Cookie Policy
Last updated: July 17, 2026 — Version 1.2
This policy explains how picto-flow uses cookies and similar technologies on the picto-flow website and application (the "Service"). It complements our Privacy Policy.
1) Who is responsible?
Data controller: Timothée Miminoshvili, sole proprietor (trade name TEL-MI Labs) — 72 rue de Dantzig, Hall 14, 75015 Paris, France — SIREN 847 659 216 — Contact: contact@pictoflow.com
Data protection contact: Timothée Miminoshvili — dpo@pictoflow.com.
2) What is a cookie?
A cookie is a file stored on your device (computer, mobile, etc.) that allows information to be stored or retrieved. Other trackers may work similarly (localStorage, IndexedDB, SDK).
3) What picto-flow uses — and does not use
picto-flow only uses trackers that are strictly necessary for the Service to work.
- ❌ No audience measurement (no Google Analytics or equivalent tool)
- ❌ No advertising or marketing tracker
- ❌ No profiling
In accordance with article 82 of the French Data Protection Act, trackers that are strictly necessary to provide the service you request are exempt from consent: this is why picto-flow shows a simple information banner on your first visit, without asking you to make any choice — there is nothing to accept or refuse.
If we were ever to introduce a tracker subject to consent, your consent would be collected before anything is set, and this policy would be updated.
4) Strictly necessary trackers used
| Tracker | Purpose | Duration |
|---|---|---|
| Authentication session (localStorage, Supabase) | Keep you signed in to your account | Until logout |
| Information banner memory (localStorage) | Avoid showing the banner again on every visit | 6 months |
| Display preferences (localStorage) | Theme, font, display size, timer settings — set by you | Until deletion |
| Technical device identifier (localStorage) | Synchronize your data across your devices | Until deletion |
| Discovery mode data (IndexedDB) | Run the Visitor mode, without an account, entirely on your device | Until deletion |
| Parental lock (localStorage) | Remember the Parental Gate mode on the device | Until deletion |
Anti-bot protection (Cloudflare Turnstile cookies, e.g. __cf_bm) |
Secure sensitive forms (sign-up, sign-in, account deletion) | About 30 minutes |
These trackers are never used to track you for advertising or statistical purposes.
5) Your means of control
- Browser settings: you can block or delete cookies and local storage — the Service may then stop working properly (unable to stay signed in, lost preferences).
- This policy can be accessed at any time from the website footer.
6) Transfers outside the European Union
The anti-bot protection (Turnstile) is provided by Cloudflare, a company established in the United States: the minimal technical data it processes is governed by the European Commission's standard contractual clauses and/or its certification under the EU–US Data Privacy Framework. All other trackers listed above stay on your device or within the European Union.
7) Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection — details and procedures in our Privacy Policy.
8) Contact and complaints
- General questions: contact@pictoflow.com
- Exercising GDPR rights: via the GDPR Portal
- Complaint: to the CNIL (www.cnil.fr)
9) Updates to this policy
This policy may be updated to reflect changes in our practices, new legal requirements, or the addition of new services. You will be notified of significant changes via the website or by email.
Version history:
- 1.0 (December 2024) - First GDPR/CNIL compliant version
- 1.1 (July 2026) - Real data controller, marketing section aligned with actual trackers
- 1.2 (July 2026) - Aligned with actual trackers: removal of audience measurement and of irrelevant categories, information banner (strictly necessary trackers only), actual transfers
Last updated: July 17, 2026