Privacy Policy
Last updated: 24 August 2026
This policy explains what CookieCodeJar collects, why, and what choices you have. CookieCodeJar is run by its creator under the public pseudonym Elzbiet Zaleski (a pen name, not a legal name on this page). For terms of use, see Terms of Service.
Data I collect on CookieCodeJar
This list is only what the site itself stores. Payment cards, legal names, billing addresses, and similar checkout data are handled entirely by Ko-fi (see Payments below). CookieCodeJar does not have a payment form and is not designed to receive that information.
- Account: email address, password hash (via Firebase Authentication), optional display name ("pen name"), optional Episode username, optional profile photo URL.
- Membership: subscription tier, next charge date (when known), linked Ko-fi email if different from your login email, credit balance, first-refill bonus status.
- Activity: assets you unlocked, download/unlock timestamps, overlay requests (including optional reference images you upload), roadmap votes and comments, asset likes, optional birthday month/day for profile features (year is not required).
- Technical: basic server and security logs from Firebase Hosting and Cloud Functions, plus Ko-fi webhook records needed to grant credits (event id, payer email, tier label, amount, event type). Not full payment or identity records.
- Local browser storage: theme preference, lightweight session hints (for example last signed-in user id for faster redirects). See Cookies below.
Payments and billing data (Ko-fi only)
CookieCodeJar does not process payments. There is no checkout, card field, or billing address form on this site. I do not want, need, or have the technical means to access your payment card, bank details, legal name, home address, phone number, or other physical or financial identity data.
All paid memberships are purchased on Ko-fi. Ko-fi and its payment partners collect and store whatever they require to charge you, issue receipts, and handle refunds. Their privacy policy governs that data, not this one.
After Ko-fi confirms a subscription or renewal, it sends CookieCodeJar an automated webhook with a small set of fields so credits and tier access can sync to the right account: typically payer email, tier name, amount, event type, and an event id. That is membership sync data, not your full Ko-fi profile or payment credentials. I do not use CookieCodeJar to browse Ko-fi for extra personal details about you.
The only billing-related information you may enter on CookieCodeJar is an optional Ko-fi email link (Profile → Membership) when your Ko-fi address differs from your login email. Receipts, payment method changes, and refund requests belong on Ko-fi.
How I use data
- Run the vault: authenticate you, show credits, enforce tier access, deliver unlocks.
- Sync Ko-fi memberships to the correct account and deposit monthly credits.
- Send transactional email (verification, password reset) through my email provider.
- Moderate abuse on roadmap, comments, and overlay queues.
- Improve the site and fix bugs. I do not sell your personal data.
Overlay reference images
Custom overlay requests may include a reference image (for example a screenshot or mood board). That file is stored temporarily so I (Elzbiet Zaleski / CookieCodeJar) can build your overlay.
- Purpose: reference images are used only to create the custom overlay for your request. They are not used for marketing, resale, my own Episode content, training data, or any other purpose.
- Who can see them: only you and site admin tools while the request is open. Other members cannot browse your reference uploads.
- Retention: the reference file stays on the server while your request is pending or in progress. When the overlay is delivered, the reference file is deleted from server storage and the path is cleared from your request record. If you cancel a pending request, the reference is deleted then as well.
- After delivery: you keep the finished overlay in My assets under the same usage rules as other vault items. The reference image itself is not kept.
Who processes data
CookieCodeJar relies on trusted processors:
- Google Firebase (Authentication, Firestore, Cloud Functions, Hosting, and optional Analytics) for accounts, app data, and product-usage measurement.
- Ko-fi for subscription payments. CookieCodeJar never sees card numbers or billing addresses. Ko-fi sends limited webhook events when you subscribe or renew; I store only what is needed to match your membership and grant credits.
- Resend (or equivalent transactional email provider) for verification and account emails.
