Cookie & Local Storage Policy
Corporate Entity: Tovelu Health Technologies Private Limited β’ Effective Date: September 22, 2026 β’ Governing Jurisdictions: 230+ Sovereign Territories
πͺ 1. Executive Summary: The Local-First Storage Architecture
Unlike conventional fitness and wellness applications that continuously harvest personal behavioral telemetry, monitor users with third-party tracking beacons, and monetize private medical routines across advertising exchanges, Tovelu Health Technologies Private Limited operates on an unapologetic Local-First Architectural Paradigm.
We strictly reject the surveillance-capitalism model. Tovelu does not deploy commercial advertising tracking pixels, cross-app tracking cookies, or third-party behavioral fingerprinting libraries. Your personal biometric meal logs, circadian timestamps, and quiz responses reside client-side in your local browser sandbox (localStorage and sessionStorage). This policy outlines every single storage key we utilize, why we utilize it, and how you retain sovereign control over your device's memory.
2. Statutory Framework & Governing Legislation
This Policy is enacted in strict conformance with global electronic communications and consumer data protection statutes across more than 230 sovereign states and international jurisdictions, specifically including:
- European Union & European Economic Area (EEA): Directive 2002/58/EC (the EU ePrivacy Directive as amended by Directive 2009/136/EC) and Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR, specifically Article 5(3)).
- United Kingdom: The Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (UK PECR), as overseen by the Information Commissioner's Office (ICO).
- United States: The California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA, Cal. Civ. Code Β§ 1798.100 et seq.), the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), and Federal Trade Commission (FTC) Act Β§ 5 standards.
- Republic of India: The Digital Personal Data Protection Act, 2023 (DPDP Act 2023) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Federal Republic of Brazil: Lei Geral de ProteΓ§Γ£o de Dados Pessoais (LGPD, Law No. 13,709/2018).
- Commonwealth of Australia & Canada: The Australian Privacy Act 1988 (Cth) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
3. Technical Definitions: Cookies, Web Storage, and Cache
For statutory and technical precision under Article 5(3) of the EU ePrivacy Directive and Section 1798.140 of the CPRA:
HTTP Cookies
Small cryptographic alphanumeric text files transmitted between a web server and your client browser, automatically returned by the browser upon subsequent network requests to maintain authenticated state.
Web Storage (LocalStorage & SessionStorage)
HTML5 Web Storage APIs (window.localStorage) that store key-value data directly in your browser's persistent client sandbox without transmitting that data across HTTP headers on every server ping.
Service Workers & Cache Storage
Background browser scripts that cache static styling, application shells, fonts, and graphical brand tokens so that Tovelu loads instantaneously and operates reliably in offline or airplane modes.
IndexedDB & Cryptographic Keys
Structured client-side databases used for holding high-volume nutritional compendiums and encrypted local backups of metabolic tracking history strictly inside the client runtime environment.
4. Exhaustive Matrix of Client-Side Storage Deployed by Tovelu
Pursuant to statutory transparency mandates, below is an exhaustive inventory of every persistent client-side key, script, and storage identifier utilized across the Tovelu software environment:
| Storage Key / Identifier | Storage Type | Statutory Purpose | Duration / Retention | ePrivacy Category |
|---|---|---|---|---|
| tovelu_theme | LocalStorage | Stores visual mode preference (dark or light) to prevent visual flashing during page rendering. |
Persistent until cleared | Strictly Necessary |
| tovelu_lifetime_active | LocalStorage | Stores cryptographic authorization token indicating valid Founding Member lifetime license activation. | Persistent until cleared | Strictly Necessary |
| tovelu_access_mode | LocalStorage | Records license mode (lifetime, trial_8h, or guest) to enforce membership boundary controls. |
Persistent until cleared | Strictly Necessary |
| tovelu_trial_expires_at | LocalStorage | Timestamp marking the exact expiration millisecond for 8-hour VIP preview sessions. | 8 Hours | Strictly Necessary |
| tovelu_survey_answers | LocalStorage | Stores onboarding metabolic questionnaire responses (age, biological sex, goals, activity, diet preferences) to calculate personalized clinical daily macro targets. | Persistent until cleared | Functional / Core Health |
| tovelu_daily_meals | LocalStorage | Stores daily meal scan results, food portion items, fiber/protein/carb totals, and sequencing tags. | Persistent until cleared | Functional / Core Health |
| tovelu_active_habits | LocalStorage | Stores circadian habit completion records (morning sunlight, water intake, post-meal stroll, sleep schedule). | Persistent until cleared | Functional / Core Health |
| tovelu_dodo_checkout_url | LocalStorage | Optional test/live merchant checkout link configuration bridge. | Session / Dynamic | Commerce / Billing |
5. Categories of Technologies & The Zero Ad-Tracking Guarantee
Category 1: Strictly Necessary Storage (Exempt from Prior Consent) 100% Compliant
Under Article 5(3) of Directive 2002/58/EC and Regulation 6 of UK PECR, storage technologies whose sole purpose is facilitating communication over an electronic communications network or strictly necessary for providing an information society service explicitly requested by the subscriber do not require prior consent. Tovelu uses these keys exclusively to uphold your theme choice, prevent session disconnects, render daily macro targets, and authenticate valid lifetime licenses.
