Cookies and storage
Draft version 1 — not yet reviewed
Costume Closet uses only what is strictly necessary to work, plus first-party analytics and cookieless Plausible statistics, so there is nothing here to opt out of — the cookie notice records your answer but does not change what runs. One thing is asked before the site is usable: what happens to a photo you upload, because that is the only place we act on your image. This page is the full detail.
What is stored in your browser
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| cc_session | First-party cookie (httpOnly, SameSite=Lax) | Keeps your anonymous session, credits and history | Up to 400 days |
| cc_rt | localStorage | Recovery token: lets us restore your identity if cookies are cleared | Until you delete your data or it expires (400 days since last use) |
| cc / kv / rt | IndexedDB | Second copy of the recovery token (redundancy) | Same as cc_rt |
| cc_draft | localStorage | Saves the items you typed on the "What do you own?" screen so going back keeps your input | Until you clear it or delete your data |
| cc_utm, cc_rec_*, cc_last_rec | sessionStorage | Remember how you arrived and your last recommendation for this tab | Until you close the tab |
| cc_consent | localStorage | Remembers your answer to the cookie notice ("accepted" or "declined"). Nothing changes either way | Until you clear it or delete your data |
| cc_photo_consent | localStorage | Records that you accepted the photo/AI terms on this browser. Until it is set, the site is not usable | Until you clear it or delete your data |
| cc_free | localStorage | Remembers that your free preview is still available (display only) | Until your balance changes |
Analytics
We record first-party product events (for example "landing viewed", "preview downloaded") linked to your random anonymous ID, kept for 12 months. We also use Plausible in its cookieless mode, which sets no cookies and collects no personal data.
About the recovery token
The recovery token is a random secret. It is not your identity by itself; on our side only its SHA-256 hash is stored. It keeps your credits and history if your cookies are cleared. If you would rather not keep it, use "Delete my data" on the Privacy page, which removes it from both places.
Clearing all site data (cookies, localStorage and IndexedDB together) creates a new anonymous identity.
Third parties
Razorpay (payments) and Cloudflare Turnstile (bot check) may set their own cookies on their own pages or widgets. We do not use advertising or tracking pixels.
Withdraw consent
Changed your mind? Clear the answers you gave us so you can choose again. This forgets only your consent answers — your session, credits, saved costumes and history stay exactly as they are. To delete those too, use the delete option on the history screen.