This Cookie Policy explains how the Production Service at makojima.com uses browser cookies and related local device storage. It should be read with the Privacy Policy.
Overview
A cookie is a small value a website asks a browser to return with later requests. Local storage is a separate browser feature that keeps data on the device and does not automatically send it with each request. Makojima uses these technologies for signed-in sessions, presentation preferences, and a bounded cache of public lesson metadata.
The current Production Service does not use advertising cookies or a cross-site behavioral advertising profile. Prototypes and protected test environments do not define what the public Production Service stores.
Essential session cookies
Our managed authentication service uses secure cookies to establish and refresh a signed-in session. They allow server-rendered pages and protected routes to determine whether the request is authenticated and to enforce account, MFA, and row-level data boundaries.
These cookies are essential to account features. Blocking or clearing them signs you out or prevents sign-in, Settings, recovery, and Agents from working. Cookie values are not displayed as account identity in public content and must not be placed in shared caches.
Cookieless analytics and performance
Makojima uses Vercel Analytics and Speed Insights to measure aggregate traffic, page delivery, and Web Vitals without setting analytics cookies. These services can still process ordinary request and device context needed to deliver a page and calculate a metric, such as network address, user agent, route, timing, and coarse location.
We use this information to understand reliability and performance, not to build advertising profiles. Cookieless does not mean that no technical request data is processed; it means the measurement tools do not depend on a persistent analytics cookie in your browser.
My Feed uses the same cookieless Vercel Analytics pipeline for two custom events. Feed Rendered reports the selected Shorts insertion point, long-video and Short counts, total card count, a bounded ordering of public card keys, and whether that ordering was shortened. Feed Card Clicked reports the public card key, displayed position, Shorts insertion point, content format, and destination platform for the card you activate. These events help Makojima compare feed placements and understand engagement with public content.
The custom event properties do not contain search text, video titles, destination URLs, raw database identifiers, account or session identifiers, email addresses, IP addresses, cookies, or local-storage values. Vercel may use a short-lived request-derived visitor hash from ordinary request context for aggregate analytics, but Makojima does not write an analytics identifier to your cookies or local storage and does not use these events for cross-site advertising or session replay.
Local device storage
Production may store the following device-level values in local storage:
- Theme preference: the visual theme choice selected for this browser.
- Navigation rail state: whether the public application rail is expanded or collapsed.
- Public lesson catalog: a versioned snapshot of already-public lesson titles, descriptions, thumbnails, and related display metadata so My Feed can show cached content before refreshing in the background.
- Last-visited time: an optional timestamp used to identify public lessons that are new since the last visit.
These keys must not store your name, email address, password, session, private progress, Agents conversations, uploaded files, or MFA and recovery information. The public catalog cache can be shared by signed-out and signed-in views because its contents are public and contain no account-specific state.
Error monitoring and security signals
If optional error monitoring is configured, it may process scrubbed diagnostics when the application fails. Makojima's configuration removes user identity, cookies, request bodies, query strings, and common credential fields and leaves session replay, default personal-data collection, and tracing disabled.
Bot detection and abuse controls process request and browser signals needed to distinguish ordinary use from automated abuse, enforce rate limits, and protect authentication and Agents. These controls may use provider-managed techniques that are not advertising. Security events generally store keyed pseudonymous identifiers rather than raw IP, email, or domain values. See the Privacy Policy for the restricted forensic-mode exception.
What we do not use
The current Production Service does not use advertising cookies, third-party social-media tracking pixels, or cookies to sell or share personal information for cross-context behavioral advertising. It does not use a cookie banner to imply that optional advertising tracking is active when it is not.
If Makojima later adds a technology that requires consent, the Production interface must provide the required notice and control before or when that technology is activated. A prototype or test design does not activate it on Production.
Your controls
You can inspect, block, or delete cookies and site data in your browser settings. You can also clear local storage for makojima.com. Clearing session cookies signs you out. Clearing local storage resets device presentation preferences and removes the cached public lesson snapshot; it does not delete your server-side account, learning, security, or Agents records.
Browser privacy modes, content blockers, and enterprise policies may limit cookies or storage. Public legal text should remain readable, but signed-in and interactive features may not function. Available theme controls appear in the current interface.
Content blockers may also prevent future cookieless analytics events. Because My Feed analytics does not store an analytics cookie or analytics identifier in local storage, clearing site data does not remove aggregate statistics already produced on Vercel's systems. It does clear the device-level preferences and public catalog cache described above.
Changes and contact
We will update this policy when Production storage or measurement practices materially change. Privacy and legal questions may be sent to legal@makojima.com. Technical support goes to hello@makojima.com. Replies will come from the Makojima address responsible for the request. Do not send cookie values, session tokens, passwords, MFA codes, or recovery phrases by email.