Each provider has its own privacy policy. For anything payment-related (cards, receipts, legal name on invoices), contact Ko-fi directly. CookieCodeJar only receives the narrow webhook fields described above.
Analytics (optional)
If you accept analytics cookies, CookieCodeJar uses Firebase Analytics / Google Analytics 4 to understand which pages and vault items people open, what they try to unlock, and where membership interest (for example Ko-fi clicks) shows up. Events are used to improve the vault and pricing, not to sell ads on CookieCodeJar.
- Examples of events: product detail views, unlock attempts, successful unlocks, unlock failures (such as not enough credits), likes, downloads, sign-in/sign-up, and Ko-fi link clicks.
- What we avoid: login emails and passwords are not sent as analytics event parameters.
- Choice: analytics is off until you Accept on the site banner. Decline keeps the jar fully usable. You can change your mind later by clearing site data for this domain (the banner will ask again).
- Google: Google processes Analytics data under its own terms. See Google Privacy Policy.
What others can see
Member profiles are for signed-in CookieCodeJar authors only (not indexed for the public web). Other members never see your login email, credit balance, or unlock list.
- Public member card (member pages and hover previews): pen name, profile photo, Episode handle (if set), membership tier badge, member since, and roadmap activity counts where shown.
- Roadmap: pen name on suggestions and comments unless you post anonymously. Comments may include a photo snapshot from when you posted.
- Only on your own Profile: login email, credits, tier billing dates, Ko-fi link email, notification settings, and your birthday month/day. On your birthday, a cake emoji may appear next to your pen name in public places (roadmap, comments, member cards) so others can celebrate with you. Your exact birth date is not listed as text on those cards.
- Admin access: I use admin tools to view private account data, billing sync, overlay queues, and moderation records to operate the service.
Cookies and local storage
The site uses browser local storage and session storage for theme, session convenience, analytics consent choice, and performance (for example cached shell HTML). Firebase Authentication sets session cookies/tokens needed to keep you signed in. Optional Firebase Analytics / Google Analytics cookies load only after you Accept analytics (see Analytics). There is no third-party advertising tracker on CookieCodeJar.
Retention and account deletion
- Account data is kept while your account is active.
- Delete account (Profile → Delete account, password required) removes your Firebase sign-in and deletes your private user profile (credits, tier, unlock history, birthday, and similar fields).
- Your public member card is marked deleted, your Episode handle is cleared, and the card shows as deleted. Pen name and photo may remain on the tombstone so old roadmap links are not broken.
- Roadmap suggestions and comments you posted may keep the pen name (and comment photo snapshot) from when you posted.
- Ko-fi billing history remains on Ko-fi until you manage it there. Cancel Ko-fi separately if you still have a membership.
- Ko-fi webhook event ids and email bonus claim flags may be retained to prevent duplicate credit grants after re-registration.
- Hosting, function, and security logs may retain technical metadata for a limited time.
Your choices
- Access and update: edit profile fields in the app anytime.
- Analytics: Accept or Decline on the optional banner. Decline (or ignoring it) leaves analytics off. Clearing this site’s browser data resets the choice.
- Delete: Profile → Delete account (password required). Cancel Ko-fi separately.
- Email: transactional emails are required for account security. Marketing is not sent from CookieCodeJar today.
- EU / UK users: you may request access, correction, or deletion by contacting me on Ko-fi or Instagram. You may also lodge a complaint with your local data protection authority.
Age
CookieCodeJar is a membership site for Episode authors: accounts, email, and optional paid Ko-fi subscriptions. It is not designed for children. If you are under the age required to use online services or make purchases in your country, use the site only with a parent or guardian. I do not knowingly collect data from children under 13. Contact me if you believe a child created an account.
International transfers
Data may be processed in the United States or other countries where Firebase and other providers operate. I use providers that offer appropriate safeguards for cross-border processing.
Changes
This policy may be updated. The "Last updated" date at the top will change when it does. Continued use after an update means you accept the revised policy.