This Cookie Policy explains what cookies, localStorage keys, and similar technologies Vesspr uses, why we use them, and how you can control them. This policy covers the Vesspr web application at vesspr.ai only, the Vesspr service delivered via Telegram, WhatsApp, and voice phone calls does not use browser cookies.
1. Introduction
Karooli Garage Private Limited ("Karooli.ai", "we", "us") uses a minimal set of cookies and browser storage to operate the Vesspr web application. With your explicit opt-in consent, we also use a small set of third-party analytics and marketing measurement tools (Microsoft Clarity, PostHog, Google Analytics 4, and the Meta Pixel) to understand how the site is used and to measure ad performance. None of these load until you accept on the consent banner. We do not engage in cross-site fingerprinting, and we do not sell personal data.
Vesspr is an emotional-wellbeing software product that delivers scheduled, opt-in conversational check-ins grounded in attachment theory, cognitive-behavioural therapy frameworks, and emotional resilience research. It is not a medical device, not a therapy substitute, not a romantic partner, and not a replacement for human connection.
2. Categories of Technologies We Use
We classify our use of browser storage into four categories:
- Strictly Necessary: Required for authentication, session management, and security. Cannot be disabled without breaking core functionality.
- Functional: Store user preferences and onboarding progress to improve your experience. Not required for the service to function at a basic level.
- Analytics and Marketing Measurement (Optional): Help us understand aggregate usage patterns and measure ad performance. Includes the Meta Pixel, which is used by Meta for conversion measurement and may be used by us for ad audience building on Meta platforms. You may opt out at any time on the consent banner.
- Payment Processor: Set by our Merchant of Record (Dodo Payments, or Creem.io as fallback) during checkout to prevent fraud. Governed by the provider's own privacy policy.
3. Complete Cookie and Storage Table
The following table lists every cookie, localStorage key, and sessionStorage key set by the Vesspr web application. This list is audited against the codebase and reflects actual behaviour as of the date above.
3.1 Server-Set Cookies (httpOnly)
3.2 localStorage Keys (Client-Set)
3.3 sessionStorage Keys (Client-Set)
3.4 Analytics and Marketing Measurement (Opt-in only)
The following third-party analytics and marketing measurement tools are loaded ONLY after you accept on our consent banner. They never load by default. If you reject, none of the storage below is ever written to your browser.
3.5 Cookieless Analytics (Legitimate Interest)
Ahrefs Web Analytics runs by default to give us aggregate site metrics. Under GDPR Article 6(1)(f) we process this minimal data on the basis of legitimate interest. The processing is justified because Ahrefs is cookieless, IPs are hashed at ingest, and only aggregate metrics are produced. No persistent identifier is written to your device.
3.6 Payment Processor
During checkout, our Merchant of Record, Dodo Payments (dodopayments.com) as primary, or Creem.io (creem.io) where applicable, may set its own cookies for fraud prevention and session management. These are governed by the respective provider's privacy policy. We do not control these cookies.
4. Technologies We Do NOT Use
To be explicit, Vesspr does not use any of the following:
- Mixpanel, Amplitude, or Segment
- Google Ads or DoubleClick remarketing tags
- TikTok Pixel, LinkedIn Insight Tag, X (Twitter) Pixel, Pinterest Tag, or Snapchat Pixel
- Cross-site fingerprinting or canvas-based identification
- Advanced Matching or Conversions API uploads of hashed contact data from this marketing site
The Meta Pixel is the only marketing measurement pixel on the site and it is consent-gated (see Section 3.4). If you believe a third-party tracker has been loaded in error or without consent, please report it to privacy@karooli.ai.
5. Consent and Control
On your first visit to vesspr.ai you will see a consent banner with two equally prominent options: "Reject all" and "Accept all". The consent-gated technologies (Microsoft Clarity, PostHog, Google Analytics 4, and the Meta Pixel) do not load until you explicitly choose to accept. Your choice is stored locally on your device under the key `vesspr.consent.v1`. If you later reject, we best-effort wipe vendor cookies on your device (including _fbp and _fbc set by the Meta Pixel) in the same turn. Ahrefs Web Analytics runs by default under legitimate interest (see Section 3.5).
Strictly Necessary cookies and storage cannot be disabled, they are required for the service to function (authentication, session management). If you block all cookies in your browser settings, you will not be able to log in.
You can change your consent decision at any time:
- Email privacy@karooli.ai and we will exclude your account from analytics within 30 days;
- Clear the vesspr.consent.v1 key from your browser's localStorage to be asked again on your next visit;
- Block third-party scripts in your browser or use an ad-blocker (Clarity, PostHog, Google Analytics, Meta/Facebook, Ahrefs domains listed in our Content-Security-Policy);
- Use Chrome's "Clear browsing data" or your browser's equivalent to wipe cookies + localStorage for vesspr.ai entirely.
6. Do Not Track
Vesspr respects the Do Not Track (DNT) browser signal. When DNT is enabled, we suppress the loading of optional analytics and marketing scripts (PostHog, Microsoft Clarity, Google Analytics 4, and the Meta Pixel). Strictly Necessary cookies are still set, as they are required for authentication.
7. Changes to This Policy
If we add new cookies or storage mechanisms, we will update this policy and change the "Last Updated" date. Material changes (such as adding a new third-party analytics provider) will be communicated via email to registered users at least 14 days in advance.
8. Contact
For questions about this Cookie Policy or to exercise your rights regarding analytics data, contact privacy@karooli.ai.
Related policies: Privacy Policy (/privacy), Terms of Service (/terms), Refund Policy (/refund).