Cookie Policy

Operated by Aratian Limited. Last updated: August 26, 2026

This Cookie Policy explains how Aratian Limited ("Company," "we," "us," or "our") uses cookies and similar tracking technologies on the angels.space website located at https://angels.space (the "Website"). This Policy should be read alongside our Privacy Notice, which provides additional detail on how we collect and use your personal information.

1. What Are Cookies

Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. Cookies are widely used to make websites function properly and more efficiently, improve user experience, and provide information to website operators. Cookies may be set by the website you are visiting ("first-party cookies") or by third parties whose services the website uses ("third-party cookies"). Cookies may persist on your device for different durations: "session cookies" are deleted when you close your browser, while "persistent cookies" remain on your device until they expire or you delete them.

This Policy also covers similar technologies that store information on your device without being cookies, in particular browser local storage and session storage. Where an item listed below is not a cookie, we say which technology it uses.

2. Cookies We Use

What we store on your device falls into the four groups set out below: the items the Website cannot be served without, the items that measure how it is used, the items that remember your preferences, and the copies our service worker keeps so that pages load quickly.

2.1 Strictly necessary

These cookies are essential for the Website to function and cannot be disabled in our systems. They are typically set in response to actions you take that amount to a request for services, such as setting your privacy preferences, logging in, or completing forms. Without these cookies, some parts of the Website may not function properly.

The sign-in cookie identifies your account, and the closed-beta access cookie contains the email address your invitation was sent to. The others in this group do not identify you.

NameTypeSet byHow long it lastsWhen it is setWhat it does
ag_okCookieUs30 daysBefore you confirm your ageRecords that you confirmed you are 18 or over. Until it exists, every page is replaced by the age gate. It is also what keeps session recording off until you have confirmed.
consent_regionCookieUsBrowser session (deleted when you close the browser)Before you confirm your ageRecords that European privacy rules apply to you. Its only value is the literal text 'eu'. It holds no identifier and nothing that distinguishes you from any other visitor in scope.
legal_regimeCookieUsBrowser session when our servers set it; 365 days once you sign in to an account that accepted a specific set of TermsBefore you confirm your ageRecords which set of legal documents applies to you: 'us' for visitors in the United States, 'eu' for everyone else. It holds no identifier.
eu_consentCookieUs180 days for both answersBefore the privacy choiceThe choice you made about analytics. Written only by your own click, never by us in the background. A refusal is remembered exactly as long as an acceptance, so declining does not mean being asked again on every visit.
sb-<project-ref>-auth-tokenCookieSupabase400 days (our sign-in library's default; we pass no cookie options)Before the privacy choiceKeeps you signed in. Holds the access token, the refresh token, the expiry and your user record. Split across numbered cookies when it is too large for one.
sb-<project-ref>-auth-token-code-verifierCookieSupabaseSingle use, deleted as soon as sign-in completesBefore the privacy choiceThe one-time secret that finishes a Google or email sign-in securely.
angels_oauth_stateCookieUs10 minutes, single useBefore the privacy choiceStops someone else starting a Google sign-in on your behalf. Cleared the moment it has been checked.
beta_okCookieUs7 daysBefore you confirm your ageClosed-beta access. Only ever set while the beta wall is switched on, which it is not in any live environment. It contains your email address inside a signed value, so we list it rather than describe this set as holding no personal data.
__cf_bmCookieCloudflareSet by Cloudflare, typically around 30 minutesBefore you confirm your ageBot detection at our network edge. Applied by Cloudflare to traffic on our domains, including our API, not written by our own code.
cf_clearanceCookieCloudflareSet by CloudflareBefore you confirm your ageRecords that a Cloudflare security challenge was passed, so you are not challenged repeatedly.
beta:admit-bouncesSession storageUsBrowser tab sessionBefore you confirm your ageCounts silent beta admission attempts so a browser that refuses cookies cannot bounce between two pages forever.
angels_tokenLocal storageUsUntil you sign outBefore the privacy choiceA sign-in token from our previous authentication system. Supabase replaced it in every environment, so nothing writes it any more, but the read path still ships and we disclose it rather than assume it is gone.

2.2 Analytics and measurement

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our Website. They help us understand which pages are the most and least popular and how visitors navigate the Website.

The information collected here is not only aggregate. When you are signed in it is attached to your account, and it feeds the systems that rank and personalize what you see. Our analytics and session recording provider is PostHog, which sets its own identifiers on your device. Our Privacy Notice describes what is collected and how it is used.

If you reach us from the EU, the EEA, the UK or Switzerland, or from Andorra, Monaco, San Marino or the Vatican, we ask before we measure anything. You get a choice with two buttons, Accept and Decline, both the same size. Nothing is pre-ticked, and carrying on browsing is not an answer.

Before you press Accept for the first time, nothing in this group exists on your device and nothing about your visit is sent anywhere. That is a description of what happens rather than a promise about what we do afterwards: the measurement code is never started, no identifiers are created, our analytics provider's script is never downloaded at all, and our own servers refuse measurements that arrive without your recorded consent.

