Cookie Policy
Version 1.0 · Effective date pending publication
See also: Terms of Use · Privacy Policy
1. About this Cookie Policy
This policy explains how Isotop (operated by Island AI Ltd) uses cookies and similar technologies on our website and web application at isotop.app, and how you can manage your choices. It supplements our Privacy Policy.
You can review or change your choices at any time from Cookie settings in the site footer, or from Settings → Privacy & Security.
3. Categories we use
Necessary (always on). Required to sign you in, keep your session, protect the Service from abuse, and remember basic interface choices. These cannot be switched off because the Service will not work without them. This includes the authentication session, the consent record itself, anti-abuse (reCAPTCHA / App Check), and first-party interface preferences such as theme and dashboard filters.
Analytics (only with your consent). Google Analytics, to understand aggregate usage so we can improve the Service. Nothing analytics-related loads until you consent, and you can withdraw at any time (see §7).
4. Cookies and storage we use (inventory)
| Name | Type | Category | Set by | Purpose | Duration |
|---|---|---|---|---|---|
__session | Cookie (HTTP-only, Secure) | Necessary | Isotop | Keeps you signed in (Firebase session) | ~14 days; cleared on logout/account deletion |
isotop-consent | Cookie | Necessary | Isotop | Stores your cookie choices (no personal data) | ~12 months |
_GRECAPTCHA | Cookie | Necessary (security) | Google reCAPTCHA / App Check | Anti-abuse / bot protection (see §5, §6) | Provider-set |
| Firebase Auth state | IndexedDB (firebaseLocalStorageDb) | Necessary | Firebase SDK | Persists your login on the device | Until logout/clear |
| App Check token | IndexedDB | Necessary (security) | Firebase SDK | Anti-abuse token | SDK-managed |
isotop-appearance | localStorage | Necessary (functional) | Isotop | Remembers your theme (light/dark) | Until cleared |
dash_filter_* | localStorage | Necessary (functional) | Isotop | Remembers dashboard filters (staff) | Until cleared |
isotop:pendingPairing | localStorage | Necessary (functional) | Isotop | Temporary Figma-plugin pairing hint (a public pairing code only, no token) | ~30 minutes (app-managed) |
iv:postChangeEmailRedirect | sessionStorage | Necessary (functional) | Isotop | Short redirect lock after an email change | ~60 seconds (session) |
_ga, _gid, _ga_<id> | Cookie | Analytics | Google Analytics | Usage measurement — only after you consent; cleared when you withdraw | Provider-set (typically ~2 years / 24 hours) |
ga-disable-<GA_ID> | In-page flag (not stored) | Analytics | Isotop | Turns Google Analytics off after you withdraw consent | Runtime only |
5. Third-party services
- Google reCAPTCHA v3 & Firebase App Check — anti-abuse/security. reCAPTCHA also loads on demand on specific flows (e.g. password reset). Provided by Google.
- Google Analytics 4 — usage measurement, loaded only after analytics consent. Provided by Google. Withdrawal disables it and clears its cookies (§7).
- Google Fonts (font preview) — when a design-system preview needs a specific Google font family, the app requests that font from Google Fonts (
fonts.googleapis.com/fonts.gstatic.com) so the preview renders correctly. This is a functional request (one font family at a time, only for the preview); the app’s own interface fonts are self-hosted and make no runtime request.
Each provider processes the associated data under its own terms; see the Privacy Policy (§7 Providers) and the providers’ own notices.
6. A note on security requests before consent
For security and abuse prevention, a request to Google reCAPTCHA / Firebase App Check may occur as the page loads, before you interact with the cookie banner, and may set an anti-abuse cookie (e.g. _GRECAPTCHA). This is limited to protecting the Service (a strictly-necessary security function) and is not used for analytics or advertising. Analytics, by contrast, does not load until you consent.
7. Managing your choices
- In-product controls: use Cookie settings (site footer) or Settings → Privacy & Security to accept, reject, or customize non-essential cookies. Necessary cookies cannot be turned off.
- Withdrawing analytics consent: when you withdraw, Isotop disables Google Analytics (sets
ga-disable-<GA_ID>) and clears the controllable first-party analytics cookies (_ga*). - Browser controls: you can also block or delete cookies through your browser settings; some necessary cookies are required for the Service to function, so blocking them may break sign-in.
8. The Isotop Figma plugin
The Isotop Figma plugin does not use browser cookies. It stores its state using Figma’s own plugin storage (figma.clientStorage) and authenticates to our servers with bearer tokens rather than cookies. A browser cookie scan of isotop.app therefore shows no plugin tokens or cookies.
9. Changes to this Cookie Policy
We may update this policy; each version will carry its own version identifier and effective date, with notice of material changes.
10. Contact
Questions about cookies: support@isotop.app — Island AI Ltd, Office A, Innovation City Business Centre, RAK BANK ROC Office, Ground Floor, Al Riffa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates.