This notice describes the cookies, local storage and optional tracking implemented in Morrovia today, and gives you control over optional categories.Last updated 30 August 2026
Cookie settings
Choose what Morrovia may use.
No current optional choice. Optional technologies are off.
Necessary
Authentication, security, trip planning, recovery and your saved privacy choice.
Always on
Changes take effect when you save them.
How the categories work
Necessary technology keeps authentication, security, trip planning, recovery and your privacy choice working. Functional storage remembers choices such as language, theme or interface state. Product analytics and affiliate attribution are optional and remain off without a current saved choice.
Current technology inventory
Better Auth session cookie
First-party, strictly necessary. Keeps a signed-in account session working and secure. In HTTPS production the expected name is __Secure-better-auth.session_token; local HTTP uses better-auth.session_token. It is HttpOnly, SameSite=Lax, Path=/ and normally lasts seven days under the installed Better Auth defaults. Secure is enabled for HTTPS/production. It is not controlled by optional tracking consent.
Better Auth OAuth state cookie
First-party, strictly necessary when Google sign-in is started. The expected HTTPS production name is __Secure-better-auth.state; local HTTP uses better-auth.state. It is HttpOnly, SameSite=Lax, Path=/ and normally lasts five minutes. It protects the temporary sign-in handoff and is not controlled by optional tracking consent.
Morrovia consent record
First-party localStorage under easyt-analytics-consent. Necessary to remember the policy version, decision time and optional category choices. It remains until replaced or browser site data is cleared.
Trip planning and recovery storage
First-party localStorage for the home-trip draft, trip cache, recovery copy, active trip, owner boundary, profile, readiness, saved finder choices, stamps and memories. Strictly necessary or functional depending on the feature. These records are created by the relevant planning action, are not tracking, and are not removed when optional tracking is rejected.
Language, theme and interface preferences
First-party localStorage or sessionStorage. Functional preferences created when a traveller changes or dismisses the relevant interface. They generally remain until replaced, the browser tab closes for sessionStorage, or site data is cleared.
Public application-shell cache
First-party Cache Storage named easyt-public-shell-v6. Functional technology created by the production service worker for public Journey pages and static assets. It remains until service-worker version cleanup or browser site data is cleared; account and API responses are excluded.
PostHog
Optional product analytics. Loaded only after Product analytics is allowed and only when its key and host are configured. Morrovia disables autocapture, dead-click and exception capture, heatmaps, performance/web-vitals capture, automatic page views and page leaves, session recording, surveys and remote feature configuration. PostHog may create its own first-party browser identifier after consent; its exact lifetime is vendor-controlled rather than set by Morrovia.
Google Analytics 4
Optional product analytics. Loaded only after Product analytics is allowed, in production, and when a GA measurement ID is configured. Morrovia sends manual page views and deliberately limited product events. GA may create first-party _ga-family cookies after consent; their exact lifetime is not configured in this repository.
Omio Impact
Optional commercial and affiliate attribution. Loaded only after Affiliate attribution is allowed. It can transform eligible Omio links and measure impressions. Normal approved Omio links remain usable when this category is off. Impact controls any vendor identifiers and their lifetime; Morrovia does not have a verified API that deletes all vendor state after loading.
Changing or withdrawing your choice
You can return to Cookie settings without signing in. Withdrawal stops future Morrovia analytics dispatch, removes Morrovia-owned analytics deduplication state, invokes supported provider opt-out/reset controls, and prevents optional SDKs from loading on the next page. It does not remove authentication, saved trips, recovery copies, language, theme or other functional data.
Microsoft Clarity is currently disabled in Morrovia because the deployed project’s replay and masking configuration has not been verified against Morrovia’s private-trip boundary.