Cookie Policy
PrankLab sets the cookies the site needs to work (including remembering how you arrived from a campaign link), plus Google Analytics and PostHog cookies so we can see which pages people use, catch errors, and (with masking) review sessions. We do not set advertising or retargeting cookies.
Última atualização: 21 September 2026
Nossas políticas são publicadas apenas em inglês. A versão em inglês é a que prevalece.
1. What we actually store on your device
| Name | Type | What it does | Lifetime |
|---|---|---|---|
| pranklab_locale | Cookie — strictly necessary | Remembers which of our eight languages you chose, so we do not send you back to English on the next page | 1 year |
| pranklab-theme | Local storage — strictly necessary | Remembers whether you picked light or dark mode | Until you clear it |
| Session cookie | Cookie — strictly necessary | Keeps you signed in once accounts go live. Set by Supabase, our authentication provider. | Session or until sign-out |
| Stripe cookies | Cookie — strictly necessary | Set only on the checkout page, by Stripe, to process your payment and detect card fraud | Set by Stripe |
| utm_source | Cookie — strictly necessary | Remembers the utm_source from a campaign link so we can attribute sign-ups and purchases to the right channel | 90 days |
| utm_medium | Cookie — strictly necessary | Remembers the utm_medium from a campaign link for the same attribution purpose | 90 days |
| utm_campaign | Cookie — strictly necessary | Remembers the utm_campaign from a campaign link for the same attribution purpose | 90 days |
| utm_referer | Cookie — strictly necessary | Remembers the utm_referer from a campaign link for the same attribution purpose | 90 days |
| referer | Cookie — strictly necessary | Remembers the referer query value from a campaign link for the same attribution purpose | 90 days |
| _ga | Cookie — analytics | Set by Google Analytics to distinguish unique visitors. Used only to measure how the site is used. | Up to 2 years |
| _ga_* | Cookie — analytics | Set by Google Analytics (GA4) to persist session state for the measurement ID we use. | Up to 2 years |
| ph_* | Cookie — analytics | Set by PostHog to distinguish unique visitors, link product events and errors to a session, and support privacy-masked session replay. Uploaded photos and generated media are blocked from recordings. | Up to 1 year |
Language and theme are also inferred from your browser's Accept-Language header and system settings the first time you visit, which requires no storage at all.
3. What we do not do
- No advertising or retargeting cookies.
- No Meta pixel, and no advertising SDKs.
- No selling personal data collected through cookies.
- No fingerprinting, and no building of an advertising profile about you across unrelated sites.
- No sending uploaded photos or generated prank media into analytics or session replay — those elements are masked or blocked before recording.
4. Controlling cookies yourself
Every browser lets you view, block and delete cookies, usually under Settings → Privacy. You can also use private browsing, which discards everything when you close the window.
Blocking our strictly necessary cookies will not stop you browsing the site, but the language you pick will not stick, your theme choice will be forgotten, and once accounts are live you will not be able to stay signed in. Blocking analytics cookies stops Google Analytics and PostHog from measuring your visits.
We honour Global Privacy Control signals. Since we neither sell nor share personal information for cross-context behavioural advertising, a GPC signal does not change what cookies we set — but it is respected all the same.
5. Questions
Anything about cookies or tracking goes to legal@pranklab.io. How we handle personal data more broadly is covered in our Privacy Policy.