Cookie Policy
Last updated: October 2, 2026
Service: Cocuyo (cocuyo.ai), an AI audiovisual creation Studio. This policy also covers previous Cine access and subscriptions.
Responsible party: Cocuyo LLC (Homestead, Florida, United States)
Contact: hola@cocuyo.ai
This policy is short on purpose: Cocuyo uses its own cookies and storage that are necessary so the account and the app work and, in addition, the measurement described in points 4 to 6: Google Analytics, Google Ads (on premiere and payment confirmation pages) and the Meta and TikTok pixels.
PostHog counts visits and verified purchases without cookies, storage on your device or person profiles. It works without prior acceptance and stops if you choose “No, thanks”, as explained in section 4.1.
1. What is a cookie?
A cookie is a small text file that a website stores in your browser to remember something between one visit and the next. It isn’t a program: it can’t read your files or install anything on your device.
2. Cookies we use (own and measurement)
| Name | Purpose and duration |
|---|---|
| cocuyo_sesion | Keeps you signed in securely. Lasts for the session or, if you mark «remember me», up to 30 days. It’s HttpOnly, Secure, and SameSite. |
| cocuyo_dispositivo | Safely recognizes this browser to apply the screen limit. It’s HttpOnly, Secure, and SameSite; lasts up to one year. |
| cocuyo_app | Indicates that Cocuyo is being used as an installed app to adapt technical functions of the PWA. It contains no identity or advertising. |
| cocuyo_ios | Indicates that Cocuyo runs inside the native iPhone app, to adapt technical features and prevent Stripe web checkout inside that app. It does not enable Apple purchases by itself. It is technical, lasts 6 hours, and contains no identity or advertising. |
| cocuyo_consentimiento | Saves your choice to accept or reject measurement so the browser and server respect the same decision. It’s necessary to remember the preference; lasts up to one year. |
| cocuyo_origen | Remembers which link you came from the first time (the campaign tag or the site domain that brought you) so we know which channels work. It’s only created if you accept measurement and lasts 90 days. |
| cocuyo_click_google | Remembers the latest Google ad click identifier for 30 days, only if you accept measurement. It links the click to a payment without loading Google Ads inside the Studio. It is deleted when you withdraw consent. |
| _fbp / _fbc | It’s set by the Meta pixel (point 5) to measure whether an ad ended up in a paid subscription or credit top-up. They’re not on Sign In or Create. Lasts up to 90 days. |
| _ttp | It’s set by the TikTok pixel (point 6), for the same purpose as Meta’s: to know whether an ad ended up in a subscription. It’s also not on Sign In or Create. Lasts up to 13 months. |
| cocuyo_idioma | We remember your language choice (Spanish or English) for one year. This is a functional preference, not a tracker. When you are signed in, we also save it to your account for emails. |
Cocuyo also uses its own local storage for interface preferences, the PWA’s technical progress, and features like support. It isn’t used to track you on other sites.
3. What we DO NOT use
- No sale of your data.
- No pixel on Sign In or Create (the login wall and Studio don’t measure ads).
Yes, we measure what you see inside Cocuyo, and starting August 28, 2026, part of that measurement is done by Google Analytics 4 (see point 4). We use it in analytics-only mode: without ad signals, without remarketing, and without ad personalization. Starting August 29, 2026, we also use the Meta pixel to know whether an ad ended in a Stripe payment (point 5). We don’t sell your data.
4. Google Analytics
Starting August 28, 2026 we use Google Analytics 4 (measurement identifier G-5R06EQPPYD) to find out how many people enter, which pages they view, and what worlds they see. It helps us decide what to produce.
Google sets two cookies of its own: _ga and _ga_<identifier>, which last up to two years and are used to distinguish visitors and sessions. Google acts as the data processing operator on behalf of Cocuyo.
What we intentionally turned off: Google’s ad signals across the whole web, with one exception: on the premiere and payment confirmation pages (pago-confirmado.html) Google Ads (identifier AW-18406766680) measures whether an ad ended up in a subscription or credit top-up confirmed by Stripe; for that it grants ad_storage and ad_user_data only on those pages after accepting measurement, with no ad personalization. Outside of that, we also turn off remarketing, demographic reports, and ad personalization. Your browsing data in Cocuyo does not feed advertising campaigns, ours or anyone else’s.
If you don’t want to be measured: you can install the Google Analytics disabling add-on, turn on your browser’s tracking protection, or block cookies from this site. None of this breaks Cocuyo: you’ll still be able to view and create normally.
Google Analytics, Google Ads, Meta and TikTok only activate when you accept measurement. PostHog runs in memory without prior acceptance and stops upon an explicit refusal. Accepting the Terms and reading Privacy when creating an account do not accept campaign measurement.
The measurement notice lets you accept or refuse with one click and saves your choice. It does not appear automatically in Studio, Sign In, Profile or the legal pages. You can change your choice from this page or “Your data” in your profile. Choosing “No, thanks” withdraws optional measurement and also stops PostHog.
