Cookie Policy
Cookie Policy
Version: 2.0
Effective date: 3 August 2026
Replaces: version 1.1 of 2 August 2026
Provider: Pedro Cantueso García de Vinuesa (trading as kreawave) — NIF 45748777Y — Avenida de la Arruzafa 50, 14012 Córdoba, Spain
Contact: [email protected]
_Issued under Article 22.2 of Law 34/2002 on information society services and electronic commerce (LSSI), which transposes Article 5(3) of Directive 2002/58/EC (ePrivacy Directive), and Articles 6, 7 and 13 of Regulation (EU) 2016/679 (GDPR). Drafted following the AEPD Guía sobre el uso de las cookies (May 2024 edition) and the EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive (version 2.0, October 2024), which apply the same consent rule to local storage, session storage and any equivalent technique for storing or reading information on your device._
0. Scope, and where this document sits
This Cookie Policy explains only what the Service stores on, or reads from, your device, and why. It does not create, modify or interpret any contractual or economic condition: plans, allowances, charging and re-charging are governed by the Terms of Service, developed by the Refund Policy. What personal data is processed, on what legal basis, for how long and with whom it is shared is set out in the Privacy Policy. In the event of any conflict between documents, the Terms of Service prevail.
It applies to kreawave.com and to every generation module of the Service — speech and audio today, and image and video generation if and when they are activated. Activating a module does not, in itself, change the storage described below; if any future module requires storage that is not listed here, this Policy will be updated and published before that module goes live (§11).
1. What cookies — and equivalent storage — are
A cookie is a small text file that a website asks your browser to store on your device, and which the browser returns to that site on later requests. Modern browsers offer other storage of the same kind: local storage (localStorage) and session storage (sessionStorage), which hold values that only the site that wrote them can read.
Under the EDPB Guidelines 2/2023 and the AEPD Guide, cookies and these equivalent techniques are treated the same way: those that are strictly necessary to provide the service you requested may be used without consent; anything else — in particular advertising, profiling or audience-measurement storage — requires your prior, specific and informed consent. This Policy therefore lists both cookies (§3) and local/session storage entries (§4).
2. Summary — the short version
As at the effective date of this Policy, and verifiable in your browser's developer tools on any page of kreawave.com:
- The Service installs no analytics cookie and no advertising cookie. There is no Google Analytics, Plausible, Fathom, Matomo, Hotjar or equivalent installed.
- A first visit to kreawave.com stores nothing at all on your device: measured on 3 August 2026, a freshly loaded home page held zero cookies and zero local storage entries until the visitor acted.
- What the Service does store is limited to (i) strictly necessary cookies for your sign-in session and for abuse prevention (§3), and (ii) local or session storage entries that remember your own settings, your own place in a purchase flow, and your own cookie choice (§4).
- One marketing tag — the Meta (Facebook) pixel — is offered behind a consent banner, is never loaded unless you press Accept, and is not operative at the effective date (§5).
3. Strictly necessary cookies (no consent required)
These cookies are essential for the Service to work and for it to be protected against abuse and fraud. They are exempt from the consent requirement under the second paragraph of Art. 22.2 LSSI and under the AEPD Guide (May 2024). All of them are first-party (set by kreawave.com), HttpOnly (they cannot be read by scripts running in the page), and are sent with the Secure and SameSite=Lax attributes. None of them is used for advertising, profiling or cross-site tracking.
| Name | Purpose | Set when | Lifetime |
|---|---|---|---|
ov_session | Keeps you signed in. Holds an opaque session token; it is not readable by scripts and it carries no personal data in itself. | You sign in, or verify your account, or sign in with Google | 7 days; deleted immediately on sign-out or account deletion |
ov_uid | Anonymous browser identifier. It lets work you produced before creating an account be linked to that browser and migrated to your account when you register, and it prevents anyone else's anonymous work from being claimed. | Your first anonymous generation or upload | 180 days (~6 months); deleted when you sign in and the migration is done |
kw_demo_vid | Cryptographically signed visitor identifier used only to apply the fair-use quota of the free public demo and to stop the demo being farmed. The value is signed by the server so it cannot be forged to obtain extra quota. | The first time a demo generation is accepted | 30 days |
ov_oauth_state, ov_oauth_nonce | One-off security tokens for "Continue with Google": they protect the sign-in against request forgery and against replay of an authentication response. | You start a Google sign-in | 10 minutes, and deleted as soon as the sign-in completes |
There is no cookie in this table whose purpose is commercial. If you block them, the site still loads, but you cannot stay signed in, and the anti-abuse limits of the free public demo will be applied on the basis of network address and device signals alone (§6).
