Cookie Policy
This is an interim cookie notice for the Textycally website at textycally.com. The list below is the complete set of cookies this site sets, read directly from the code that sets them. Textycally is operated by Black Leaf Digital LLC. Questions go to support@textycally.com.
Five cookies. All five are strictly necessary: they either keep you signed in, let you resume signing up, or remember the cookie choice you already made. None of them track you, and none of them are used for advertising.
Cookies this site sets
zw_access
- What it does. Holds your platform access token so the site knows you are signed in.
- Set by. Our server, when you log in.
- How long. As long as your sign-in session lasts. It is set to expire together with your refresh window.
- Flags. HttpOnly, SameSite=Lax, path
/, and Secure in production, so it is never readable by page scripts and is never sent to another site.
zw_refresh
- What it does. Holds the refresh token that renews your access without asking for your password again.
- Set by. Our server, when you log in.
- How long. As long as your sign-in session lasts.
- Flags. HttpOnly, SameSite=Lax, path
/, Secure in production.
zw_onboarding
- What it does. Records how far through the signup wizard you have got, so you can close the tab and pick up where you left off.
- Set by. Our server, as you move through onboarding.
- How long. 30 days.
- Flags. HttpOnly, SameSite=Lax, path
/, Secure in production.
zw_dev
- What it does. Stands in for a sign-in session while a developer runs the site locally with no backend attached.
- Set by. Our server, and only when the developer-auth switch is turned on. That switch is off on textycally.com, so this cookie is never set on the live site.
- How long. 30 days.
- Flags. HttpOnly, SameSite=Lax, path
/, Secure in production.
zw_texting_consent
- What it does. Records the choice you made on the cookie banner, together with the version of the notice you were shown, so we do not ask you again and so we can tell what you agreed to.
- Set by. The banner itself, in your browser. This is the one cookie here that is written by page script rather than by our server, so unlike the other four it is readable by script on this site.
- How long. 365 days.
- Flags. SameSite=Lax, path
/, and Secure whenever the page is served over HTTPS.
What this site does not use
- No analytics cookies. No advertising cookies. No cross-site tracking cookies.
- No third-party trackers of any kind: no Google Analytics, no Meta pixel, no heatmap or session-replay tool.
- Nothing is written to your browser’s local storage or session storage.
The payment step
On the credits step of onboarding, and only after you choose a credit pack, we load an embedded Stripe payment component so you can pay without your card details ever reaching us. Stripe may set its own cookies at that point for fraud prevention, under Stripe’s own policy. That component is not present on any other page of this site.
Your choices
You can reject non-essential cookies from the banner. You can also clear or block cookies in your browser at any time. Because every cookie listed above is strictly necessary, blocking them does not stop tracking, since there is no tracking to stop. It will instead sign you out, lose your place in the signup wizard, or make the cookie banner ask you again.
Status of this document
This is an interim notice. It describes the site as it is actually built today, and it is published so that the consent banner links to a real disclosure instead of a missing page. A counsel-reviewed cookie policy will replace it. The version string shown beneath the title is the sha256 of this document exactly as published.