Cookie Policy
This page lists every cookie and every piece of browser storage The Chart Maker uses, what each one does, and how long it lasts. Most of it never leaves your device.
1. What this covers
"Cookies" here means cookies and the two other ways a site can keep something in your browser: localStorage (small named values) and IndexedDB (a small database). We use all three, and the list in section 3 covers all three, because from your point of view they raise the same question: what is being kept, and can you get rid of it.
Most of what we store is not about you. It is the chart you are working on, the secret that proves an anonymous chart is yours, and a random number that lets us count one heart per visitor. The Privacy Policy explains the wider picture; this page is the inventory.
2. When we ask for consent
No advertising is running on this site yet. This section describes what happens once it is. Until then no ad script loads, no advertising cookies are set, and nothing about your visit reaches Google through advertising at all. This notice disappears by itself on the deploy that switches advertising on, and the "Last updated" date above moves with it.
If you are in the European Economic Area, the United Kingdom, or Switzerland, a consent message appears before advertising cookies are used for personalised advertising. You can accept, reject, or choose purposes individually, and rejecting is one click, not a maze. The choice is remembered so you are not asked on every page, and you can change it at any time from Your privacy choices.
The strictly necessary items in section 3 are not part of that choice. We take the position that they are exempt because the site cannot do what you asked it to do without them: you cannot heart a chart once if we cannot tell that it was you who hearted it, and an anonymous chart cannot be yours to edit if the browser holds no token. They are never used for advertising and never leave our systems.
Outside those regions we do not show a consent message, which is the ordinary practice for US-operated sites. You still have the opt-out in section 5 and the browser controls in section 6, and we honor Global Privacy Control everywhere, not only where it is legally required.
3. The full list
This is everything. If you find something in your browser from thechartmaker.com that is not on this list, tell us at [email protected] and we will either explain it or remove it.
Our own cookies and keys are named exactly, and a name ending in a colon or a dot is a prefix: there is one key per thing it applies to, which is a chart or a draft in most cases, and one of the moments we ask how it went in the case of the tcm.feedback.asked. keys. Google's advertising and consent storage is listed as a family rather than name by name, because Google sets those names, changes them without telling us, and we never read them. What it is for is in the table, and in Google's own notice (section 4).
Strictly necessary
Needed for the site to do what you asked it to do. These are not used for advertising and are not subject to a consent choice, but you can still delete them in your browser settings (see section 5).
| Name | Type | Set by | Purpose | Lasts |
|---|---|---|---|---|
tcm_anon | Cookie | The Chart Maker | A random identifier with no meaning outside this site. It keeps the charts and uploads you saved without an account attached to you, counts one heart and one view per visitor, applies rate limits, and enforces a ban. It is not derived from your device or browser and is never used for advertising. | 1 year, renewed as you keep using the site |
Sign-in session cookies | Cookie | The Chart Maker | Set only if you sign in. Keeps you signed in between pages, and protects the sign-in redirect against forgery. Signing out ends the session. | Until you sign out, or 7 days of inactivity |
better-auth.message | localStorage | The Chart Maker (sign-in library) | Written when your signed-in state changes in one tab, so the site's other open tabs notice and stop showing you as signed in after you have signed out. The value is the word "session", the name of what changed, a random number for that tab, and a timestamp. It holds no session token and nothing about your account. | Overwritten by the next change; removed when you clear site data |
tcm-ads-optout | localStorage | The Chart Maker | Records that you asked us not to share your information for personalised advertising, so the request survives a reload. Written only when you use the opt-out switch. A Global Privacy Control signal from your browser needs no storage at all: it is read on every page load and applied for that page view, so we never write down that you sent one. | Until you clear site data or turn the opt-out off |
tcm-drafts | IndexedDB | The Chart Maker | Autosaves the chart you are building so a reload or a dropped connection does not lose your work. The draft and images you add stay on your device until you confirm a site-backed action such as Publish or Share. After that, later saves and new images go to the site. | Until you delete the draft or clear site data |
tcm-maker-draft: | localStorage | The Chart Maker | One key per landing page you have actually made something on, holding the id of the draft you were working on there, so that reloading the page or coming back to it later puts your work back in the editor instead of a blank one. It is written only once you have edited something, never for a visit; the value is an id for a draft in this browser and means nothing anywhere else. The page says when it has reopened your work and offers a fresh board, which forgets the id without deleting the draft. | Until you clear site data, or until the draft it points at is gone |
tcm-draft-claim: | localStorage | The Chart Maker | One key per chart open in an editor, holding a random number for the tab that has it open and the time that tab last checked in. It is how a second tab on the same chart knows to stop saving instead of overwriting what the first tab is doing. It holds no identifier for you and is removed when the editor closes. | While the chart is open in an editor; stale entries are replaced |
tcm-edit-token: | localStorage | The Chart Maker | One key per chart you saved without an account, holding the secret that proves the chart is yours. We store only a hash of it on the server, so the copy in your browser is the one that matters. The same secret rides in the cross-device edit link after the #, which is why browsers never send it to us. Treat an edit link like a password. | Until you clear site data |
tcm-forked-from: | localStorage | The Chart Maker | One key per draft you started by remixing a published chart, holding the public id of the chart it came from. It is written before the draft has ever been saved to us, and its value is reported once, when you publish that draft, so your version can credit the original. The key is removed at that point. | Until you publish the draft or clear site data |
tcm-share-copy-artifacts | localStorage | The Chart Maker | Holds copy-link snapshot ids, copy secrets and revoke secrets for independent-copy links created on this device, so an anonymous sender can show the link again and stop new copies. The values are written only after the Share dialog's second confirm. | Until you clear site data, or until you discard the stored link |
tcm-share-copy-recipient: | localStorage | The Chart Maker | One key per copy-link snapshot you confirmed "Make my copy" on, holding the retry key and edit token for that action. Written on this device before the copy request is sent, so a double tap or a dropped connection returns the same new chart instead of creating another. Nothing is written if you leave without confirming. | Until you clear site data |
tcm-publish-intent: | localStorage | The Chart Maker | Remembers that you started signing in from the Publish dialog so the unconfirmed form can reopen on this chart after OAuth. Mirrored to sessionStorage in case one store is dropped during the redirect. Signing in does not upload the chart; Publish still has to be confirmed. The flag is single use and ignored after 15 minutes. | Until sign-in returns, or 15 minutes |
tcm-bingo-daubs: | sessionStorage | The Chart Maker | One key per published bingo card you are playing in this tab, holding the numbers of the squares you have daubed, so an accidental refresh keeps your board. Written only when you daub or reset a square. It holds no identifier for you and is never sent anywhere. | Until you close the tab |
tcm:bingo:player: | localStorage | The Chart Maker | One key per live bingo room you joined, holding the random token that is your seat in that room, so a reload or a phone that slept brings back the same card and the same daubs. Mirrored to sessionStorage in case one store is dropped. Sent to us only with the requests you make inside that room (daubing, calling bingo, refreshing the game state); it identifies your seat, not you. | Until you clear site data; the room itself is deleted seven days after it ends |
tcm:bingo:host: | localStorage | The Chart Maker | One key per live bingo room you host, holding the random host token that lets this browser run the game (start, call, confirm wins, end). Mirrored to sessionStorage in case one store is dropped. Sent to us only with the host actions you take in that room. Copying the host link puts the same token in a URL you choose to share. | Until you clear site data; the room itself is deleted seven days after it ends |
tcm:bingo:header-ask | sessionStorage | The Chart Maker | A single-use flag set when you open a bingo template with Use this template, so the editor can ask you once to give the freshly dealt card a header. Removed the moment the editor reads it. | Until the editor opens, or you close the tab |
tcm:subcategory-intent | localStorage | The Chart Maker | The subject you chose on a topic page (for example Minecraft) when you pressed Make a tier list, kept until the new draft exists so the publish dialog can preselect it. Mirrored to sessionStorage; moved under the draft key below the moment the editor opens. | Six hours, or until the editor adopts it |
tcm:subcategory-intent: | localStorage | The Chart Maker | The same chosen subject, scoped to one draft id so it never leaks into another chart. Mirrored to sessionStorage; the publish dialog reads and clears it. | Six hours, or until you publish that draft |
tcm:bingo:caller | localStorage | The Chart Maker | The numbers called so far on the bingo number caller page, so a refresh does not lose the game in progress. Written only when you draw, pick, undo or reset a number, and removed by Reset. Never sent anywhere. | Until you reset the board or clear site data |
Google consent-message storage | Cookie | Google (Privacy & messaging) | Remembers the choice you made in the consent message so you are not asked again on every page. Necessary in the sense that recording a refusal is what makes the refusal work. | Set by Google; clearing site data makes the message reappear |
Preferences
Remember a choice you made so the interface behaves consistently. They stay on your device and are never sent to us.
