Cookie Notice
This Cookie Notice explains how Novato Labs Ltd (doing business as Novato Labs) ("we," "us," or "our") uses cookies and similar technologies when you visit https://trylooksi.com, use the Looksi web app, or use the Looksi mobile app (together, the "Services").
It explains what these technologies are, why we use them, and the choices you have. It should be read alongside our Privacy Notice, which describes everything else we do with your personal information.
If you have any questions, email us at privacy@novatohq.com.
THE SHORT VERSION
- We do not use advertising cookies, and we do not use cookies to build a profile of you or to follow you across other websites.
- We do not sell or share your information with advertisers or data brokers.
- We do not use session replay or screen recording anywhere in the Services.
- Every cookie we set is strictly necessary to sign you in and keep the Services secure. Because of that, we do not ask you for cookie consent, and you will not see a cookie banner. If that ever changes, we will ask you before setting any non-essential cookie.
- The Looksi mobile app does not use cookies at all. It uses secure storage on your device, which is explained in section 5.
1. WHAT ARE COOKIES AND SIMILAR TECHNOLOGIES?
A cookie is a small text file that a website asks your browser to store on your device. Cookies are widely used to make websites work, to keep you signed in, and to protect against certain kinds of attack.
Cookies set by the website you are visiting are called first-party cookies. Cookies set by a different company are called third-party cookies.
Cookies that last only until you close your browser are session cookies. Cookies that stay on your device until they expire or you delete them are persistent cookies.
Similar technologies include web beacons and pixels, which are tiny images or scripts used to detect that a page or email has been opened, and local storage, which lets a site or app store data on your device. Section 4 explains which of these we use, and section 5 explains what the mobile app stores.
2. COOKIES ON OUR MARKETING WEBSITE
Our public marketing pages, which are the home page, pricing, FAQ, this notice, our Privacy Notice, and our Terms of Service, do not set any cookies. There is no analytics, no tag manager, no advertising pixel, and no tracking script on those pages.
3. COOKIES IN THE WEB APP
The cookies below are set when you sign in to or use the Looksi web app. All of them are first-party cookies, all are strictly necessary, and none are used for analytics or advertising.
Cookie names may appear with a __Secure- or __Host- prefix. That prefix is a browser security feature and does not change what the cookie does.
| Cookie | Purpose | Type | How long it lasts |
|---|---|---|---|
next-auth.session-token | Keeps you signed in and identifies your session. Without it you would be signed out on every page load. | First-party, strictly necessary | 7 days |
next-auth.csrf-token | Protects against cross-site request forgery, which is an attack that tries to make your browser perform actions on your account without your knowledge. | First-party, strictly necessary | Session, deleted when you close your browser |
next-auth.callback-url | Remembers the page you were on so we can return you there after you sign in. | First-party, strictly necessary | Session, deleted when you close your browser |
next-auth.state | Set only while you are signing in with Google. Ties the response from Google to the sign-in you actually started. | First-party, strictly necessary | About 15 minutes |
next-auth.pkce.code_verifier | Set only while you are signing in with Google. Part of the PKCE security exchange that prevents an intercepted sign-in code from being used by someone else. | First-party, strictly necessary | About 15 minutes |
sessionid | Signs in staff to our administration tools. It is set on our API domain and is not used for normal accounts. | First-party, strictly necessary | 2 weeks |
csrftoken | Cross-site request forgery protection for our API and administration tools. | First-party, strictly necessary | 1 year |
4. WEB BEACONS AND PIXELS
We do not use web beacons, tracking pixels, or clear GIFs on our website, in the web app, or in our emails. We do not track whether you have opened an email we send you.
5. THE MOBILE APP DOES NOT USE COOKIES
The Looksi mobile app is not a web browser and does not use cookies. It does store information on your device, and it does send us diagnostic and product analytics data. Here is exactly what that means.
Stored on your device. The app uses your device's secure storage to hold your sign-in token, so you are not asked to sign in every time you open the app, along with a small amount of app state such as your onboarding progress, your saved scan preference, and a cached copy of your plan allowance. This information stays on your device and is removed when you sign out or delete the app.
Analytics. We use PostHog to understand how the app is used, for example which screens people visit and where they get stuck. It is hosted in the European Union. It is linked to your account identifier so we can tell one person's journey from another's, but we do not send it your name or your email address, and it never receives your photographs. Session replay is switched off. We use this to fix problems and decide what to build next, not to advertise to you.
Crash reporting. We use Sentry to receive a report when the app crashes or hits an error, so we can fix it. It is configured not to send personal information, and its session replay is also switched off.
No advertising identifiers. The app does not use your device's advertising ID, does not ask for permission to track you across other companies' apps and websites, and contains no advertising software.
6. COOKIES SET BY OTHER COMPANIES
When you sign in with Google, Google sets its own cookies on its own sign-in pages. Those cookies are controlled by Google, not by us, and are governed by Google's privacy policy. We receive only the account information described in our Privacy Notice.
If you buy a subscription through our website, payment is taken on a secure checkout page hosted by Stripe. Stripe sets its own cookies on that page to process the payment and to detect fraud. Those cookies are controlled by Stripe and are governed by Stripe's privacy policy. We never see or store your full card details. Subscriptions bought inside the mobile app are handled by Apple or Google and do not involve cookies.
7. HOW TO CONTROL COOKIES
Because the cookies we use are strictly necessary, there is nothing here to switch off in a preference center, and blocking them will stop you from signing in.
You can still control cookies through your browser. Most browsers let you see the cookies stored on your device, delete them, and refuse new ones. If you block or delete our cookies, you will not be able to stay signed in to the web app, and some parts of it will not work.
Instructions for the main browsers:
For the mobile app, you can clear everything stored on your device by signing out or deleting the app. If you want us to stop processing your analytics data, or you want it deleted, email privacy@novatohq.com and we will handle it as a privacy request under our Privacy Notice.
8. DO NOT TRACK
Some browsers offer a "Do Not Track" setting. There is still no agreed standard for how websites should respond to it, so we do not respond to it. This makes no practical difference to you, because we do not track you across other websites or apps in the first place.
9. YOUR PRIVACY RIGHTS
Information collected through cookies and the technologies described here may be personal information. Your rights over it, including your rights to access it, correct it, and have it deleted, are set out in full in our Privacy Notice.
10. CHANGES TO THIS NOTICE
We may update this Cookie Notice, for example if we start using a new technology or change how an existing one works. The date at the top shows when it was last revised. If we ever introduce a cookie that is not strictly necessary, we will ask for your consent before it is set.
11. HOW TO CONTACT US
If you have questions about this notice, email us at privacy@novatohq.com.