Effective Date: April 19, 2026 | Last Updated: May 22, 2026
Required for ARA to function. These do not require consent under the ePrivacy Directive. They include Firebase Authentication tokens (so you stay signed in), the cookie consent record itself, your theme preference (Cream or Moss), and short-lived Firebase SDK heartbeats. Blocking them will break sign-in.
ARA uses Google Analytics 4 to understand which features get used and where the app breaks. These cookies are only placed if you tap "Accept All" or enable Analytics in the preferences panel. If you decline, no GA script is loaded and no analytics data leaves your browser.
ARA uses Sentry to capture crashes and failed requests so we can fix them quickly. Sentry is also consent-gated: nothing loads until you toggle Error Tracking on. Sentry's session replay feature, which records richer diagnostic context, is only activated if you have also accepted Analytics.
No marketing cookies
Every cookie or storage entry ARA places, what category it falls into, and how long it lasts. Cookies set by third parties (Stripe Checkout, Google Fonts) are listed only where ARA's UI triggers them; their own policies apply once you reach their domain.
| Name | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
firebaseLocalStorageDb | Firebase Auth | Keeps you signed in between visits. | Strictly necessary | Persistent |
firebase-heartbeat-store | Firebase SDK | Internal Firebase telemetry. No personal data. | Strictly necessary | Persistent |
ara_cookie_consent_detail | ARA | Stores your consent choice, the policy version, and a timestamp. | Strictly necessary | 12 months |
ara_cookie_consent | ARA (legacy) | Backwards-compatible mirror of your analytics choice. Kept so old code paths keep working. | Strictly necessary | 12 months |
ara-theme | ARA | Remembers your Cream or Moss theme choice. | Strictly necessary | Persistent |
_ga, _ga_* | Google Analytics | Distinguish anonymous sessions for usage analytics. | Analytics (consent-gated) | Up to 26 months |
| Sentry session replay | Sentry | Records user interactions to help diagnose errors. Only when both Analytics and Error Tracking are on. | Analytics (consent-gated) | Session |
Some Firebase SDK state uses IndexedDB rather than traditional cookies. Listed here under the same heading because the consent rules treat them identically.
Some pages link to or embed third-party services. Those services set their own cookies, governed by their own policies. The ones ARA triggers:
Full subprocessor list and what data each one sees lives in Privacy Policy §5.
You can review or change your cookie choices at any time. The fastest way:
You can also:
Heads up
ARA honours the Global Privacy Control (GPC) signal. If your browser or extension sends a Sec-GPC: 1 header or sets navigator.globalPrivacyControl totrue, we treat it as an opt-out of any sale or sharing of personal data, and as a directional opt-out of analytics tracking that we have not yet bound to a separate consent choice.
Note that ARA does not currently sell or share personal data with advertisers (see Privacy Policy), so GPC mostly serves as a stronger consent signal than the banner alone. The older "Do Not Track" header is honoured where reasonably possible, but the W3C DNT specification has been discontinued and is no longer maintained.
When you choose a cookie option we store the choice locally under ara_cookie_consent_detail together with:
For signed-in users, an additional copy is written to your account under users/{uid}/consent_records as an immutable audit trail. These records are kept so we can demonstrate compliance under GDPR Article 5(2). They are not used for anything else and are accessible to you via your data export.
Consent expires after 12 months. At that point the banner re-displays so you can confirm or change your choice. If we change the policy in a way that affects what we ask consent for, we bump the policy version, which also re-prompts.
We may update this Cookies Policy when we add, remove, or change a cookie. Material changes will be announced through the cookie banner before they take effect. The "Last Updated" date at the top of this page indicates when the policy was last revised.
If you have questions about cookies on ARA, write to us:
Entity
Arbos Folk
CVR 46278895
Address
Byhøjvænget 17
8380 Trige, Denmark
Responsible person
Leif Pettersen
More legal documents
Privacy Policy
What we collect, why, and how long we keep it.
Terms of Service
The agreement you accept when you sign in.
Security & Privacy
How ARA protects sanctuary data, end to end.
Legal Notice
Operator identification and supervisory authority.