Cookie Policy
Operated by Aratian Limited. Last updated: August 26, 2026
This Cookie Policy explains how Aratian Limited ("Company," "we," "us," or "our") uses cookies and similar tracking technologies on the angels.space website located at https://angels.space (the "Website"). This Policy should be read alongside our Privacy Notice, which provides additional detail on how we collect and use your personal information.
2.1 Strictly necessary
These cookies are essential for the Website to function and cannot be disabled in our systems. They are typically set in response to actions you take that amount to a request for services, such as setting your privacy preferences, logging in, or completing forms. Without these cookies, some parts of the Website may not function properly.
The sign-in cookie identifies your account, and the closed-beta access cookie contains the email address your invitation was sent to. The others in this group do not identify you.
| Name | Type | Set by | How long it lasts | When it is set | What it does |
|---|---|---|---|---|---|
| ag_ok | Cookie | Us | 30 days | Before you confirm your age | Records that you confirmed you are 18 or over. Until it exists, every page is replaced by the age gate. It is also what keeps session recording off until you have confirmed. |
| consent_region | Cookie | Us | Browser session (deleted when you close the browser) | Before you confirm your age | Records that European privacy rules apply to you. Its only value is the literal text 'eu'. It holds no identifier and nothing that distinguishes you from any other visitor in scope. |
| legal_regime | Cookie | Us | Browser session when our servers set it; 365 days once you sign in to an account that accepted a specific set of Terms | Before you confirm your age | Records which set of legal documents applies to you: 'us' for visitors in the United States, 'eu' for everyone else. It holds no identifier. |
| eu_consent | Cookie | Us | 180 days for both answers | Before the privacy choice | The choice you made about analytics. Written only by your own click, never by us in the background. A refusal is remembered exactly as long as an acceptance, so declining does not mean being asked again on every visit. |
| sb-<project-ref>-auth-token | Cookie | Supabase | 400 days (our sign-in library's default; we pass no cookie options) | Before the privacy choice | Keeps you signed in. Holds the access token, the refresh token, the expiry and your user record. Split across numbered cookies when it is too large for one. |
| sb-<project-ref>-auth-token-code-verifier | Cookie | Supabase | Single use, deleted as soon as sign-in completes | Before the privacy choice | The one-time secret that finishes a Google or email sign-in securely. |
| angels_oauth_state | Cookie | Us | 10 minutes, single use | Before the privacy choice | Stops someone else starting a Google sign-in on your behalf. Cleared the moment it has been checked. |
| beta_ok | Cookie | Us | 7 days | Before you confirm your age | Closed-beta access. Only ever set while the beta wall is switched on, which it is not in any live environment. It contains your email address inside a signed value, so we list it rather than describe this set as holding no personal data. |
| __cf_bm | Cookie | Cloudflare | Set by Cloudflare, typically around 30 minutes | Before you confirm your age | Bot detection at our network edge. Applied by Cloudflare to traffic on our domains, including our API, not written by our own code. |
| cf_clearance | Cookie | Cloudflare | Set by Cloudflare | Before you confirm your age | Records that a Cloudflare security challenge was passed, so you are not challenged repeatedly. |
| beta:admit-bounces | Session storage | Us | Browser tab session | Before you confirm your age | Counts silent beta admission attempts so a browser that refuses cookies cannot bounce between two pages forever. |
| angels_token | Local storage | Us | Until you sign out | Before the privacy choice | A sign-in token from our previous authentication system. Supabase replaced it in every environment, so nothing writes it any more, but the read path still ships and we disclose it rather than assume it is gone. |
2.2 Analytics and measurement
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our Website. They help us understand which pages are the most and least popular and how visitors navigate the Website.
The information collected here is not only aggregate. When you are signed in it is attached to your account, and it feeds the systems that rank and personalize what you see. Our analytics and session recording provider is PostHog, which sets its own identifiers on your device. Our Privacy Notice describes what is collected and how it is used.
If you reach us from the EU, the EEA, the UK or Switzerland, or from Andorra, Monaco, San Marino or the Vatican, we ask before we measure anything. You get a choice with two buttons, Accept and Decline, both the same size. Nothing is pre-ticked, and carrying on browsing is not an answer.
Before you press Accept for the first time, nothing in this group exists on your device and nothing about your visit is sent anywhere. That is a description of what happens rather than a promise about what we do afterwards: the measurement code is never started, no identifiers are created, our analytics provider's script is never downloaded at all, and our own servers refuse measurements that arrive without your recorded consent.
