apple Push Notification Service (APNs, iOS) or Google Firebase Cloud Messaging (FCM, Android). This token is not a cookie within the meaning of Article 82 of the French Data Protection Act, but constitutes personal data whose processing is governed by the Privacy Policy.
Enabling notifications is subject to the User's explicit consent via the system dialogue box and can be revoked at any time in the device or Application settings (Profile screen → Notifications).
5. Future Changes
Should the Application ever integrate trackers requiring consent (analytics, marketing, attribution), Gerlando Zicari will implement:
- a consent banner complying with CNIL requirements;
- granular choice on a purpose-by-purpose basis;
- equivalence between consent and refusal (one click to accept, one click to refuse);
- a consent register that can be invoked.
This policy would then be updated accordingly and submitted for new acceptance.
6. Contact
For any questions relating to this policy: legal@hollyfriends.com