This will be short, because there is not much to tell.
The app (app.thelittertray.app)
The app itself puts ten things in your browser, listed below so you can check them against your browser's own list. Five are essential cookies. Four remember choices: your colour-vision palette, theme, last Google sign-in account and dismissal of a failed-payment notice. One records your analytics choice, and is set only after you accept or decline the banner, when analytics is switched on. All ten are first-party: they are set by us for this app. If you accept analytics, Google Analytics then sets its own cookies, named _ga and _ga_ followed by our property id, and we set one session-storage marker named ltr_ga4_app_session that lasts until you close the tab. Those are listed below too. If you later decline, we delete the Google cookies from your browser.
| Name | What it is for | Kind | How long it lasts |
|---|---|---|---|
__Host-littertray_session |
Keeps you signed in. | Cookie, essential | Your browser session. The sign-in itself also ends after a period of inactivity, and again at a fixed maximum age, whichever comes first. |
__Host-littertray_login_csrf |
Proves that a form you sent us came from a page we gave you: the sign-in, contact, invitation and Google sign-in forms. | Cookie, essential | Your browser session, and cleared the moment you are signed in. |
__Host-littertray_google_state |
Ties a Google sign-in back to the browser that started it. | Cookie, essential | 10 minutes, and cleared as soon as you come back from Google. |
__Host-littertray_tier_intent |
Remembers the paid tier you chose long enough to carry that choice through Google sign-in and setup. | Cookie, essential | 10 minutes, and cleared as soon as the Account page uses it. |
__Host-littertray_oauth |
Does the same job for connecting your YouTube channel. | Cookie, essential | 10 minutes, and cleared as soon as the connection finishes. |
__Host-littertray_google_account |
Remembers which Google account you last signed in with, so coming back does not start at the account picker. It holds the account identifier Google gave us, never your email address. | Cookie, preference | 90 days, or until you sign out, or until you choose a different Google account on the sign-in page. |
__Host-littertray_vision |
Remembers the colour-vision palette, if you switch to it, so every page can wear it as soon as it arrives. | Cookie, preference | Until you change it or clear your cookies, up to 400 days. |
__Host-littertray_payment_notice_dismissed |
Remembers that you put down the notice about a payment that did not go through. | Cookie, preference | Until you close your browser. |
littertray-theme |
Remembers the light or dark theme you pick with the button in the corner. | Local storage, preference | Until you change it or clear your browser storage. |
__Host-ltr_consent |
Remembers whether you accepted or declined analytics cookies, so we do not ask on every page and so Google Analytics does not run unless you accepted. | Cookie, analytics | 12 months, or until you change your choice from Analytics choices in the footer. |
| Name | What it is for | Kind | How long it lasts |
|---|---|---|---|
_ga, _ga_[id] |
Set by Google Analytics after you accept, to tell one visit from the next. Nobody else receives them. | Cookie, analytics | Up to 13 months, or deleted the moment you decline. |
ltr_ga4_app_session |
Marks that this browser tab has already sent its first analytics page view. | Session storage, analytics | Until you close the tab. |
The five essential cookies let the server sign you in, protect forms and remember the paid tier you asked to see after setup. The colour-vision cookie lets the server apply your chosen palette before the page appears. Your theme stays in local storage and is never sent to us. The Google account cookie remembers your last sign-in for up to 90 days, so we can offer that account next time; signing out or choosing "Not you?" clears it. It holds Google's account identifier, not your email address, and sends that identifier back to Google as a sign-in hint. The payment-notice cookie remembers your dismissal until you close your browser.
24 August 2026. The cookie that proves a form came from us used to name the join form among the pages that set it: "the sign-in, join, contact and Google sign-in forms." Join was the public waiting-list form. That form closed on 23 August 2026. The cookie is still set for sign-in, contact, invitation acceptance and Google sign-in.
One name you may see that is deliberately not in the table: __Host-littertray_invite. Nothing sets it. It belonged to an older invitation flow, and the only thing the app still does with it is send the instruction that deletes it, so its name can go past in a response header while holding nothing at all. It is here because a list that claims to be complete should explain the name you can see rather than leave you to wonder.
That is the complete list. No advertising cookies. No third-party cookies except Google Analytics after you accept, which never runs unless you said yes.
The marketing site (thelittertray.app)
The marketing site remembers the light or dark theme you choose with the button in the corner, kept in your own browser's local storage exactly as the app keeps it. If analytics is switched on for this installation, the same first-party consent cookie and banner you meet in the app also appear here. Google Analytics then runs only after you accept.
The site sits behind Cloudflare, which answers the connection before it reaches our server; the Privacy Policy's provider table sets out what Cloudflare sees. Some of Cloudflare's optional protections set a cookie of their own. Ours are not doing that. The only first-party cookie this site sets is __Host-ltr_consent, and only after you accept or decline analytics.
The analytics banner
Essential and preference cookies do not need a banner. The analytics cookie does. When the operator has pasted a Google Analytics measurement id, you see a banner asking you to accept or decline. Declining is one click and is remembered. Analytics choices in the footer re-opens the banner. If no measurement id is set, there is no banner and Google Analytics does not load.
If this changes
If we add any analytics or any third-party cookie, we will update this notice before it happens, say exactly what was added and why, and add a consent mechanism if the law requires one.
Questions: office@thelittertray.app.