If you accept and later decline, we stop, and we delete what that measurement left on your device, in local storage and in session storage alike. One thing survives a Decline, and we would rather name it than round the sentence up: our analytics provider's own off switch, listed below as __ph_opt_in_out_. It holds no identifier and it is the thing that keeps collection off, so deleting it would let that provider's background collectors start again on the same page. It is the only thing that stays.

Session recording never runs for those visitors. Not before the choice, and not after it. Accepting analytics does not switch it on, and it cannot be switched on by a setting: that would take a new version of this page, a new choice put to you, and a separate answer from you.

We remember the answer for 180 days either way, so declining does not mean being asked again on every visit. We also keep a record that we asked: what you chose, when, which versions of these documents were in force, and a shortened form of your IP address. That record carries no advertising identifier and no device identifier.

Everywhere else, including the United States, there is no opt-in step and measurement runs from the first visit. We would rather say that plainly than imply a choice you do not have. One detail deserves stating rather than burying: it starts before you confirm you are 18. The age confirmation is the first thing you see, but our analytics provider's identifier is already set on that screen. Session recording is the exception, and it does wait for the age confirmation. Everything set at that point is listed below, in the "When it is set" column.

NameTypeSet byHow long it lastsWhen it is setWhat it does
angels_analytics_anon_idLocal storageUsNo expiry (removed if you withdraw)Only once you acceptA random id for this browser. It lets us count a returning visitor as one person rather than several, and if you later create an account we connect that earlier activity to it. It is also sent to our API on feed and reel requests.
angels_analytics_session_idLocal storageUsRotates after 30 minutes of inactivityOnly once you acceptGroups one sitting of activity together.
angels_analytics_session_last_atLocal storageUsOverwritten on every interactionOnly once you acceptThe time you were last active, used only to decide when the id above should roll over.
angels_analytics_retry_queueLocal storageUsPer batch, capped and expiredOnly once you acceptHolds measurements that failed to send, so a dropped connection does not lose them. Each held item carries the browser id, the session id and the event.
ph_<token>_posthogCookiePostHog365 days (vendor default)Only once you acceptPostHog's own identifier and stored state: the id it knows you by, the referring site, campaign parameters and feature-flag state. After you sign in, that id becomes your account id and your email address is attached to it as a property.
ph_<token>_posthogLocal storagePostHogNo expiryOnly once you acceptThe main copy of the same store. PostHog writes both halves because we do not override its default storage setting.
ph_<token>_window_idSession storagePostHogBrowser tab sessionOnly once you acceptTells one browser tab apart from another so recordings are not interleaved.
ph_<token>_primary_window_existsSession storagePostHogBrowser tab sessionOnly once you acceptTells a fresh tab apart from a page reload.
__ph_opt_in_out_<token>Local storagePostHogNo expiry. The one thing a Decline leaves behind, on purpose.Only once you acceptPostHog's own off switch, and the opposite of a tracker: it holds no identifier and its only job is to keep measurement off. It is written when you withdraw, and it is deliberately the one item we do not delete when you do, because removing it would let PostHog's own background collectors start again on that page.
angels_post_referrerSession storageUs5 minutes, read once then deletedOnly once you acceptRemembers which post you came from so the next measurement can say where you arrived from. It never leaves your device, but its only purpose is measurement, so it is listed here rather than under preferences and it waits for your answer like everything else in this group.

2.3 Interface preferences

These enable the Website to provide enhanced functionality and personalization, such as remembering your preferences and display settings. All of them are set by us, and none of them are used to build an advertising profile of you or to follow you across other websites. Most of them are read only by the pages you already have open; where an item's value is sent to us, its entry below says so. If you do not allow them, some or all of these features may not function properly.

Every item in this group is stored in browser local storage or session storage rather than as a cookie. Local storage has no expiry and is cleared when you clear your browser storage; session storage is dropped when you close the tab.

NameTypeSet byHow long it lastsWhen it is setWhat it does
angels_themeLocal storageUsNo expiryBefore you confirm your ageLight, dark or match-my-system. Read before the first pixel is drawn so the page does not flash the wrong colour.
angels_feed_session_seedSession storageUsBrowser tab sessionBefore the privacy choiceA random number that fixes the order of your feed for this sitting, so scrolling further does not show you the same posts again.
angels_anon_reel_swipesSession storageUsBrowser tab sessionBefore the privacy choiceCounts how many videos you have watched without an account, so the sign-up prompt appears once rather than constantly.
angels_anon_feed_renderedSession storageUsBrowser tab sessionBefore the privacy choiceWhich posts the feed has already shown you without an account, so the free allowance runs down across refreshes instead of starting again each time. It holds post ids, never anything about you.
angels_dismissed_suggestionsLocal storageUsNo expiryBefore the privacy choiceWhich suggestions you dismissed, so they stay dismissed.
angels_spotlight_recentLocal storageUsNo expiryBefore the privacy choiceWhich Angels were featured to you recently, so a repeat visit shows different ones.
library:viewLocal storageUsNo expiryBefore the privacy choiceWhether you last used grid or list layout in your Library.
library:hasCustomCollectionsLocal storageUsNo expiryBefore the privacy choiceA hint that you have your own collections, so the Library reserves space for them instead of shifting the page when they load.
whispers-bubble-positionLocal storageUsNo expiryBefore the privacy choiceWhere you dragged the floating Whispers button, so it stays where you put it.
angels_pwa_install_snoozeLocal storageUsA timestamp; the prompt returns after it passesBefore the privacy choiceHow long to leave you alone after you dismissed the prompt to install the app.
angels_push_optin_snoozeLocal storageUsA timestamp; the prompt returns after it passesBefore the privacy choiceThe same, for the prompt asking whether you want notifications.
angels_push_userLocal storageUsUntil notifications are turned off on this browserBefore the privacy choiceWhich account last turned notifications on here. It holds an account id, so if a different person signs in on the same browser their notifications are not silently attached to the previous account's subscription.
wallet_offer_seen_<offer>Session storageUsBrowser tab sessionBefore the privacy choiceWhen a particular balance message was last shown to you, so it is not repeated in the same sitting but does come back when you return to the app later.