If you accept and later decline, we stop, and we delete what that measurement left on your device, in local storage and in session storage alike. One thing survives a Decline, and we would rather name it than round the sentence up: our analytics provider's own off switch, listed below as __ph_opt_in_out_. It holds no identifier and it is the thing that keeps collection off, so deleting it would let that provider's background collectors start again on the same page. It is the only thing that stays.
Session recording never runs for those visitors. Not before the choice, and not after it. Accepting analytics does not switch it on, and it cannot be switched on by a setting: that would take a new version of this page, a new choice put to you, and a separate answer from you.
We remember the answer for 180 days either way, so declining does not mean being asked again on every visit. We also keep a record that we asked: what you chose, when, which versions of these documents were in force, and a shortened form of your IP address. That record carries no advertising identifier and no device identifier.
Everywhere else, including the United States, there is no opt-in step and measurement runs from the first visit. We would rather say that plainly than imply a choice you do not have. One detail deserves stating rather than burying: it starts before you confirm you are 18. The age confirmation is the first thing you see, but our analytics provider's identifier is already set on that screen. Session recording is the exception, and it does wait for the age confirmation. Everything set at that point is listed below, in the "When it is set" column.
| Name | Type | Set by | How long it lasts | When it is set | What it does |
|---|---|---|---|---|---|
| angels_analytics_anon_id | Local storage | Us | No expiry (removed if you withdraw) | Only once you accept | A random id for this browser. It lets us count a returning visitor as one person rather than several, and if you later create an account we connect that earlier activity to it. It is also sent to our API on feed and reel requests. |
| angels_analytics_session_id | Local storage | Us | Rotates after 30 minutes of inactivity | Only once you accept | Groups one sitting of activity together. |
| angels_analytics_session_last_at | Local storage | Us | Overwritten on every interaction | Only once you accept | The time you were last active, used only to decide when the id above should roll over. |
| angels_analytics_retry_queue | Local storage | Us | Per batch, capped and expired | Only once you accept | Holds measurements that failed to send, so a dropped connection does not lose them. Each held item carries the browser id, the session id and the event. |
| ph_<token>_posthog | Cookie | PostHog | 365 days (vendor default) | Only once you accept | PostHog's own identifier and stored state: the id it knows you by, the referring site, campaign parameters and feature-flag state. After you sign in, that id becomes your account id and your email address is attached to it as a property. |
| ph_<token>_posthog | Local storage | PostHog | No expiry | Only once you accept | The main copy of the same store. PostHog writes both halves because we do not override its default storage setting. |
| ph_<token>_window_id | Session storage | PostHog | Browser tab session | Only once you accept | Tells one browser tab apart from another so recordings are not interleaved. |
| ph_<token>_primary_window_exists | Session storage | PostHog | Browser tab session | Only once you accept | Tells a fresh tab apart from a page reload. |
| __ph_opt_in_out_<token> | Local storage | PostHog | No expiry. The one thing a Decline leaves behind, on purpose. | Only once you accept | PostHog's own off switch, and the opposite of a tracker: it holds no identifier and its only job is to keep measurement off. It is written when you withdraw, and it is deliberately the one item we do not delete when you do, because removing it would let PostHog's own background collectors start again on that page. |
| angels_post_referrer | Session storage | Us | 5 minutes, read once then deleted | Only once you accept | Remembers which post you came from so the next measurement can say where you arrived from. It never leaves your device, but its only purpose is measurement, so it is listed here rather than under preferences and it waits for your answer like everything else in this group. |
2.3 Interface preferences
These enable the Website to provide enhanced functionality and personalization, such as remembering your preferences and display settings. All of them are set by us, and none of them are used to build an advertising profile of you or to follow you across other websites. Most of them are read only by the pages you already have open; where an item's value is sent to us, its entry below says so. If you do not allow them, some or all of these features may not function properly.
