Cookie Policy
What Cannaid keeps in your browser, what each item is there to do, and how to change or clear it.
Effective date: September 9, 2026
1. What This Policy Covers
This policy explains what Cannaid (cannaid.ai) stores in your browser — cookies and similar technologies like localStorage and IndexedDB — and the choices you have. It works together with our Privacy Policy.
Questions: contact@cannaid.ai.
2. The Short Version
- Cannaid sets no cookies of its own. Cookies come only from the third-party services below — each one either security-essential or gated behind your consent:
- A single security cookie from reCAPTCHA protects sign-ups from bots and is always active (see section 6).
- Google Analytics cookies are set only if you accept them in the cookie banner. Decline, and no analytics cookies are ever set.
- Counting visits and measuring speed sets no cookies. We also count page views with Vercel Web Analytics and measure loading speed with Vercel Speed Insights, neither of which stores anything in your browser at all — so they are not a cookie choice (see section 4).
- Advertising cookies from the Mantis ad network are set only if you separately allow ad personalization in the cookie banner. A few ads show either way — declining just makes them non-personalized and cookie-free (see section 5).
- Your grow journal and preferences live in your browser's localStorage, on your device — they are storage, not tracking, and never leave your browser.
- Nothing beyond the security cookie runs without your consent — and we never sell data.
3. Cookies vs. Browser Storage
Cookies are small files a website places in your browser, sent back to a server with every request — which is why they can be used for tracking. localStorage and IndexedDB are also browser storage, but they stay in your browser and are not sent anywhere by themselves. Cannaid relies almost entirely on the second kind.
4. Analytics Cookies (only with your consent)
We use Google Analytics to understand how the site is used — which pages are visited, from what kind of device, roughly where from. This helps us decide what to improve.
- Analytics cookies are set only after you accept them in the cookie banner. If you decline, Google Analytics does not run at all.
- If you accept, Google Analytics sets cookies such as _ga (tells returning visitors apart; expires after about 2 years) and a _ga_... measurement cookie (keeps session state; similar lifetime).
- These cookies are provided by Google (Google Ireland Ltd. / Google LLC); the data handling is described in our Privacy Policy.
- Your choice is remembered in your browser. You can change your mind at any time via the "Cookie settings" link in the footer; declining after a previous accept stops Google Analytics and removes its cookies. Clearing this site's browser data also resets the choice, and you will be asked again.
Counting visits and measuring speed, without cookies. Separately from Google Analytics, we use Vercel Web Analytics to count how many people visit and Vercel Speed Insights to measure how quickly pages load on real devices — both from our hosting provider. They set no cookies and write nothing to your browser storage, so there is nothing to consent to and nothing to clear: they run whatever you choose above. They produce aggregate visit totals and loading-speed measurements only — no profile, no cross-site tracking, and nothing that identifies you.
5. Advertising Cookies (only with your consent)
Cannaid shows a few ads — on the home page, the articles, the health library, the strain library, and the diagnosis results page — to help keep the service free. Ads are served by Mantis Ad Network, an ad network specialized in cannabis-industry advertisers, and appear once you have made your cookie-banner choice.
- The ads themselves show either way. Advertising cookies are set only if you allow "Ad personalization" in the cookie banner — a separate choice from analytics. If you decline, ads are served without cookies and without profiling you.
- If you allow it, Mantis may set cookies to tailor ads, limit how often you see the same ad, and measure ad performance. Mantis (a US company) processes technical data such as your IP address and browser characteristics; the data handling is described in our Privacy Policy.
- The grow journal and the diagnosis survey never show ads.
- You can withdraw at any time via the "Cookie settings" link in the footer — ads continue, but non-personalized and without advertising cookies.
6. A Security Cookie (Bot Protection)
To keep automated abuse away from account creation and the community features, the site uses Google reCAPTCHA v3 (via Firebase App Check). It works invisibly in the background — it never shows puzzles or checkboxes.
- reCAPTCHA sets one cookie, _GRECAPTCHA (provided by Google Ireland Ltd. / Google LLC; expires after about 6 months), used to tell humans apart from bots.
- Because this is a security measure necessary to protect the service, it is active regardless of your analytics choice in the cookie banner. The legal basis and the data it processes are described in our Privacy Policy.
7. What We Keep in Browser Storage
Everything below stays on your device and is never transmitted to us:
- Your grow journal (
cannaid_grows,cannaid_entries,cannaid_reminders,cannaid_alerts) — grows, journal entries including photos, reminders, and the alerts the app raised from your own readings. - Preferences (
cannaid_units,cannaid_language) — your measurement units and interface language. - Small conveniences (
cannaid_tips_dismissed,cannaid_demo_login) — which grow tips you've dismissed, and whether you're using the demo session. - Quiz progress (
cannaid_quiz_best_…,cannaid_quiz_result_…, one pair per quiz) — your best score and your most recent answers, so you can see how you did last time. - Diagram adjustments (
cannaid_anatomy_edits) — label positions you have dragged on the plant-anatomy diagram, so a reload doesn't discard them. - Your cookie-banner choice (
cannaid_cookie_consent), so we don't ask on every visit. - Your age confirmation (
cannaid_age_confirmed) — that you confirmed being 18 or older, acknowledged the legality notice (that you know the legal status of cannabis where you live and will not use Cannaid for unlawful activities), and agreed to our Privacy Policy and Terms of Service, so the entry check doesn't reappear for 24 hours. When you create an account we ask for your date of birth for a stronger check; that date is evaluated on your device only and is never stored or sent to us — only the result (that you are 18+) matters.
Two further items use session storage, which your browser clears automatically when you close the tab:
- Your latest diagnosis (
cannaid_diagnose_result) — the written result shown on the results page, kept so that reloading the page does not lose it. It clears when you choose "Diagnose another" or close the tab, and it holds the written result only — never the photo you uploaded. - A one-time sign-in notice (
cannaid_google_existing_notice) — so a message about an account you already have is not shown twice.
8. Signing In (Firebase)
If you create an account, Google Firebase keeps your session in your browser's IndexedDB storage so you stay signed in — this is essential for the account to work. If you choose "Sign in with Google", Google's own sign-in pages use Google's cookies on Google's domains, governed by Google's policies.
9. What We Do NOT Use
- No marketing or tracking cookies beyond the two consent-gated services described above (Google Analytics, Mantis ad personalization) — and neither sets anything unless you allow it.
- No cross-site tracking pixels, no fingerprinting.
- We never sell data derived from cookies or storage.
10. Managing and Clearing
- Analytics: decline or withdraw consent as described in section 4 — the site works identically either way.
- Ad personalization: allow or withdraw as described in section 5 — ads simply become non-personalized and cookie-free without it.
- Blocking: browsers can block cookies and site storage entirely; note that blocking storage disables sign-in and the grow journal.
- Clearing: you can wipe Cannaid's stored data via your browser's site-data settings. Warning: clearing site data permanently deletes your grow journal (it exists only on your device) and signs you out. Use the journal's built-in Export backup first.
11. Changes to This Policy
We may update this policy as the service evolves — for example, if we add or replace an analytics or advertising tool. The "Effective date" above always shows the current version.
12. Contact
- Cookie and storage questions: contact@cannaid.ai
- Data requests: support@cannaid.ai