1. What cookies and local storage are
A cookie is a small value stored by the browser and returned to the website on later requests. Local storage is browser-held data that scripts can read for the same site. CRYA distinguishes storage required to deliver a requested, secure service from optional storage used for analytics or personalisation.
3. Why essential storage does not use an optional-consent banner
These cookies are requested or strictly necessary for secure authentication, anti-forgery protection, session continuity, and a deliberately requested owner maintenance path. CRYA does not use an “accept all” design for cookies that are not optional in the first place.
Optional analytics is blocked until the visitor makes a choice. ‘Allow analytics’ and ‘Essential only’ are presented together, and the footer Privacy choices control allows that decision to be revisited. A browser Do Not Track or Global Privacy Control signal is treated as a denial by the CRYA tracker.
4. Local and session storage
The website does not rely on browser localStorage or sessionStorage for account tokens, support cases, purchase entitlements, or group controls. Those records remain in the secure CRYA service and its protected cookies.
When you are signed in, My CRYA may keep a best-effort local mirror named crya:account-preferences for non-sensitive presentation choices: theme, motion, density, language preference, optional sound, and product discovery. It contains no token, account profile, service request, or private control data. The CRYA API remains the authority: My CRYA reloads and saves the account-backed preference through the protected service, and continues to work if browser storage is unavailable. The mirror lasts until you clear site data or replace it with a later preference.
5. Analytics and external destinations
CRYA first-party analytics stores one anonymous row per consented page view: time, calendar day, path without query data, broad device class, broad language category, and broad referral category. It does not persist an analytics cookie ID, account ID, IP address, full referrer, query string, or raw user agent. Rows are aggregated in CRYA Studio and automatically expire after the configured 30-to-365-day retention period.
If a valid Google Analytics 4 Measurement ID and the Google switch are both enabled in CRYA Studio, the Google tag loads only after consent. CRYA disables advertising storage, advertising user data, advertising personalisation, and Google signals in its configuration. Google processes the resulting measurement under Google’s own terms and privacy information.
Opening Telegram, Google sign-in, Google Play, or another external destination moves you into that provider’s service. The provider may set its own cookies or device storage under its notice. CRYA does not describe those third-party cookies as if CRYA controls them.
6. Your controls
You can inspect or delete cookies and local storage in your browser settings. Signing out clears the CRYA session cookie. Clearing a temporary login cookie can require you to restart that sign-in; clearing crya:account-preferences only resets its local presentation mirror. Blocking all cookies can stop secure account features from working.
Use Privacy choices in the footer to allow or refuse analytics at any time. Refusal stops CRYA page measurements and prevents the Google tag from loading. Clearing the preference cookie causes the choice to be requested again. A new notice version also requests a fresh choice.
7. Changes and questions
This policy is updated when storage names, purposes, providers, or durations change. For a question about a cookie or unexpected storage, contact CRYA and include the browser, page, cookie name, and observation time without copying the protected cookie value.