4.1. PostHog
Since September 9, 2026, we use PostHog to measure web page visits and subscription or credit purchases confirmed by Stripe. Campaign tags let us relate a visit and purchase to the originating ad.
Since September 24, 2026 it works without cookies or storing anything on your device: data lives only in page memory while you visit, no person profiles are created and your location is not used. It therefore works without asking for permission; if you choose “No, thanks” in the notice or on this page, sending stops. It does not load inside the iOS or Android apps. It does not record sessions or collect form fields, emails, prompts, private files or access links. The page address is sent without parameters or fragments; the payment identifier is hashed.
PostHog no longer uses cookies (it previously used one with the ph_phc_ prefix and the cocuyo_ph_origen tag; both are deleted automatically on your next visit). Only if you accept campaign measurement do we use session storage to avoid counting the same purchase twice. The project is hosted in PostHog’s United States region.
5. Meta Pixel
Only if you accept measurement, since August 29, 2026 we use the Meta pixel (identifier 1577380453882195) to measure ad campaigns: visits to cocuyo.ai pages (homepage, profiles, player, profile, and legal and payment confirmation pages; never on Sign In, Create, Support, Recover, or the account deletion page) and, only when Stripe confirms a charge, the standard event Purchase (amount in USD and payment session identifier). That event does not fires when creating an account, when requesting a magic link, or when entering an access code.
The Pixel is not on enter.html or on create.html. If a payment is completed and the browser blocks the pixel, the server can notify Meta on its own (Conversions API) using the same identifier, so it doesn’t count twice. The token for that API isn’t sent on the page.
If you don’t want Meta to measure you: turn on your browser’s tracking protection, use an ad blocker, or delete the cookies from this site. You’ll still be able to view and create normally.
6. TikTok Pixel
Only if you accept measurement, since August 29, 2026 we also use the TikTok pixel (identifier DA937EBC77UC8FLJARE0), with exactly the same pixel scope as Meta’s: visits to the same pages and, only when Stripe confirms a charge, the standard event Purchase (amount in USD and the payment session identifier).
What we intentionally left off purposefully: the automatic advanced match, which would scan the web forms and send TikTok the email of whoever types them in — whether they buy or not; and the enhanced data sending, which would collect clicks, time on each page, and content. Neither one is needed to know whether an ad worked.
It’s not enter.html or on create.html, and it doesn’t run inside iOS and Android apps: only on the web.
If you don’t want TikTok to measure you: the same applies as above — tracking protection, a blocker, or deleting site cookies. You can also withdraw your acceptance from this page or your profile. The server purchase journey is described at the end of this policy.
7. How to delete cookies from your browser
You can view and delete cookies from any site (including Cocuyo) from your browser settings:
- Chrome: Settings → Privacy and security → Cookies and other site data (or “Clear browsing data”).
- Safari: Settings → Privacy → Manage website data.
- Firefox: Settings → Privacy & security → Cookies and site data.
If you clear Cocuyo data, your session will be closed and the device’s technical identity and some local preferences will be reset.
8. Metrics
Cocuyo measures, within its own server, which worlds start, progress, or end, to decide what to produce: that part doesn’t leave our machine. The site audience is also measured by Google Analytics 4 (point 4). Ad campaigns are measured by the Meta pixel (point 5), only on public pages and with Purchase when Stripe actually charges.
If you have any questions about this policy, write to us at hola@cocuyo.ai.
The Cocuyo light illuminates worlds, not people.
Last content review: October 3, 2026.
Purchase journey measurement
With your consent, we retain the campaign source and a random browser identifier for 30 days using the cocuyo_atribucion and cocuyo_medicion_id cookies. We measure arrival, verified registration, checkout initiation and confirmed purchases. TikTok receives these events and available click or browser identifiers; this journey does not add sharing of email, phone, prompts or files. We keep our own delivery log for 30 days and retry failed deliveries. Withdrawing consent deletes these identifiers and the record linked to this browser. You can change your choice on this page or in your profile.
Our measurement of visits and tools
Only if you accept measurement, Cocuyo records the entry page, public pages visited, tools opened, referring domain and campaign tags. A visit is grouped using a random identifier stored in the tab's storage, which expires after 30 minutes of inactivity. Our record is kept for at most 30 days and uses the browser identifier described above to delete data when you withdraw your choice. Account registrations and checkout starts are counted only when our server confirms them. These visits are not linked to your account and their events are not sent to advertising platforms. We do not record form text, prompts, files, private page addresses, access parameters or screen recordings. You can withdraw measurement from Your privacy choices and view this browser's data in your data download.
Operational signals with your consent
We also receive heartbeats while the page is visible and signals when it is hidden or closed, with the server time, to review how the service works and interruptions. A departure recorded when a heartbeat expires is an inference; hiding or closing the page are indicators. In tools, Apps and Studio, we record the start, an error or the cancellation of a run; a tool’s local result is distinguished from a generation confirmed by the server and does not prove remote delivery. These signals are collected only with your consent. When you withdraw your choice, measurement stops on this device and we request deletion of the record linked to this browser; deletion on the server requires that request to arrive successfully.