Every item in this group is stored in browser local storage or session storage rather than as a cookie. Local storage has no expiry and is cleared when you clear your browser storage; session storage is dropped when you close the tab.
| Name | Type | Set by | How long it lasts | When it is set | What it does |
|---|---|---|---|---|---|
| angels_theme | Local storage | Us | No expiry | Before you confirm your age | Light, dark or match-my-system. Read before the first pixel is drawn so the page does not flash the wrong colour. |
| angels_feed_session_seed | Session storage | Us | Browser tab session | Before the privacy choice | A random number that fixes the order of your feed for this sitting, so scrolling further does not show you the same posts again. |
| angels_anon_reel_swipes | Session storage | Us | Browser tab session | Before the privacy choice | Counts how many videos you have watched without an account, so the sign-up prompt appears once rather than constantly. |
| angels_anon_feed_rendered | Session storage | Us | Browser tab session | Before the privacy choice | Which posts the feed has already shown you without an account, so the free allowance runs down across refreshes instead of starting again each time. It holds post ids, never anything about you. |
| angels_dismissed_suggestions | Local storage | Us | No expiry | Before the privacy choice | Which suggestions you dismissed, so they stay dismissed. |
| angels_spotlight_recent | Local storage | Us | No expiry | Before the privacy choice | Which Angels were featured to you recently, so a repeat visit shows different ones. |
| library:view | Local storage | Us | No expiry | Before the privacy choice | Whether you last used grid or list layout in your Library. |
| library:hasCustomCollections | Local storage | Us | No expiry | Before the privacy choice | A hint that you have your own collections, so the Library reserves space for them instead of shifting the page when they load. |
| whispers-bubble-position | Local storage | Us | No expiry | Before the privacy choice | Where you dragged the floating Whispers button, so it stays where you put it. |
| angels_pwa_install_snooze | Local storage | Us | A timestamp; the prompt returns after it passes | Before the privacy choice | How long to leave you alone after you dismissed the prompt to install the app. |
| angels_push_optin_snooze | Local storage | Us | A timestamp; the prompt returns after it passes | Before the privacy choice | The same, for the prompt asking whether you want notifications. |
| angels_push_user | Local storage | Us | Until notifications are turned off on this browser | Before the privacy choice | Which account last turned notifications on here. It holds an account id, so if a different person signs in on the same browser their notifications are not silently attached to the previous account's subscription. |
| wallet_offer_seen_<offer> | Session storage | Us | Browser tab session | Before the privacy choice | When a particular balance message was last shown to you, so it is not repeated in the same sitting but does come back when you return to the app later. |
We review this inventory regularly.
2.4 Cache storage that survives updates
Our service worker keeps copies of pages, static files and media in your browser's Cache Storage, so that the Website loads quickly and still opens when your connection drops. It uses three stores: pages-<version> and static-<version>, which are replaced with each new release of the Website, and media-v1, which survives releases and holds a capped number of the images you have already viewed. Nothing in these stores leaves your device, and clearing your browsing data for this site removes all three.
The media store is the one worth knowing about: because it deliberately survives a release, images you have already viewed can remain on your device after an update, and on this Website those images are adult content. Clearing your browsing data for this site removes them.
| Name | Type | Set by | How long it lasts | When it is set | What it does |
|---|---|---|---|---|---|
| pages-<build> | Cache storage | Us | Deleted when a new version of the site is installed | Before you confirm your age | A copy of pages you have already opened, so the app still shows something when your connection drops. Cleared on every deployment. |
| static-<build> | Cache storage | Us | Deleted when a new version of the site is installed | Before you confirm your age | The app's own code and fonts, cached so pages open quickly. Cleared on every deployment. |
| media-v1 | Cache storage | Us | Survives deployments. Capped at roughly 300 images, oldest evicted first. Cleared by clearing site data. | Before you confirm your age | Images you have already been shown, kept so scrolling back does not re-download them. This bucket deliberately survives updates, and it holds adult imagery, so it is listed here rather than left as an implementation detail. |
5. Do Not Track and Global Privacy Control
We do not currently respond to "Do Not Track" (DNT) or Global Privacy Control (GPC) browser signals. Where your consent is required before something is stored on your device, we collect that consent through our consent banner, and you can change your decision at any time.
6. Sensitive Data Considerations
Because our Website operates in the adult content space, we recognize that cookies and tracking data associated with your visits may constitute sensitive personal information under applicable privacy laws. We do not use cookie data from our Website to infer, derive, or create profiles related to your sexual orientation, sexual behavior, or adult content preferences for purposes unrelated to the operation of the Website. We do not sell or share cookie data that could reveal sensitive personal information.
7. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in our use of cookies, changes in technology, or changes in applicable law. When we make material changes, we will update the date shown at the top of this Policy and provide notice as required by law. We encourage you to review this Policy periodically.
8. Contact Us
If you have questions about this Cookie Policy, please contact us at:
Aratian Limited, Andrea Syngrou 32A, Lakatameia 2300, Nicosia, Cyprus
Email: legal@angels.space
See also our Privacy Notice and Terms of Service.