Cookie policy
Last updated: October 8, 2026
Corally only uses technical cookies and storage to keep the website working or remember your choices. First-party metrics store nothing on your device and do not use the anonymous quota cookie. We add no analytics or advertising cookies, so we do not show a cookie banner for this measurement.
Cookies
- corally_session: keeps you signed in. Expires after 60 days or when you sign out.
- corally_anon: an anonymous identifier to count the route allowance without an account (daily and last 7 days) and prevent abuse. Lasts one year.
- NEXT_LOCALE: the language you last used. Lasts one year.
- While signing in with Google, a temporary 10-minute cookie protects the process.
Browser storage
We keep preferences in your browser (localStorage) that never leave your device: light or dark theme, map background and layers, and the tips and guided tour you have already seen.
The app uses no cookies: your session, chosen language and the phone's notification identifier are kept in the phone's secure storage (iOS Keychain or Android Keystore) and never leave it. They are deleted when you sign out or uninstall the app.
Metrics without device storage
We measure pages, actions, visit origin, approximate country, region and city, language, device and whether it looks like a bot in our own database, without third parties. These metrics do not store your IP. Anonymous visitors are distinguished only within a day using a hash and a salt deleted at the UTC day boundary; account activity is linked to the user.
We do not install cookies, localStorage or sessionStorage for measurement or use corally_anon. The purpose is to improve Corally and the basis is legitimate interest. Retention: the configured retention period (contact the controller). The privacy policy explains the data and your rights.
Third parties
The map is loaded from OpenFreeMap, Spain's National Geographic Institute and Mapterhorn; we do not set cookies for them. If you sign in with Google, Google applies its own cookies on its own page.
How to delete them
You can delete cookies and storage in your browser settings. If you delete corally_session you will need to sign in again.
Provider sign-in
Signing in with Apple uses a temporary technical cookie to check that the response belongs to your sign-in attempt. It expires when the attempt completes or after the configured timeout (10 minutes by default).