Cookie Policy
Every cookie and browser store the site uses, what each one is for, and which of them run only if you say yes.
Last updated Sep 14, 2026
In short
The cookies needed to use the site run without asking — without them you cannot sign in and your language cannot be remembered. Beyond those there is exactly one optional group: marketing. Unless you explicitly accept it, no marketing request leaves your browser.
Strictly necessary and functional
This group is not subject to consent; it is the service itself. Clear them from your browser and you are signed out and your preferences reset.
- sb-<project>-auth-tokenCookie
Keeps you signed in. It can be split across parts, so you may also see it with a .0 / .1 suffix.
Lifetime: For the session, refreshed
- sb-<project>-auth-token-code-verifierCookie
Completes the sign-in and email confirmation flow.
Lifetime: Until the flow finishes
- tv_localeCookie
Remembers which language you read the site in.
Lifetime: 1 year
- tv_view_roleCookie
Remembers which role you are browsing as, and builds the menu to match.
Lifetime: 1 year
- themelocalStorage
Remembers your light or dark theme preference.
Lifetime: Until you clear it
- tv:draft:*sessionStorage
Holds what you typed in the profile setup form until the tab closes, so a refresh does not lose it.
Lifetime: When the tab closes
- tv:onboarding:rolesessionStorage
Carries the role you picked through the sign-up steps.
Lifetime: When the tab closes
Two of the technologies listed are not cookies. localStorage and sessionStorage are your browser’s own storage areas; unlike cookies they are not sent to the server on their own. Both stay on your device.
Analytics
We use Google Analytics to see which pages get visited. This too only comes into play if you accept: until you do, Google’s script is never added to the page.
- _gaCookie
Set by Google Analytics to count repeat visits as the same browser.
Lifetime: Set by Google
- _ga_<measurement id>Cookie
Holds session state. The suffix varies with the measurement property.
Lifetime: Set by Google
The only thing that reaches Google is the address of the page you are on. We have turned off Google’s own collection of page views, so we decide which address gets reported — and the same limits apply as for the marketing pixel: it does not run on pages belonging to your account, your messages, your requests or your share links, nor on a page whose address carries a search term.
Marketing
We use the Meta Pixel to measure whether our advertising works. It only comes into play if you accept: until you do, Meta’s script is never added to the page and your browser makes no request to Meta at all.
The pixel is only ever started on public pages: open a page belonging to your account, your messages, your notifications or one of your share links directly, and Meta’s script is never added to it. Nor is it added on a page whose address carries a search term.
Once it has loaded, though, Meta reports the addresses of the pages you visit as you move around the site in that tab, on its own — behaviour we are not able to switch off. So moving from a public page into your account can put that page’s address in front of Meta. Nothing beyond the address goes: the text of your requests, your photographs and your messages are never sent, under any circumstances.
- _fbpCookie
Set by the Meta Pixel to distinguish your browser for advertising measurement.
Lifetime: Set by Meta
- _fbcCookie
If you arrived from a Meta ad, ties that click to the measurement.
Lifetime: Set by Meta
What reaches Meta when you accept, and what does not:
- Sent: the address of the page you are on, and a standard page-view event.
- Sent: when you finish creating an account, an event saying that a registration happened. We put nothing in it — not your email address, not your name, nothing about your account.
- Sent: the email address and phone number you type into the form fields on the sign-in and sign-up pages. Meta reads these itself through its automatic advanced matching feature and sends them hashed; you do not have to submit the form — typing into the field is enough. The purpose is to match the person who saw an ad with the person who then signed up.
- Sent: when you click a button on those pages, the button’s text and the names of the fields in the form. Meta collects this itself too; the values you typed are not sent beyond the email and phone above, and your password is never sent under any circumstances.
- Not sent: the content of your tattoo request, the images you uploaded, your skin tone, quote amounts, your messages.
- Not sent: the contents of any form other than those two pages. The pixel does not run at all on the pages holding the quote form, the studio contact form or the profile forms, so nothing typed there is read.
- Not sent: the addresses of your share links. A shared brief is only reachable by pasting its link, so the pixel is never started on that page.
- Not sent: what you type into the search box. The pixel is not started on a page whose address carries a search term.
Changing your mind
You can change your decision at any time from the cookie preferences link in the footer. When you withdraw marketing consent the page reloads, Meta’s script is removed, and the _fbp and _fbc cookies it left behind are deleted.
You cannot switch off the strictly necessary cookies here; that takes your browser’s own settings, and signing in stops working if you do.
Third parties that set no cookie
When you open the discovery map, your browser requests the map imagery from CARTO directly. That request sets no cookie but does show your IP address to CARTO. If you never switch to the map tab, it never happens. Some profile images likewise load from wherever they are hosted.
Further reading
The Privacy Policy covers what we do with your data as a whole; the KVKK disclosure covers the notice required under Turkish data protection law.