| Name | Type | Set by | Purpose | Lasts |
|---|---|---|---|---|
tcm:bingo:mute | localStorage | The Chart Maker | Remembers that you turned the sounds off on the bingo room pages (the call blip and the win chime). Present only while sound is off. | Until you turn sound back on or clear site data |
tcm-hearted: | localStorage | The Chart Maker | Remembers which charts you hearted so the button shows the right state the moment the page paints, rather than after a round trip. | Until you clear site data |
tcm.feedback.asked. | localStorage | The Chart Maker | One key per moment where the site asks how it went, so the question is not put to you again after every publish or every saved image. The value is one word, "answered" or "dismissed", and the time it was written. It holds no identifier, nothing you typed, and nothing about your chart, and nothing reads it back out of your browser. | Until you clear site data; a dismissal stops silencing the question after 120 days |
Advertising
Used to serve and measure the ads that pay for the site. Where the law requires consent, they are used for personalised advertising only after you have given it.
| Name | Type | Set by | Purpose | Lasts |
|---|---|---|---|---|
Google advertising cookies and storage | Cookie | Google (AdSense) | Set by Google on pages that carry ads, to serve and measure them, to limit how often you see the same ad, and, where you have allowed it, to personalise them. We do not read these and we do not receive an advertising profile from Google. | Set by Google; see Google's own disclosures |
4. Third-party storage
Google is the only third party that sets storage on this site, and it does so only on pages that carry advertising. There are no ads, and therefore no Google storage, on this page, on the other legal pages, or in the editor on phones and tablets.
We do not use Google Analytics, Facebook pixels, or any other tracking tag. Our own analytics (Umami) runs on our server, sets no cookie at all, and does not store your IP address.
What Google does with advertising storage is described in Google's advertising technologies notice, and you can change your Google-wide ad settings at myadcenter.google.com.
5. How to refuse or delete them
- Our opt-out: Your privacy choices turns off personalised advertising for this browser and tells Google to serve non-personalised ads instead. It is one switch and it takes effect immediately.
- The consent message (EEA, UK, Switzerland): reopen it from the same page and change any purpose.
- Your browser: every browser can block or delete cookies and site data for a single site. Deleting ours resets your anonymous identifier, signs you out, and removes your local drafts, your edit tokens, and the small markers that remember which charts you hearted and which chart a draft was remixed from.
- Industry opt-outs: optout.aboutads.info and youronlinechoices.eu.
- An ad or tracker blocker works here and we do not detect or block them.
One warning about deleting site data, because it is the one that costs people work: your drafts and your edit tokens live in that same storage. Clearing it deletes drafts we cannot recover, and loses the ability to edit charts you made without an account. Export or sign in first.
6. Global Privacy Control and Do Not Track
Global Privacy Control (GPC). If your browser or an extension sends a GPC signal, we treat it as an instruction not to share your information for personalised advertising, and we apply it automatically on every page, in every region, without asking you to do anything else. You can confirm that we received it on Your privacy choices, which shows the current state for this browser.
Do Not Track (DNT). Browsers send this header inconsistently and no common standard for honoring it was ever agreed, so, like most sites, we do not respond to it. Use GPC or the opt-out above instead; both do something real.
7. Changes and contact
When the site starts or stops using a cookie, this page changes with it, and the "Last updated" date at the top moves. Questions: [email protected].
See also the Privacy Policy, the Terms of Service, and Your privacy choices.