Privacy & cookies
This notice covers Baarcha’s sign-in records, cookies and optional first-party audience measurement. You can use the product without enabling analytics.
Account and security information
Google sign-in provides your account identifier, email, name and profile picture. We record sign-in times, browser family and major version, operating-system family and device category to operate accounts and investigate access issues. Active sessions record creation and last-use times.
When trusted network capture is configured, sign-in records include an IP address encrypted at rest and an approximate country, region and city. Authorized admins can view the IP for up to 30 days. We do not collect precise GPS or a full browser fingerprint. Security recording is separate from the optional analytics switch.
IP location is looked up in a local database; your IP is not sent to a geolocation API. It may reflect a VPN, mobile gateway or proxy rather than where you live. Local/private addresses cannot be geolocated, and older records cannot be reconstructed. IP geolocation by DB-IP (City Lite, CC BY 4.0).
Optional audience analytics
Only after you accept analytics, a first-party visit cookie groups activity for 30 minutes. We count broad page categories, visits, referring domains, campaign labels, device/browser categories, browser language and time zone. The random visit identifier is not an account identifier or a cross-day person identifier. If you sign in, the referring domain, landing category and campaign can separately be attached to your account.
Visitor analytics does not store IPs, full URLs, query contents, private project IDs, conversation text, precise coordinates or advertising profiles. Private app and admin pages are excluded from page measurement. Browser language and time zone are preferences, not verified location. GPC and Do Not Track signals disable optional measurement.
Cookies & browser storage
punicas_platform: necessary, HttpOnly account session; up to 30 days, invalid after seven days idle.__Host-baarcha_oauth: necessary, temporary Google sign-in security check; 10 minutes.baarcha_consentandbaarcha:analytics-choice:v2local storage: necessary to remember your cookie choice; 90 days.baarcha_visit: optional, signed HttpOnly visit cookie; 30 minutes without extending its lifetime on each page.baarcha:visit-source:v2session storage: optional visit attribution in this tab; 30 minutes.__Host-baarcha_source: optional attribution while signing in; 10 minutes, cleared when the callback completes.
Other product storage, such as your language, chat drafts and settings, supports features you use and is not read for audience measurement. Google’s own sign-in page is governed by Google’s policies. We do not load third-party advertising trackers through these analytics tools.
Retention and access
Encrypted sign-in IPs expire after 30 days. Detailed sign-in records, signup attribution and optional visit reports expire after 90 days; administrative action records after one year. Expired data is removed by scheduled cleanup; expired IPs are withheld from admin responses even before cleanup runs. Administrative records contain operator, target, reason and outcome—not session tokens or API secrets.
Reports are restricted to authorized administrators. Rejecting analytics stops future optional collection, clears visit-source storage and requests deletion of the current visit record and cookie. It does not automatically delete earlier visits whose cookies have expired, account-linked signup attribution or security records. For access, deletion or other questions about your data, contact [email protected].