4. Local storage and session storage used by the Service
These are not cookies, but they are covered by the same rules. All entries below are first-party: they can only be read by kreawave.com, and they are not transmitted automatically with every request the way a cookie is. Session storage is erased when you close the tab; local storage persists until you delete the site's data.
| Key | Storage | Purpose | Lifetime |
|---|---|---|---|
kw_consent | local | Records your answer (Accept / Decline) to the marketing banner of §5, so you are not asked again. | Until you delete site data |
ov_uid | local | Browser identifier used by the generation pages; the counterpart of the cookie of the same name in §3. | Until you delete site data |
ov_favorites | local | The voices you have starred, so they stay at hand. Written only when you star one. | Until you delete site data |
ov_votes | local | The ratings you yourself have given to voices, so the interface can show them back to you. | Until you delete site data |
kw_load_notice_i, kw_load_notice_level | local / session | Which queue-load notice you have already been shown, so the same message is not repeated at you. | Until you delete site data / until the tab closes |
kw_nobal_dismissed | session | Whether you have dismissed the "not enough balance" notice in this tab. | Until the tab closes |
kw_plan_intent, kw_cycle_intent | local | Which plan and which billing cycle you clicked before registering, so the sign-up page offers the same one. They hold an identifier only — no price, no payment data. | Until you delete site data (removed as soon as they are used) |
kw_pending_plan, kw_pending_txn, kw_wallet_before | session | What you were in the middle of buying, so that when the payment provider sends you back the account page can confirm the activation instead of leaving you in the dark. | Until the tab closes; cleared when the purchase resolves |
ov_admin_token | session | Staff only. Access token for the administration panel, held in that tab alone. It is never created for ordinary visitors. | Until the tab closes |
None of these entries contains card or payment data — card details never reach the Service's systems (§7.2) — and none of them is used for advertising or to build a profile. Under the AEPD Guide they are exempt from consent, either as strictly necessary for the delivery of the interface you requested or as customisation created at your own explicit request.
5. Marketing — the Meta (Facebook) pixel: consent required, and not operative today
kreawave advertises on Meta platforms, and the main pages of the site carry a single marketing tag, the Meta pixel (Meta Platforms Ireland Ltd.). The following rules apply to it, and they are enforced in code, not merely promised:
- Nothing is loaded before you choose. The tag is not requested, and no Meta cookie can exist, until you press Accept in the banner. Pressing Decline, or leaving the banner alone, means the tag is never requested. Continuing to browse is not treated as consent.
- Status at the effective date: the pixel is not operative. Measured on 3 August 2026 on the live site: even after pressing Accept, the tag is blocked by the Service's own content-security policy, so the Meta script never executes and no Meta cookie is stored on your device (
document.cookieremains empty). - If it is ever made operative, it would set the first-party cookies
_fbp(browser identifier) and, if you arrived from a Meta advertisement,_fbc(click identifier), with a lifetime of up to 90 days, and it would report to Meta that you visited the page, for advertising measurement. Before that happens, this Policy, the banner and the Privacy Policy will be updated and the consent banner shown again (§11). - You may withdraw consent at any time and as easily as you gave it (§8). Withdrawal does not affect the lawfulness of processing carried out before it (Art. 7.3 GDPR).
The banner is shown on the main pages of the site — home, sign-up, sign-in, password reset, generation, account, history and voice cloning — and links to this Policy.
6. Analytics: none. And what we do instead
The Service uses no audience-measurement or web-analytics tool of any kind. Nothing is written to your device for statistical purposes.
Abuse prevention is done without storing anything on your device: the Service applies fair-use and rate limits using your network (IP) address and a short one-way hash computed from headers your browser sends with every request anyway (User-Agent, Accept-Language, Accept-Encoding and the browser-brand hint). Nothing is written to, or read from, your terminal equipment to obtain it, it is not used to identify you and it is not used for advertising; its only purpose is to stop a free demo, a trial or a plan being farmed. The legal basis is the Provider's legitimate interest in preventing fraud and abuse (Art. 6.1.f GDPR, recital 47). Retention of server-side access logs is described in the Privacy Policy.
