CannaTally may use limited first-party storage when it is needed for site operation, security, privacy preferences, or a pseudonymous acquisition handoff. It is not used to store your cannabis journal or build a cannabis advertising profile.
COOKIES & DEVICE STORAGE
First-party storage with a narrow job.
CannaTally keeps public-site storage limited to operation, security, preferences, offline reliability and privacy-minimized acquisition attribution—not a profile of your cannabis activity.
When acquisition tracking is enabled, the website may remember a random visitor identifier and minimal first-touch information such as landing page, referring site host, and campaign parameters. A short-lived opaque reference can accompany you from cannatally.com to cannatally.me so the application can attribute an account or install without putting your email, cannabis records, or raw tracking history in the URL.
Selected public pages and brand files may be cached on your device so basic public information can load reliably. Cached public files are different from account records.
The public website is not designed to place cannabis usage, allotment, journal, product history, or other sensitive app records into advertising telemetry. CannaTally does not use session replay or device fingerprinting as part of the planned first-party acquisition model.
Hosting, security, email, and other service providers may process limited technical information needed to deliver, protect, and support the service. Their use must stay limited to the service CannaTally asks them to provide.
Account, sign-in, inventory, journal, subscription, and other signed-in information belong to the CannaTally application at cannatally.me and are governed by the applicable privacy disclosures and controls.
The signed-in app is a separate data context.
Your CannaTally account lives at cannatally.me. Public-site acquisition data must remain intentionally small and must not be silently expanded to include sensitive application records.

