TRAVLR Back to app
On this page
  • 1. What Are Cookies?
  • 2. What We Use
  • 3. Strictly Necessary
  • 4. Analytics
  • 5. Third-Party Storage
  • 6. Managing Cookies
  • 7. Updates
  • 8. Contact
Legal

Cookie Policy

Last updated: 2 September 2026

01 What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently, remember your preferences, and provide information to site owners.

In addition to cookies, TRAVLR uses localStorage and sessionStorage — browser-side storage mechanisms that work similarly to cookies but are never transmitted to the server. They are used to persist your preferences (such as sidebar state) without server round-trips.

This policy covers all cookies and browser storage set by travlr.earth. Everything we set ourselves is named travlr- or travlr:, so you can see the whole of it in your browser’s developer tools and check it against the table below.

02 What We Use — Overview

The headline: TRAVLR sets no advertising or tracking cookies of its own, and there are no social media pixels anywhere in the app. Nothing we store is used to build a picture of you, and none of it is shared with anyone for advertising. What we do store is your own settings and the state of whatever you were last doing — plus, if you click a sponsored card, a throwaway id that lasts until you close the tab so that one click is not counted twice. The one third party on the page is our travel affiliate network, which exists to credit us when a sponsored link leads to a booking; it is named in Third-Party Storage & Resources and it runs on the website only, never in the iOS or Android app.

We categorise our cookies into two types:

  • Strictly Necessary — essential to operate the Service. Cannot be turned off.
  • Analytics — help us understand how TRAVLR is used. Set only with your consent.

03 Strictly Necessary Cookies & Storage

These are required for TRAVLR to function. They do not require consent under GDPR (Recital 25, ePrivacy Directive).

One entry is listed here for completeness rather than because the Service needs it: travlr-ad-session-id is created only at the moment you choose to open a sponsored card, and your browser discards it when you close the tab. If you never click one, it is never created.

Name Type Purpose Duration Set by
sb-*-auth-token Cookie / localStorage Supabase authentication session — keeps you logged in Session / 1 week Supabase
travlr-cookie-consent localStorage Stores your cookie consent preferences so we don't ask every visit 13 months TRAVLR
Interface preferences
travlr-theme, travlr-style, travlr-ds-style, travlr-sidebar-collapsed, travlr-mapmode, travlr-mapmode-cat, travlr-ms-mode, travlr-ms-sub-*, travlr-scalebar, travlr-haptics, travlr-formfactor, travlr-privacy-screen, travlr-boot-bg, travlr:railHost
localStorage Remembers how you have set the app up — colour theme, map style, which panel and map mode you were last in, the scale bar, haptics, and whether the sidebar is collapsed. Preferences only; none of it describes you Persistent (until cleared) TRAVLR
Feature state
travlr-bucket-v1, travlr-cart-v1, travlr-*-migrated-v1, travlr-recent-searches, travlr-search-recent-v1, travlr-waitlist-v1, travlr-onboarding-pending, travlr-display-name, travlr-pro, travlr-push-enabled, travlr:lt-active, travlr:lt-visibility, travlr:get-app-dismissed
localStorage Keeps a feature where you left it — a bucket list or basket held on this device before you have an account, your recent searches, whether a live track is running, and prompts you have already dismissed so we stop showing them Persistent (until cleared) TRAVLR
travlr-oauth-pending sessionStorage Remembers which provider you chose while you are away at a Google or Apple sign-in page, so the app knows what it is waiting for when you come back Until the tab closes TRAVLR
travlr-ad-session-id sessionStorage A random one-off id, created only if you click a sponsored card, so the same click is not counted twice. It is not linked to your account, not sent to the partner, and a new one is generated in the next tab Until the tab closes TRAVLR

04 Analytics Cookies

We may use analytics tools to understand how the Service is used in aggregate — which features are popular, where errors occur, and how performance can be improved.

Analytics cookies are only set after you have given explicit consent. If you decline analytics in the cookie banner, none of the following are set.