7. Third parties that may store data in their own context
The Service's content-security policy (measured on 3 August 2026) authorises requests to only two external providers, both of them functional:
7.1 Cloudflare Turnstile — anti-bot verification
The sign-up, sign-in and public-demo forms are protected by Cloudflare Turnstile (Cloudflare, Inc.). The verification is loaded from challenges.cloudflare.com and runs in Cloudflare's own domain context, where Cloudflare may store the data it needs to decide whether the request comes from a human. Measured on 3 August 2026, pages of kreawave.com return no Cloudflare cookie of their own. This verification is strictly necessary for the security of the registration and sign-in process, and it is therefore exempt from consent under Art. 22.2 LSSI. Cloudflare's own information on its cookies: https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/
7.2 Paddle — payments
Payments are processed by Paddle.com Market Limited, which acts as Merchant of Record (Terms of Service §4). Paddle's script is loaded from cdn.paddle.com only when a signed-in user opens the billing area of their account, and the checkout itself is displayed in a frame served by buy.paddle.com. Paddle sets its own cookies in its own context for fraud prevention and to keep the checkout session secure; they are necessary to complete a payment you have requested. Card details are entered into Paddle's checkout and never reach the Service's systems. Paddle's notices: https://www.paddle.com/legal/privacy
7.3 Meta
Only if, and only after, the tag described in §5 becomes operative and you have accepted it.
No other third party receives requests from the pages of kreawave.com. In particular, there is no advertising network, no data broker, no session-recording tool and no social-network widget embedded in the Service.
8. Accepting, refusing and withdrawing consent
How consent is asked. On the main pages listed in §5, a banner offers two options presented with equal availability — Accept and Decline — with no pre-ticked boxes and with the refusal reachable in exactly the same single click as the acceptance. Nothing subject to consent is loaded until Accept is pressed.
How refusal is treated. If you press Decline, the choice is remembered on that browser so you are not asked again, and the marketing tag is never requested.
How to change your mind, in either direction. Your answer lives in your own browser (kw_consent, §4). To revoke it — or to grant it after having refused — delete kreawave.com's site data in your browser; the stored answer disappears and the banner is shown again on your next visit:
- Chrome: Settings → Privacy and security → Third-party cookies → See all site data and permissions → search kreawave.com → Delete.
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data → kreawave.com → Remove Selected.
- Safari: Settings (Preferences) → Privacy → Manage Website Data → kreawave.com → Remove.
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data → See all cookies and site data → kreawave.com → Delete.
Because the answer is stored on the device, it applies to that browser and that device only: a different browser, a different device or a private-browsing window will ask you again. Note that deleting site data also removes the strictly necessary entries of §3 and §4, so you will be signed out and your local favourites list will be cleared; that is expected, and your account, your balance and your generation history live on the server and are unaffected.
Withdrawing consent never affects the lawfulness of processing carried out beforehand (Art. 7.3 GDPR), and it never affects your rights under the Terms of Service or the Refund Policy.
9. Browser-level controls
You may also block or delete cookies and site storage from your browser's settings, including blocking them for kreawave.com specifically or for all sites. Be aware of the consequences: if the strictly necessary cookies of §3 are blocked, you will not be able to stay signed in, purchases may not be confirmable on return from the payment provider, and the anti-abuse limits of the free demo will be applied by network address and device signals alone.
The browsers' own instructions: Chrome · Firefox · Safari · Edge
10. International transfers
Where the third parties of §7 are involved, part of the processing may take place outside the European Economic Area. The transfer mechanisms relied upon (adequacy decisions, standard contractual clauses or equivalent safeguards under Chapter V GDPR), the categories of data concerned and the retention periods are set out in the Privacy Policy, which is the controlling document on this point; this Policy does not restate them so that the two can never diverge.
11. Changes to this Policy
The Provider undertakes that:
- Any change to what is stored on your device will be published in this Policy before it becomes live, never after.
- Every substantive change raises the version number and the effective date shown at the top of this document, so that what was in force on a given date can always be established.
- If a change affects storage that requires consent, the banner will be shown again and previous answers will not be reused for the new purpose.
The version in force is always available at https://kreawave.com/legal/cookies.
12. Contact and complaints
Questions about cookies and about this Policy: [email protected]. The Provider's full contact channels — postal, telephone and electronic — and the response deadline are set out in the Legal Notice.
If you consider that your data-protection rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es), without prejudice to any other administrative or judicial remedy.