Cookie Policy

Version 1.0 · Effective date pending publication

See also: Terms of Use · Privacy Policy

1. About this Cookie Policy

This policy explains how Isotop (operated by Island AI Ltd) uses cookies and similar technologies on our website and web application at isotop.app, and how you can manage your choices. It supplements our Privacy Policy.

You can review or change your choices at any time from Cookie settings in the site footer, or from Settings → Privacy & Security.

2. What cookies and similar technologies are

“Cookies” are small files a site stores in your browser. We also use related browser storage:

  • Cookies — small key/value files (some set by us, some by third-party providers).
  • localStorage / sessionStorage — first-party browser storage for preferences and short-lived state.
  • IndexedDB — used by the Firebase SDK to keep you signed in and to hold anti-abuse (App Check) state.

We group these into two categories (below). We do not use advertising or cross-site tracking cookies.

3. Categories we use

Necessary (always on). Required to sign you in, keep your session, protect the Service from abuse, and remember basic interface choices. These cannot be switched off because the Service will not work without them. This includes the authentication session, the consent record itself, anti-abuse (reCAPTCHA / App Check), and first-party interface preferences such as theme and dashboard filters.

Analytics (only with your consent). Google Analytics, to understand aggregate usage so we can improve the Service. Nothing analytics-related loads until you consent, and you can withdraw at any time (see §7).

There is no “Marketing” category — Isotop uses no advertising/marketing cookies or pixels.

4. Cookies and storage we use (inventory)

NameTypeCategorySet byPurposeDuration
__sessionCookie (HTTP-only, Secure)NecessaryIsotopKeeps you signed in (Firebase session)~14 days; cleared on logout/account deletion
isotop-consentCookieNecessaryIsotopStores your cookie choices (no personal data)~12 months
_GRECAPTCHACookieNecessary (security)Google reCAPTCHA / App CheckAnti-abuse / bot protection (see §5, §6)Provider-set
Firebase Auth stateIndexedDB (firebaseLocalStorageDb)NecessaryFirebase SDKPersists your login on the deviceUntil logout/clear
App Check tokenIndexedDBNecessary (security)Firebase SDKAnti-abuse tokenSDK-managed
isotop-appearancelocalStorageNecessary (functional)IsotopRemembers your theme (light/dark)Until cleared
dash_filter_*localStorageNecessary (functional)IsotopRemembers dashboard filters (staff)Until cleared
isotop:pendingPairinglocalStorageNecessary (functional)IsotopTemporary Figma-plugin pairing hint (a public pairing code only, no token)~30 minutes (app-managed)
iv:postChangeEmailRedirectsessionStorageNecessary (functional)IsotopShort redirect lock after an email change~60 seconds (session)
_ga, _gid, _ga_<id>CookieAnalyticsGoogle AnalyticsUsage measurement — only after you consent; cleared when you withdrawProvider-set (typically ~2 years / 24 hours)
ga-disable-<GA_ID>In-page flag (not stored)AnalyticsIsotopTurns Google Analytics off after you withdraw consentRuntime only

5. Third-party services

  • Google reCAPTCHA v3 & Firebase App Check — anti-abuse/security. reCAPTCHA also loads on demand on specific flows (e.g. password reset). Provided by Google.
  • Google Analytics 4 — usage measurement, loaded only after analytics consent. Provided by Google. Withdrawal disables it and clears its cookies (§7).
  • Google Fonts (font preview) — when a design-system preview needs a specific Google font family, the app requests that font from Google Fonts (fonts.googleapis.com / fonts.gstatic.com) so the preview renders correctly. This is a functional request (one font family at a time, only for the preview); the app’s own interface fonts are self-hosted and make no runtime request.

Each provider processes the associated data under its own terms; see the Privacy Policy (§7 Providers) and the providers’ own notices.

7. Managing your choices

  • In-product controls: use Cookie settings (site footer) or Settings → Privacy & Security to accept, reject, or customize non-essential cookies. Necessary cookies cannot be turned off.
  • Withdrawing analytics consent: when you withdraw, Isotop disables Google Analytics (sets ga-disable-<GA_ID>) and clears the controllable first-party analytics cookies (_ga*).
  • Browser controls: you can also block or delete cookies through your browser settings; some necessary cookies are required for the Service to function, so blocking them may break sign-in.

8. The Isotop Figma plugin

The Isotop Figma plugin does not use browser cookies. It stores its state using Figma’s own plugin storage (figma.clientStorage) and authenticates to our servers with bearer tokens rather than cookies. A browser cookie scan of isotop.app therefore shows no plugin tokens or cookies.

9. Changes to this Cookie Policy

We may update this policy; each version will carry its own version identifier and effective date, with notice of material changes.

10. Contact

Questions about cookies: support@isotop.app — Island AI Ltd, Office A, Innovation City Business Centre, RAK BANK ROC Office, Ground Floor, Al Riffa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, United Arab Emirates.

We use cookies. Necessary cookies keep Isotop secure and signed in. With your consent we also use analytics (Google Analytics) to improve the product. See our Cookie Policy and Privacy Policy.