Category 2: Functional Health & Biometric Data Storage Client-Side Only
Your questionnaire responses, meal scan items, portion gram adjustments, and daily streaks are stored locally so you can access your daily protocol instantaneously without sending private medical lifestyle logs to cloud telemetry clusters. Under GDPR Article 9(2)(a) and Section 6 of the India DPDP Act 2023, you provide explicit, affirmative consent upon onboarding to allow your browser to persist these entries locally.
Category 3: Targeted Advertising, Behavioral Fingerprinting & Third-Party Cookies EXPLICIT ZERO POLICY
Tovelu deploys ZERO third-party advertising cookies, ZERO cross-site tracking pixels, and ZERO commercial data brokerage beacons. We do NOT embed Meta Pixel, TikTok Pixel, Google Ads Remarketing tags, X/Twitter Ads conversion tracking, or Criteo behavioral fingerprinting scripts. We do not participate in real-time bidding (RTB) ad exchanges. We do not monetize your metabolic struggles or private health data.
6. Third-Party Infrastructure & Merchant Processing
To maintain high availability, secure international payments, and reliable CDN asset delivery across 230+ sovereign states, Tovelu interacts with trusted enterprise infrastructure providers who may place technical cookies on their respective domains during direct interactions:
- Payment Processors (Dodo Payments & Stripe): When initiating checkout for the $197 Lifetime Pass, you may be redirected to a PCI-DSS Level 1 certified hosted payment portal operated by our payment partners. These merchant partners deploy fraud prevention, bot detection, and anti-money laundering (AML) cookies strictly necessary to process card authorizations, Apple Pay, and UPI transactions securely.
- Transactional Communications (Brevo / Sendinblue): If you provide your email to receive your protocol summary or receipt, Brevo processes transactional verification emails in compliance with standard European privacy regulations.
- Global Content Delivery Networks (Google Cloud / Cloudflare): Static JavaScript libraries, typography files, and brand icons may be served through globally distributed edge caches utilizing ephemeral performance cookies for DDoS mitigation, HTTP/2 multiplexing, and routing integrity.
7. Sovereign User Control: How to Inspect, Clear, and Disable Storage
Because Tovelu honors your absolute sovereignty over your personal data, you can audit, export, or permanently erase your client storage at any moment using standard browser tooling:
Google Chrome & Chromium (Brave / Edge)
Settings β Privacy and Security β Cookies and other site data. Or press F12 β Application tab β Local Storage β Clear site data.
Apple Safari (macOS & iOS)
Preferences (or iOS Settings β Safari) β Advanced β Website Data β Search for "tovelu.com" β Remove All.
Mozilla Firefox
Settings β Privacy & Security β Cookies and Site Data β Clear Data, or use Storage Inspector (Shift+F9).
Consequences of Clearing Storage
Clearing LocalStorage will reset your theme preference, clear active meal entries, and require you to restore your license key via your purchase confirmation email.
8. Global Privacy Control (GPC) & Do Not Track (DNT) Compliance
Pursuant to Cal. Code Regs. tit. 11, Β§ 7025 (California Consumer Privacy Act Regulations), Tovelu natively recognizes and honors automated universal opt-out preference signals emitted by user-agents, specifically the Global Privacy Control (GPC) HTTP header and JavaScript DOM properties (navigator.globalPrivacyControl === true).
Because Tovelu engages in zero selling, zero cross-context behavioral advertising, and zero data rental, our baseline architecture is permanently pre-configured to the highest privacy tier demanded by GPC and Do Not Track (DNT) standards worldwide.
9. Territorial Statutory Schedules
European Union (GDPR) & United Kingdom (UK GDPR / PECR)
You have the statutory right under Chapter III of the GDPR to access, rectify, restrict processing of, and erase your personal data. Because Tovelu stores core health variables locally on your hardware, you can exercise your Right to Erasure (Article 17) directly and autonomously by wiping your browser storage without waiting for corporate processing cycles.
California & United States Residents (CCPA / CPRA)
Under Cal. Civ. Code Β§ 1798.120 and Β§ 1798.121, you have the right to opt-out of the "sale" or "sharing" of personal information and to limit the use of sensitive personal information. Tovelu explicitly confirms: We do not sell your personal data. We do not share your personal data for cross-context behavioral advertising. We have not done so in the preceding twelve (12) months.
Republic of India (DPDP Act 2023)
In accordance with the Digital Personal Data Protection Act, 2023, you have the right to access a summary of personal data processed, seek correction or erasure, and register grievances with our Data Protection & Grievance Redressal Officer. Processing is conducted strictly pursuant to lawful purpose and informed digital consent.
10. Policy Modifications & Periodic Review
Tovelu reserves the right to update or amend this Cookie and Local Storage Policy periodically to reflect technological evolutions, product architecture improvements, or updates to international statutory directives. Any material modifications will be reflected with a revised "Effective Date" at the apex of this document. Continued engagement with Tovelu software following the posting of modifications constitutes acknowledgement of such revisions.
11. Contact the Data Protection & Grievance Officer
If you have technical questions regarding client storage mechanics, data sovereignty, or wish to register an inquiry regarding this Policy, please contact our designated privacy team:
Corporate Entity: Tovelu Health Technologies Private Limited
Office: Data Protection & Regulatory Compliance Department
Email for Cookie & Privacy Matters: legal@tovelu.store
General Support & Account Inquiries: contact@tovelu.store
Response Commitment: Statutory inquiries are acknowledged within 24 to 48 hours.