Cookie Policy
Last updated: September 6, 2026
In Short
- The pages on yoneco.app — this page, the home page, the privacy policy and the credits page — set no cookies and load nothing from other companies.
- The Yoneco web app at yoneco.app/app/ keeps the dictionary, your study progress and your sign-in in your browser's storage. It cannot work without them, so no consent is asked for them.
- The web app uses Google Analytics cookies only if you accept them in the banner shown when the app opens. Until then Google's analytics tag is not loaded, no analytics cookie is set and nothing is sent to Google Analytics. You can change your choice at any time under Settings → Privacy.
What This Policy Covers
"Cookies" here means every way a website can store information in
your browser: cookies proper, but also localStorage,
sessionStorage, IndexedDB databases and the offline
cache kept by a service worker. European ePrivacy rules treat all of
these alike, so this policy covers all of them.
Strictly Necessary Storage (No Consent Needed)
The web app stores a few things in your browser that it cannot run without. European rules exempt these from consent, so no permission is asked for them. They are written as soon as you open the app and are removed when you clear the site's data in your browser. The app keeps:
- The Japanese dictionary and your study progress, in a database on your device, so the app answers instantly and works offline — together with a note of which dictionary version is installed, so it is only downloaded again when it changes.
- Your sign-in, so you stay signed in — to your anonymous account or the account you chose — between visits.
- Your choices, such as whether you accepted analytics cookies and whether you have already seen the reading tour.
- A copy of the app's own files, so the app opens faster and works offline. It is replaced when a new version is published.
- A short-lived security token, renewed about once an hour, proving that requests to the story service come from the real Yoneco app rather than from a bot.
None of these are cookies in the strict sense, and no other website can read them. The sign-in and the security token are issued and handled for us by Firebase (Google). Two genuine third-party cookies are set on Google's own domain; they are exempt from consent too, but we list them here because they are not ours:
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
_GRECAPTCHA |
Google reCAPTCHA v3 | The risk analysis behind the security token described above, which tells people from bots. Set on Google's domain under Google's privacy policy. | 6 months |
| Google sign-in cookies | Only if you choose "Continue with Google": Google's own sign-in session, governed by Google's privacy policy. | Set by Google |
Analytics Cookies (Only With Your Consent)
With your permission, the web app uses Google Analytics for Firebase to record anonymous usage events: which screens are opened, that a story was completed, that a search was made, and similar. This tells us which features matter and where the app fails. Analytics events are linked to a pseudonymous identifier derived from your account — never to your email address — and Google Analytics does not store your IP address.
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
_ga |
Google Analytics | Distinguishes one browser from another. | 2 years |
_ga_<container id> |
Google Analytics | Keeps the state of the current session. | 2 years |
Until you accept, Google's analytics tag (gtag.js) is not loaded, no
analytics cookie is set and no analytics event is sent. (The Firebase
analytics module is part of the app's own code and loads with it, but
it does nothing until you accept.) If you decline, or later
withdraw your consent, the app stops sending events and removes the
_ga cookies it can reach. Google processes this data on
our behalf; see
how Google uses information from sites that use its services.
Files Loaded From Other Servers
To run at all, the web app loads a few files from Google's content
delivery network: the Firebase JavaScript libraries and Flutter's
rendering engine from www.gstatic.com, and the Roboto and
Noto Sans JP fonts from fonts.gstatic.com. These requests
show Google's servers your IP address, as any download does, but set
no cookies.
The Android App
The Android app uses no cookies. It sends anonymous usage statistics and crash reports to Google Analytics for Firebase and Firebase Crashlytics; you can switch both off under Settings → Privacy.