Cookie and storage policy

Cookie and Storage Policy

Build A Hooper uses limited first-party storage to operate the guest game flow. Optional analytics remain off without valid provider configuration and express user consent.

Owner-approved historical release.

The Owner accepted the residual risk of displaying attributed player names and historical facts. This is an independent project, not an opinion from external counsel or an endorsement by the NBA, any team, or any player.

Effective date
July 26, 2026
Last updated
July 26, 2026
Version
cookie-r11-production-v1

Build A Hooper is operated by PENG CHAI, an individual operator based in Oregon, United States. The service is provided at buildahooper.dev. For support, privacy or deletion requests, intellectual-property complaints, or security reports, email support@buildahooper.dev.

Application storage inventory
ItemType and purposeLifespan / triggerControl
bah_guestStrictly necessary first-party cookie containing a random guest-session credential used to locate server-side session and run state. JavaScript cannot read it.Max-Age=86400 (24 hours), set when a guest session is created. HttpOnly, SameSite=Lax, Path=/; Secure is added outside local mode but still requires production verification.Browser cookie controls; removal ends access to the associated guest session from that browser.
CSRF credentialStrictly necessary runtime memory and API-response value used to protect cookie-authenticated mutations.Held for the active page/runtime session and refreshed with the guest session.Cleared when the page/runtime ends; may refresh automatically.
bah_one_time_deletion_noticeStrictly necessary sessionStorage UI marker recording that the one-time deletion-credential notice was shown. It is not the credential.Written after publication and lasts for the browser tab session under ordinary browser behavior.Closing the tab/session or browser storage controls.
bah_analytics_consentFirst-party localStorage preference recording a versioned granted or denied decision for the exact configured analytics provider set. It is not written when no analytics provider is configured.Written only after the user accepts or declines the displayed optional analytics providers; retained until changed or removed through browser controls. A changed provider set requires a new decision.The on-page analytics setting can review the choice or disable future loading; browser storage controls can remove the preference.
Server-side stateGuest session, game choices, version references, result/challenge state, and keyed deletion-credential digest. This is not browser storage.Private session/run: 24-hour application expiry in tested local code. Public-object and provider retention are not approved.A valid credential makes active result and linked challenge unavailable in tested local code; broader deletion remains production-gated.

Optional provider storage and requests

Google Analytics, Microsoft Clarity, and Plausible are configured, but their external scripts and analytics requests remain blocked until express consent. After consent, Google Analytics and Plausible may measure visits and usage, while Microsoft Clarity may provide interaction diagnostics, heatmaps, and session replay. These providers may set or read their own cookies or similar identifiers and receive request/device/usage information under their terms; the exact inventory must be re-scanned whenever configuration changes. Declining analytics creates no provider script or provider network request.

Advertising and social embeds are disabled. This policy does not claim “no cookies,” “no browser storage,” “no tracking,” or “we never store data.” Questions may be sent to support@buildahooper.dev.