← Back to Yoneco

Cookie Policy

Last updated: September 6, 2026

In Short

  • The pages on yoneco.app — this page, the home page, the privacy policy and the credits page — set no cookies and load nothing from other companies.
  • The Yoneco web app at yoneco.app/app/ keeps the dictionary, your study progress and your sign-in in your browser's storage. It cannot work without them, so no consent is asked for them.
  • The web app uses Google Analytics cookies only if you accept them in the banner shown when the app opens. Until then Google's analytics tag is not loaded, no analytics cookie is set and nothing is sent to Google Analytics. You can change your choice at any time under Settings → Privacy.

What This Policy Covers

"Cookies" here means every way a website can store information in your browser: cookies proper, but also localStorage, sessionStorage, IndexedDB databases and the offline cache kept by a service worker. European ePrivacy rules treat all of these alike, so this policy covers all of them.

Strictly Necessary Storage (No Consent Needed)

The web app stores a few things in your browser that it cannot run without. European rules exempt these from consent, so no permission is asked for them. They are written as soon as you open the app and are removed when you clear the site's data in your browser. The app keeps:

  • The Japanese dictionary and your study progress, in a database on your device, so the app answers instantly and works offline — together with a note of which dictionary version is installed, so it is only downloaded again when it changes.
  • Your sign-in, so you stay signed in — to your anonymous account or the account you chose — between visits.
  • Your choices, such as whether you accepted analytics cookies and whether you have already seen the reading tour.
  • A copy of the app's own files, so the app opens faster and works offline. It is replaced when a new version is published.
  • A short-lived security token, renewed about once an hour, proving that requests to the story service come from the real Yoneco app rather than from a bot.

None of these are cookies in the strict sense, and no other website can read them. The sign-in and the security token are issued and handled for us by Firebase (Google). Two genuine third-party cookies are set on Google's own domain; they are exempt from consent too, but we list them here because they are not ours:

Cookie Set by Purpose Lifetime
_GRECAPTCHA Google reCAPTCHA v3 The risk analysis behind the security token described above, which tells people from bots. Set on Google's domain under Google's privacy policy. 6 months
Google sign-in cookies Google Only if you choose "Continue with Google": Google's own sign-in session, governed by Google's privacy policy. Set by Google

Analytics Cookies (Only With Your Consent)

With your permission, the web app uses Google Analytics for Firebase to record anonymous usage events: which screens are opened, that a story was completed, that a search was made, and similar. This tells us which features matter and where the app fails. Analytics events are linked to a pseudonymous identifier derived from your account — never to your email address — and Google Analytics does not store your IP address.

Cookie Set by Purpose Lifetime
_ga Google Analytics Distinguishes one browser from another. 2 years
_ga_<container id> Google Analytics Keeps the state of the current session. 2 years

Until you accept, Google's analytics tag (gtag.js) is not loaded, no analytics cookie is set and no analytics event is sent. (The Firebase analytics module is part of the app's own code and loads with it, but it does nothing until you accept.) If you decline, or later withdraw your consent, the app stops sending events and removes the _ga cookies it can reach. Google processes this data on our behalf; see how Google uses information from sites that use its services.

Changing your choice. Open the app, then Settings → Privacy → Allow analytics cookies. Clearing the site's data in your browser also resets your choice, and the banner will ask again.

Files Loaded From Other Servers

To run at all, the web app loads a few files from Google's content delivery network: the Firebase JavaScript libraries and Flutter's rendering engine from www.gstatic.com, and the Roboto and Noto Sans JP fonts from fonts.gstatic.com. These requests show Google's servers your IP address, as any download does, but set no cookies.

The Android App

The Android app uses no cookies. It sends anonymous usage statistics and crash reports to Google Analytics for Firebase and Firebase Crashlytics; you can switch both off under Settings → Privacy.