Legal

Cookie Policy

How Hilaron uses cookies, local storage, and similar technologies on our websites and mobile apps — and the choices available to you.

Effective April 24, 2026Last updated April 24, 2026

1. What Are Cookies?

Cookies are small text files that a website places on your device when you visit. They allow the site to recognize your browser, remember your preferences, keep you signed in, and protect against fraud.

We use the term “cookies” broadly in this policy to also include similar technologies such as local storage, session storage, and IndexedDB — modern web storage mechanisms that perform comparable functions in your browser.

2. How We Use Cookies

We use cookies and similar technologies for the following purposes:

  • Strictly necessary: required for the Service to function — including authentication, session management, and security/fraud protection. These cannot be disabled without breaking core functionality (such as signing in or completing a donation).
  • Functional: remember your preferences (such as theme, language, or currency display) so the Service feels consistent across visits.
  • Performance and analytics: help us understand how the Service is used in aggregate, identify errors, and improve the experience. We use these to measure page-load performance and feature engagement, not to build advertising profiles.

We do not currently use advertising cookies, retargeting pixels, or third-party trackers that build cross-site advertising profiles.

3. Cookies and Local Storage We Set

The following first-party cookies and storage items are set directly by Hilaron:

  • Authentication / session tokens — keep you signed in across pages and visits. Issued via Firebase Authentication.
  • CSRF protection tokens — defend against cross-site request forgery on form submissions and donations.
  • Preferences — remember UI choices such as theme (light/dark), display currency, and dismissed notifications.
  • Anti-fraud signals — detect suspicious activity (such as unusual donation patterns or repeated failed sign-in attempts).
  • Donation funnel state — temporarily preserves checkout progress so an interrupted donation can be resumed.

4. Third-Party Cookies

Some pages of the Service load resources from trusted third parties that may set their own cookies on your device:

  • Stripe — processes payments and uses cookies for fraud prevention (e.g. Stripe Radar) and to maintain the secure payment session. See Stripe’s Privacy Policy.
  • Google Firebase — provides authentication, database, and hosting services and may set cookies necessary for those features. See Google’s Privacy Policy.
  • Cloudflare — provides DDoS protection and content delivery, and may set cookies (such as __cf_bm) to distinguish humans from bots. See Cloudflare’s Privacy Policy.

These third parties are independent controllers of the data they collect through their cookies. Their use is governed by their own privacy policies linked above.

5. Your Choices

You have several options for managing cookies:

  • Browser controls: most browsers let you view, manage, and delete cookies through their settings. You can also choose to be notified before a cookie is stored.
  • Block third-party cookies: most browsers offer a setting to block third-party cookies; this generally does not prevent the Service from working but may disable certain features (e.g. embedded payment forms).
  • Clear local storage: you can clear local storage and IndexedDB from your browser’s site-data tools. Doing so will sign you out and clear saved preferences.
  • Do Not Track: we do not currently respond to browser “Do Not Track” signals because there is no industry-standard interpretation, but we also do not engage in cross-site advertising tracking.

Disabling strictly necessary cookies will prevent you from signing in or completing donations on the Service.

6. Cookies in Our Mobile Apps

Our iOS and Android applications do not rely on browser cookies. Instead, they use platform-native secure storage (such as iOS Keychain and Android EncryptedSharedPreferences) and standard mobile device identifiers (such as Apple’s IDFV) for session management, fraud prevention, and analytics. These serve the same purposes as the cookies described above and are subject to the same protections under our Privacy Policy.

7. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in technology, our practices, or applicable law. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (for example, through a banner or in-app notification).

8. Contact Us

If you have questions about this Cookie Policy or how we use cookies, please contact us at [email protected].

For full detail on how we handle personal information, please review our Privacy Policy.


Looking for our Terms of Service or Privacy Policy? They’re available alongside this Cookie Policy.