Cookie Notice
Last updated: October 7, 2026
This notice lists the cookies and browser storage Kivvie sets on kivvie.app, what each one is for, and how long it lasts. It also covers the third-party cookies that YouTube sets when a video plays, which we do not control. It sits alongside our Privacy Policy and Terms of Service.
The short version:
We use cookies to keep you signed in, to see how the site is used, and to measure Meta ads on public pages. We do not use cookies to build profiles of children. Signed-in parent product pages do not load Meta Pixel.
1. Cookies We Use
1.1 Strictly Necessary: Sign-In
These keep you signed in and keep your session secure. Kivvie cannot work without them, so they are set whenever you sign in and are not optional.
| Cookie | Purpose | Set by |
|---|---|---|
next-auth.session-token__Secure-next-auth.session-token | Holds your signed-in session so you do not have to log in on every page. The __Secure- version is used over HTTPS. | Kivvie (first party) |
next-auth.csrf-token | Protects sign-in and sign-out requests against cross-site request forgery. | Kivvie (first party) |
next-auth.callback-url | Remembers which page to return you to after Google sign-in completes. | Kivvie (first party) |
Signing in also involves Google, because Kivvie uses Google OAuth. Google may set its own cookies on Google's domains during that step. That is covered by the Google Privacy Policy, not by this notice.
1.2 Analytics: PostHog
We use PostHog to understand how the website is used, so we can fix problems and improve the product. Analytics loads on the live kivvie.app site only. It is switched off in the internal builds we use for development and testing, where no analytics cookie is set at all.
| Cookie | Purpose | Lifetime |
|---|---|---|
ph_<project key>_posthog | Stores a visitor identifier and session identifier so repeat visits are not double counted. Before you sign in this is a random value. Once you sign in, it is set to your Kivvie parent profile identifier, so we can recognise a returning parent and connect an error report to an account we can help. It never contains your name, your email address, or any child's details. | 12 months |
PostHog also keeps related values in your browser's local storage, such as the active feature flags for your session. Clearing site data removes both the cookie and the local storage entries.
Session replay in PostHog:
Where analytics is active, PostHog session replay records how website pages look and how visitors move through them (page layout, scrolling, mouse movement, and clicks) so we can find broken or confusing parts of the website. It keeps its state in the same PostHog cookie and local storage described above.
- Form inputs are always masked - the characters you type are replaced before the recording leaves your browser
- Page content is blocked on app pages, meaning the dashboard, onboarding, watch, sign-in, support, and email-preference pages. Text, images, video, and other elements on those pages are not captured
- Admin pages are never recorded
- Network request headers and bodies are not recorded
- Console logs and canvas content are not recorded
- Recordings are linked to the same visitor identifier as the PostHog cookie above, which becomes your parent profile identifier after you sign in
- We can switch session replay off, or record only a sample of visits, through the build configuration of our website
What we switch off in PostHog:
- Autocapture is disabled - we do not silently log every click and form interaction
- Rage-click tracking is disabled
- Surveys are disabled
- Web performance autocapture is disabled
- Profiles are created for signed-in users only, not for anonymous visitors
Every analytics event passes through a redaction filter before it leaves your browser. That filter is built on a deny-list: it drops properties whose names match known sensitive patterns, including passwords, access and refresh tokens, API keys, payment card fields, child PINs, search text, and identifiers for child profiles, channels, and videos. It also scans text values for email addresses and token-like strings and replaces them, and strips query strings from web addresses on sign-in, checkout, and callback pages. Because the filter matches on known patterns rather than inspecting every possible value, we treat it as a safety net that backs up our main rule, which is not to attach sensitive data to analytics events in the first place. Session replay recordings rely on the masking described above rather than on this filter.
1.3 Marketing: Meta Pixel
On public marketing pages (homepage, pricing, blog, features, login, and similar), we load Meta Pixel so we can measure ads aimed at parents. It only records a PageView. We do not send Advanced Matching fields. We never send child names, ages, PINs, profile IDs, channels, playlists, or watch history to Meta. It does not load on signed-in dashboard, onboarding, admin, or watch pages. Meta may set cookies on Meta domains; those are controlled by Meta, not by Kivvie, and are covered by the Meta Privacy Policy.
| Cookie | Purpose | Lifetime |
|---|---|---|
_fbp | A browser id Meta uses to recognise repeat visits to our public pages. | Up to 3 months |
_fbc | Set when you arrive from a Meta ad click, so Meta can attribute a later visit to that ad. | Up to 3 months |
Blocking these cookies does not affect any Kivvie feature. The child app never loads Meta Pixel, and no child information is sent to Meta.
1.4 Video Playback: YouTube
Kivvie plays videos through YouTube's player. When a video loads, YouTube may set its own cookies on YouTube domains to support playback. These are third-party cookies controlled by Google, not by Kivvie, and are governed by the Google Privacy Policy and the YouTube Terms of Service.
2. What We Do Not Use
- No ads inside the product - Kivvie shows no advertisements in the app or parent dashboard
- No marketing pixels on signed-in product pages - Meta Pixel loads only on public marketing pages, not on dashboard, onboarding, admin, or watch
- No data-broker trackers - we do not sell browsing data to data brokers
- No cookie-based profiling of children - children use the mobile app, which does not use website cookies to build behavioural profiles
3. How to Control Cookies
You can clear or block cookies at any time in your browser settings. Every major browser lets you delete existing cookies, block new ones, or block third-party cookies only.
Two things worth knowing before you do:
- Blocking the sign-in cookies listed in section 1.1 will sign you out and prevent you from signing back in. Kivvie cannot keep you logged in without them.
- Blocking analytics or Meta Pixel cookies does not affect any Kivvie feature. Everything keeps working.
Most browsers also offer a private or incognito window, which discards all cookies when you close it.
4. Changes to This Notice
If we add, remove, or change a cookie, we will update this page and the "Last updated" date above.
5. Contact Us
Questions about cookies or anything else in this notice? Email us at admin@kivvie.app. Kivvie is operated by M2V2 Solutions Pty Ltd, Australia.
