Cookies and storage

A small map of browser state.

The current MVP uses a few browser mechanisms for login, temporary measurement, theme preference, and optional 3D/AR experiences.

Draft · Last reviewed September 27, 2026 · Policy owner: pending

Authentication cookies

Better Auth manages the cookies needed to keep a restaurant user signed in and protect dashboard requests. These are part of the authenticated service and are not used to follow guests across unrelated sites.

Session storage

After a guest accepts analytics, public-menu measurement creates a temporary `dishreveal-analytics-session` identifier in browser `sessionStorage` and sends it with first-party menu events. It is designed to last for a browser session.

Local storage

The site stores the analytics choice as `dishreveal-cookie-consent` in `localStorage`. The restaurant dashboard also stores a `dishreveal-dashboard-theme` preference so its light/dark presentation can be remembered. Neither value contains menu, account, or payment information.

Third-party scripts and assets

Pages that use the interactive viewer currently load model-viewer from unpkg. That request can expose ordinary network metadata to the CDN. The production decision is to self-host or otherwise document this dependency before final policy publication.

Analytics choice

Public menus remain available when a guest declines optional measurement. Analytics events and the temporary analytics session identifier are created only after a guest accepts analytics.

Changing preferences

You can change or withdraw your optional analytics choice at any time. Choosing necessary storage only also removes the temporary analytics session identifier from this browser tab.

For questions, use Contact.