We review this inventory regularly.

2.4 Cache storage that survives updates

Our service worker keeps copies of pages, static files and media in your browser's Cache Storage, so that the Website loads quickly and still opens when your connection drops. It uses three stores: pages-<version> and static-<version>, which are replaced with each new release of the Website, and media-v1, which survives releases and holds a capped number of the images you have already viewed. Nothing in these stores leaves your device, and clearing your browsing data for this site removes all three.

The media store is the one worth knowing about: because it deliberately survives a release, images you have already viewed can remain on your device after an update, and on this Website those images are adult content. Clearing your browsing data for this site removes them.

NameTypeSet byHow long it lastsWhen it is setWhat it does
pages-<build>Cache storageUsDeleted when a new version of the site is installedBefore you confirm your ageA copy of pages you have already opened, so the app still shows something when your connection drops. Cleared on every deployment.
static-<build>Cache storageUsDeleted when a new version of the site is installedBefore you confirm your ageThe app's own code and fonts, cached so pages open quickly. Cleared on every deployment.
media-v1Cache storageUsSurvives deployments. Capped at roughly 300 images, oldest evicted first. Cleared by clearing site data.Before you confirm your ageImages you have already been shown, kept so scrolling back does not re-download them. This bucket deliberately survives updates, and it holds adult imagery, so it is listed here rather than left as an implementation detail.

3. Third-Party Cookies

Some cookies on our Website are set by third-party services that appear on our pages. We do not control the cookies set by these third parties, and their use is governed by the respective third party's privacy policy. The third-party services that may set cookies or read storage on our Website are:

  • PostHog, our analytics and session recording provider. It writes the analytics identifiers listed in section 2.2.
  • Stripe, our payment provider. Its script loads wherever a payment surface is shown, which is the card setup page, the checkout pages, and the in-page panels where you add a card, devote to an Angel, unlock content or sponsor a goal. Its cookies serve fraud prevention and device and session identification.
  • Supabase, our authentication provider. Its client library writes the sign-in cookies listed in section 2.1.
  • Cloudflare, which hosts the Website, delivers our video, and runs the bot challenge on the sign-in, registration and password reset forms. It sets bot management cookies, such as __cf_bm, on traffic through our domains, and challenge state cookies where that challenge is configured.

4. How to Manage Cookies

You can control and manage cookies in several ways. Most web browsers allow you to manage your cookie preferences through their settings. You can typically set your browser to: block all cookies; accept only first-party cookies; delete cookies when you close your browser; or be notified when a cookie is being set, allowing you to accept or reject it. Please note that if you block or delete cookies, some features of the Website may not function properly or may become unavailable.

To learn how to manage cookies in your specific browser, consult the help documentation for that browser or visit the browser manufacturer's website. If you use multiple browsers or devices, you will need to manage your cookie settings in each browser and on each device separately.

If you are in the EU or the EEA, our consent banner is where you accept or refuse the analytics items in section 2.2, and you can change that decision at any time under Privacy choices in your account settings. Strictly necessary items are not covered by that choice, because the Website cannot be served without them.

5. Do Not Track and Global Privacy Control

We do not currently respond to "Do Not Track" (DNT) or Global Privacy Control (GPC) browser signals. Where your consent is required before something is stored on your device, we collect that consent through our consent banner, and you can change your decision at any time.

6. Sensitive Data Considerations

Because our Website operates in the adult content space, we recognize that cookies and tracking data associated with your visits may constitute sensitive personal information under applicable privacy laws. We do not use cookie data from our Website to infer, derive, or create profiles related to your sexual orientation, sexual behavior, or adult content preferences for purposes unrelated to the operation of the Website. We do not sell or share cookie data that could reveal sensitive personal information.

7. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our use of cookies, changes in technology, or changes in applicable law. When we make material changes, we will update the date shown at the top of this Policy and provide notice as required by law. We encourage you to review this Policy periodically.

8. Contact Us

If you have questions about this Cookie Policy, please contact us at:

Aratian Limited, Andrea Syngrou 32A, Lakatameia 2300, Nicosia, Cyprus

Email: legal@angels.space

See also our Privacy Notice and Terms of Service.