Cookie Policy
This page individually lists every cookie and similar storage mechanism (including localStorage) actually used by yazar.io. It is not a generic template list - a category not used in the product (e.g. marketing cookies) is not shown here as if it existed.
Last updated:
Categories
The four categories below follow the distinction used in the Turkish Data Protection Authority's Cookie Guidance. yazar.io currently has no cookies or similar storage items for MARKETING purposes - that category does not appear in the table below, and is not presented as if it existed.
- Strictly Necessary: required for the service to function; cannot be turned off.
- Preference / Functionality: remembers user choices like language/theme.
- Analytics: helps us understand how the product is used.
- Support / Live Chat: only loaded when you deliberately click the "Message us" button; never loaded on page load.
- Marketing: no cookies in this category are currently used on yazar.io.
Cookies and storage items in use
The table below lists every cookie/localStorage item that genuinely exists in the codebase as of the date this document was published.
Changing your preference
You can change your language preference anytime from the Language selector on the /ayarlar (Settings) page. You can change your theme preference from the theme toggle in the interface. Both instantly update the relevant cookie/localStorage item.
You can change your analytics consent at any time: use the "Cookie Preferences" link at the bottom of the page, or (if signed in) the "Manage Cookie Preferences" button on the /ayarlar page. If you withdraw consent, PostHog's data in your browser AND the yzr_attr "first-touch" cookie are cleared, and no further data is sent to either PostHog or Google Analytics.
You can clear all cookies/localStorage from your browser settings at any time; this affects everything, including strictly necessary cookies, and may sign you out.
Contact
For questions about this policy: support@yazar.io
| Name | Provider | Purpose | Category | Duration | Party | Legal basis |
|---|---|---|---|---|---|---|
| sb-<project-ref>-auth-token | Supabase (our first-party infrastructure provider) | Keeps your session (signed-in state) secure. | Strictly Necessary | Session duration + automatic refresh (Supabase default) | First-party (managed by Supabase on our behalf) | No consent required - necessary to provide the service (sign-in-gated areas). |
| locale | yazar.io | Remembers your interface language (Turkish/English). | Preference / Functionality | 1 year | First-party | No consent required (functional preference cookie). |
| theme (localStorage) | yazar.io / next-themes | Remembers your light/dark theme choice in your browser. Never sent to the server. | Preference / Functionality | Until you or your browser clears it | First-party | No consent required (browser-only preference, never transmitted). |
| cookie_consent | yazar.io | Remembers your cookie preference (whether you allow analytics cookies). | Strictly Necessary | 180 days | First-party | No consent required - a consent mechanism needs to remember this choice to function at all. |
| ph_<project-key>_posthog (localStorage / cookie) | PostHog | Stores an identifier that links your browser across visits for anonymous/identified product analytics. Autocapture, session recording, and heatmaps are all DISABLED - page views are sent only manually and in a restricted form (no query parameters, personal URL portions reduced to a template). | Analytics | PostHog default (long-lived, e.g. ~1 year) | Third-party (PostHog, hosted in the EU region) | Your explicit consent - only loaded if you've actively approved Analytics via "Accept All" or "Customize Preferences" in the cookie banner. |
| yzr_attr | yazar.io | Remembers, one time, which source/campaign you arrived from when you first visited the site (campaign parameters, the domain of the site that referred you, the first page you opened) - used for "first-touch" attribution. | Analytics | 30 days | First-party | Your explicit consent - only written if you've approved Analytics in the cookie banner; cleared if you withdraw consent. |
| _ga / _ga_<container-id> | Google Analytics (GA4) | Stores an identifier that links your browser across visits for anonymous visit/page-view statistics. | Analytics | Google Analytics default (e.g. ~2 years for _ga) | Third-party (Google) | Your explicit consent - only loaded if you've actively approved Analytics via "Accept All" or "Customize Preferences" in the cookie banner. |
| Crisp (client.crisp.chat cookies / localStorage) | Crisp (Crisp IM SAS) | Used to deliver your messages and run the chat session when you start a live support chat. | Support / Live Chat | Crisp's own default duration (not separately configured by yazar.io) | Third-party (Crisp) | Not loaded automatically - only loaded when you deliberately click the "Message us" button in the bottom-right corner, as a result of an action you initiated yourself. |