Yahalaly
Cookie Policy

Cookie Policy

Last updated: August 29, 2026

Yahalaly uses first-party cookies for account authentication, request security, a language choice, and saving an optional analytics choice. With analytics consent, the first channel detected after consent can also be held in same-tab session storage until the tab closes. No advertising, cross-site marketing, or third-party analytics cookies are active at the founding-member launch.

1) What a cookie is

A cookie is a small value stored by a browser and returned with later requests to the same service. Some cookies are necessary to keep an account signed in, protect a state-changing request, or remember a setting.

2) Cookies currently used

Security cookies may be replaced earlier when you sign in, sign out, revoke a session, reset credentials, or when Yahalaly rotates them for security. Server-side session, audit, rate-limit, and security records are not browser cookies and are covered by the Privacy Policy.

  • access_token — HTTP-only authentication cookie used for a short signed-in session; configured for up to 15 minutes.
  • refresh_token — HTTP-only authentication cookie used to renew a session securely; configured for up to 30 days and revocable from account session controls.
  • csrf_token — first-party anti-CSRF value used to validate state-changing requests; configured for up to 30 days.
  • locale — first-party preference cookie set when you choose an interface language; configured for up to one year.
  • yahalaly_analytics_consent — first-party choice cookie containing only the consent version and an analytics true/false choice; configured for up to one year.

3) Optional aggregate analytics and same-tab attribution

Fixed public-image actions can cover published blank prompt cards and the localized women-first campaign card. The image and its fixed QR destination contain no account, profile, member, recipient, or referral identifier. A consented count contains only the fixed page, channel, and requested image-share or image-download action; it does not contain the image, caption, link, destination, delivery, saving, or download completion.

Yahalaly shows equal choices to allow or decline optional first-party aggregate analytics. The tracker runs only after an allow choice and remains disabled when a browser sends Do Not Track or Global Privacy Control, or reports automated-browser operation. On public pages, including this policy, you can reopen Analytics choices and change the setting at any time. A signed-in trusted-invitation action never turns analytics on; its fixed aggregate stages are counted only if the current consent version already records an allow choice.

When allowed, the browser locally reduces an allowlisted campaign value or referring hostname to one fixed channel such as a member-shared public invitation, a shared blank prompt card, a shared Niyyah conversation-builder link, ChatGPT, Reddit, Pinterest, Deenlist, deen.page, Muslim Business Germany, MuslimConnect, Ummah, ummah.build, Built for Muslims, Startup Muslim, Quora, Medium, LinkedIn, SaaSHub, Datteltäter, Islamische Zeitung, Kleinanzeigen, Habiba & Habibi, ZamZam e.V., Commonsplace, YouTube, TikTok, Instagram, a search category, other social, other external, internal, or direct. An unrecognized non-empty campaign source becomes only other external. Only this label is kept in session storage for the current tab; raw referrers, URLs, query strings, campaign names, account identifiers, profile identifiers, and referral identifiers are never placed there. The first label is not replaced by later navigation in that tab.

Public page-view, fixed public-tool-stage (start, use, link share, copy, print, blank-card image-share attempt, or blank-card image-download initiation), signed-in trusted-invitation-stage (prompt view, WhatsApp open, successful native-share handoff, or successful copy), and registration-button-click requests are sent without account credentials, cookies, or a referrer header. Image actions describe a requested browser action, not confirmed delivery, saving, or download completion. Member, profile, recipient, destination, or referral identifiers, invitation text, tool entries and outputs, selections, generated text, and clipboard content are never included. After a genuinely new account is created, the registration request can increment a completed-signup daily total only when the current analytics-choice cookie still says allow and browser privacy signals permit it. Duplicate and rejected attempts do not increment that total. This optional analytics channel is not added to the member, audit-log, or person-level product analytics record.

Separate from optional analytics, a recognized Yahalaly registration link can supply one fixed allowlisted entry-page label that is stored with the new account for registration and activation cohort comparison regardless of the analytics choice. The registration form discloses this when a label is present. It does not store the raw page URL, referrer, campaign text, query string, or anything entered in a public tool. This account-level field is covered by the Privacy Policy; it is not a cookie or same-tab attribution value.

The aggregate table contains no event, visitor, session, or user identifier, exact event time, IP address, user agent, raw referrer, URL, query string, campaign name, device, or country. Its daily totals are retained for up to 400 days. Same-tab attribution is normally removed when the tab closes, and is removed sooner after a decline choice. Yahalaly does not use this measurement to follow a person across sites.

4) Browser controls

You can inspect, delete, or block cookies and site storage using browser settings. Blocking authentication or security cookies prevents sign-in and protected account actions from working. Deleting the locale cookie resets automatic language selection. Deleting the analytics-choice cookie makes the choice panel appear again; choosing decline stops future optional analytics requests and clears the same-tab fixed-channel value.

5) No advertising or third-party analytics

Yahalaly does not activate advertising, cross-site marketing, or third-party analytics technology at launch. A future provider or category would be named with its purpose and duration, and any required choice would be presented before it becomes active.

6) Contact and changes

Material changes receive a new effective date. Questions about cookies or browser storage can be sent to privacy@yahalaly.com.