Name Type Purpose Duration Set by
[Not yet active] — TRAVLR currently has no analytics cookies active. This section will be updated when analytics tooling is introduced. — —

We will update this policy before deploying any analytics tool and will re-seek your consent if required.

05 Third-Party Storage & Resources

TRAVLR loads resources from the following domains other than travlr.earth. Where one is a third party, it may set its own storage items, governed by its own cookie policy:

Domain Purpose Their cookie policy
travlr-tiles.matsmiersen.workers.dev Our own map server — imagery, map data, elevation, fonts and country outlines. A separate address, but our infrastructure, not a third party's Sets no cookies and no storage
api.mapbox.com Mapbox — close-up satellite imagery, loaded only once you zoom in past roughly country level on the Satellite map style Sets no cookies on these requests — Mapbox Privacy Policy
vafmymyjxabkgkijcatd.supabase.co Backend API, database, authentication, storage Supabase Privacy Policy
api.wheretheiss.at Real-time ISS position (anonymous API, no cookies set) No known cookie policy — anonymous public API
tpembars.com Travelpayouts, our travel affiliate network. This script turns qualifying outbound travel links on the page into affiliate links, so that if you go on to book something we are credited for it. Website only — the iOS and Android apps never load it Travelpayouts Privacy Policy
search.hotellook.com, search.jetradar.com, tp.media Where a “Sponsored” card takes you when you tap it — a hotel or flight search carrying our affiliate id. Nothing is requested from these domains while you are simply reading a page; they are only ever opened by your own tap Travelpayouts Privacy Policy

We do not use social media plugins or embedded video players (YouTube/Vimeo). The one advertising-adjacent thing we do use is the travel affiliate network above: it may set its own cookie to remember that you arrived at a travel partner from TRAVLR, which is how a booking gets credited to us. It is not an ad network, it does not target ads at you, and it is not used to build a profile of you — but it is a third party, and it is listed here rather than buried.

This list is shorter than it used to be. TRAVLR previously loaded fonts from Google Fonts, code libraries from jsDelivr, and fallback profile pictures from an avatar API — four external companies told your IP address and the page you were on, every visit. Those files are now served from our own domain and the avatars are drawn in your browser, so none of those requests are made any more. Map data and elevation moved the same way (close-up satellite imagery is the exception — it has to come from Mapbox directly): see Sharing & Third-Party Processors in the Privacy Policy.

06 Managing Your Cookie Preferences

6.1 Cookie banner

When you first visit TRAVLR, a cookie consent banner appears at the bottom of the screen. You can:

  • Accept all — enables strictly necessary and analytics cookies.
  • Necessary only — enables only strictly necessary storage; no analytics.
  • Manage preferences — opens a detailed panel to choose category by category.

You can change your preferences at any time by clicking "Cookie settings" in the app sidebar footer.

6.2 Browser controls

You can also control cookies directly in your browser. Instructions for major browsers:

  • Google Chrome
  • Mozilla Firefox
  • Apple Safari
  • Microsoft Edge

Note: blocking all cookies may prevent some features of TRAVLR from working correctly, in particular authentication.

6.3 Clearing browser storage

To clear TRAVLR’s entries, open your browser’s Developer Tools (F12) and go to Application → Storage. Under Local Storage → travlr.earth you will find the preference and feature keys; deleting them resets your settings and logs you out of any active session. Under Session Storage you will find the two short-lived keys from the table above, which your browser discards on its own when you close the tab.

07 Updates to This Policy

We will update this Cookie Policy when we add, modify, or remove storage items. The "Last updated" date at the top of this page reflects the most recent revision.

If we introduce cookies that require consent and you have previously only accepted necessary cookies, we will display a new consent prompt.

08 Contact

If you have questions about our use of cookies, please contact:

TRAVLR Privacy Team
Email: privacy@travlr.earth
© 2026 TRAVLR. All rights reserved.
Privacy Policy Terms of Service Cookie Policy Contact