Privacy choices
Necessary onNecessary cookies are active. Optional analytics stays off unless you choose otherwise.
Legal & Compliance
US-only notice. Four tiers — Required, Insights, Financial Sharing, Marketing — with denied-by-default GTM/GA4/Clarity and GPC honored as opt-out. Finance-web loads zero ad trackers. TEMPLATE — requires counsel approval.
This Cookie Policy supplements the Privacy Policy at /legal/privacy and Terms at /legal/terms for US residents 18+ using USD only. It implements the four-tier model from docs/plans/legal/financial-privacy-enforcement.md: Tier 1 Required and Bank Security (always active, locked), Tier 2 Financial Insights and Analytics (opt-in, zero-PII), Tier 3 Third-Party Financial Data Sharing (opt-in, no partners in this release), Tier 4 Advertising and Marketing (opt-in, denied by default). Marketing-web (public landing, product, pricing, compare, tools, contact) enforces all four tiers. Finance-web, iOS, and Android (authenticated ledger with Plaid data) enforce Tier 1 plus optional Tier 2 only and never load Tier 4 tags. Admin console loads no marketing tags. Your selection is stored in voyager_consent for 365 days; changing browsers or clearing storage resets you to necessary-only. Continued browsing of marketing-web without changing settings keeps Tier 2–4 off except where GPC handling below applies.
Strictly necessary first-party storage required for security and to remember your choice: voyager_consent (first-party cookie, 365-day lifespan, values necessary-only, analytics-permitted, or marketing-permitted, flags SameSite=Lax and Secure), Supabase auth session and refresh cookies (HttpOnly, Secure, SameSite=Strict, Path=/), anti-CSRF and Plaid link state nonces (short-lived, cleared after exchange or expiry), Next.js routing cache and theme/font initializers (functional, no cross-site IDs). Tier 1 contains no advertising IDs, no financial dollar amounts, and no sale/share signals. The toggle for Tier 1 is permanently locked to Active because logout revocation, CSRF defense, and consent memory cannot function without it. Blocking Tier 1 in your browser will break sign-in, connection flows, and consent persistence and will cause repeated prompts. Content Security Policy restricts script and frame sources to wyna.app, Supabase, Plaid — and, only after Tier 4 consent, the analytics vendors listed in Section 5.
Tier 2 covers privacy-preserving product telemetry on both marketing-web and finance-web, off by default until you permit analytics. When enabled, we collect only coarse operational metrics such as chart_type net_worth, render_time_ms, item_count, route-level error counts, and API latency buckets via our consent-aware analytics helper in src/web/packages/analytics and observability wrappers. Payloads must never include transaction amounts, merchant descriptions, account masks, security symbols, email addresses, or user IDs; server OpenTelemetry traces strip authorization headers and financial request bodies before export. Disabling Tier 2 immediately drops client beacons before dispatch and samples out server traces for your session, with no degradation to ledger, budgets, or exports. Tier 2 is distinct from Tier 4 advertising — enabling insights never enables GTM ad_storage, Clarity heatmaps, or affiliate pixels. You can toggle Tier 2 in the consent banner, at /legal/cookies#manage, and in finance-web Settings under Data and Privacy, with changes synced to POST /api/user/consent context financial_privacy_preferences where applicable.
Tier 3 governs any future sharing of financial data with affiliates, loan-rate widgets, savings offers, credit estimators, valuation providers, or anonymized intelligence feeds under GLBA and state laws. In this US-only release there are zero Tier 3 partners: no affiliate embeds load, no offer APIs are called, and no financial payloads leave the Plaid/Supabase/Stripe boundary for marketing. If partners are introduced, they will render behind a FinancialPartnerGate placeholder while Tier 3 is off, and backend jobs will filter out users with FinancialDataSharingOptedOut true before matching offers. Core Plaid linking remains a first-party user-directed service under your separate Aggregation Authorization and is unaffected by Tier 3 state — declining partner sharing never blocks connecting your own bank or viewing your own ledger. Any Tier 3 launch will require a new versioned Privacy Policy, a re-consent event, updated data map and vendor DPAs, and counsel approval before a single partner script is allow-listed in CSP.
Tier 4 is off until you choose marketing-permitted. Only then do we store voyager_attrib (first-party cookie plus localStorage, 30-day lifespan, campaign UTMs utm_source, utm_medium, utm_campaign, gclid, and referral codes only, XSS-sanitized, never email or financial figures) and load Google Tag Manager with Consent Mode v2 default-denied then update-to-granted, GA4 with anonymize_ip and minimal retention, Microsoft Clarity with Consent API v2, and privacy-friendly Plausible/PostHog where configured. Zero pre-consent tracking: no ad script, iframe, pixel, or heatmap loads while Tier 4 is off; gtag consent defaults stay denied for ad_storage, ad_user_data, ad_personalization, and analytics_storage. If Tier 4 is declined, UTM parameters are used only in-memory for session routing and are never persisted or sent to ad networks. Accepting Tier 4 on marketing-web may constitute CCPA Sale/Sharing — use Your Privacy Choices below or GPC to opt out anytime, which flips you back to denied and purges Tier 4 loads on next navigation.
For transparency, the complete inventory is: voyager_consent (first-party, 365 days, consent tier); voyager_attrib (first-party cookie and localStorage, 30 days, UTMs/referral only with consent); Supabase sb-access/sb-refresh session cookies (HttpOnly, session to 30 days per auth settings, Tier 1); Plaid link_token and state nonce plus Plaid Link state (minutes to hours, Tier 1, never agreement text or tokens in persistent cookies); Plausible/PostHog first-party events (only with Tier 2/4 per configuration, no cross-site IDs); Clarity _clck (1 year) and _clsk (1 day) strictly gated behind Tier 4; GA4 _ga (up to 2 years), _ga_container (15 minutes), _gcl_au/gclid (90 days) strictly gated behind Tier 4 with denied defaults; GTM dataLayer in-memory only (no persistent ID). We deploy no Flash cookies, WebSQL, IndexedDB trackers, fingerprinting, Meta/TikTok/LinkedIn pixels, or social widgets in this release. Material additions trigger a refreshed consent prompt and a new lastUpdated date.
You control all non-essential tiers at any time: use the bottom-viewport consent banner, visit /legal/cookies#manage, click Cookie preferences in the footer, clear browser storage to reset to necessary-only, or email privacy@wyna.app with subject Opt-Out. If we detect Global Privacy Control (Sec-GPC: 1) or Do Not Track (DNT: 1), we treat it as an opt-out of sale/share and Tier 4: voyager_attrib is not written, denied defaults are kept, and partner/tag loads are suppressed without manual action. Finance-web, iOS, and Android never load GTM, GA4, Clarity, or ad pixels regardless of marketing-web Tier 4 state — they honor only Tier 1 plus Tier 2 insights with zero-PII scrubbing, enforced by CSP and the shared analytics package. Cross-domain linkage between marketing IDs and financial ledger IDs is prohibited. Withdrawing Tier 4 stops future marketing collection but does not delete finance ledger data — use export/deletion in Settings or contact privacy@wyna.app per the Privacy Policy. This is a TEMPLATE — do not publish until counsel approves vendor list, lifespans, GPC handling, and US-only scope.
Cookie consent · Privacy ledger
Current tier: necessary
voyager_consent · 365 days · denied-by-default