Cookie Policy
What max.app stores in your browser, and which third parties it connects to.
This page describes what www.max.app stores in your browser and which third parties your browser connects to while you use it. It is a policy document, not a consent banner — the reason there is no banner is explained below.
It forms part of our Privacy Policy.
The short version
- The Site sets no cookies — none, first-party or third-party.
- One preference is stored locally, on your device, and never sent to us.
- Usage measurement is cookieless.
- On the pages with a form, your browser connects to Cloudflare for a bot check.
What is stored on your device
| Name | Type | Purpose | Sent to us? |
|---|---|---|---|
maxapp-v3-theme | Local storage | Remembers whether you chose the light or dark theme | No |
That is the whole list. Local storage is not a cookie: it is not attached to requests, so this value never leaves your browser. Clearing site data removes it, and the Site works normally without it — it simply forgets your theme.
There is no advertising storage, no cross-site identifier, no session or login cookie, and no web beacon or tracking pixel.
Third parties your browser connects to
Not everything that involves a third party involves a cookie. These connections are worth naming even though none of them stores anything on your device.
Vercel Web Analytics — every page
Usage is measured with Vercel Web Analytics, which is cookieless and sets nothing on your device. It records the page you are on, where you arrived from, coarse technical details such as country, browser and device type, and events for the links, buttons and forms you use.
The one form value it receives is the workload you select from the fixed list. It never records what you type — not your name, email, company or message — and it does not identify you across other sites.
Cloudflare Turnstile — pages with a form only
Before we accept a contact, newsletter or waitlist submission we check it with Cloudflare Turnstile, so that a person gets through and a script does not.
On a page that carries a form, your browser contacts Cloudflare, which receives your IP address, your user agent and technical signals about the browser itself. Cloudflare does not receive what you type. The check sets no cookie for this Site and writes nothing to your browser's storage.
Pages with no form on them do not contact Cloudflare at all. This page is one of them.
Cloudflare's own handling of what it receives is governed by its privacy policy at cloudflare.com/privacypolicy.
Why there is no cookie banner
A consent banner is required for storage that is not strictly necessary — analytics cookies, advertising identifiers and the like. This Site uses none of those.
The theme preference is storage you asked for by clicking the toggle, and it never reaches us. The bot check is strictly necessary to keep the forms usable, and we rely on legitimate interests for it. Neither requires consent, so asking for it would be theatre.
If that ever changes — if we add anything that does require consent — a banner will appear before it loads, not after.
Controlling browser storage anyway
You can clear or block local storage and cookies regardless. Doing so on this Site costs you only the remembered theme.
- Apple Safari — and on iPhone or iPad
- Google Chrome — desktop, Android and iOS
- Mozilla Firefox
- Microsoft Edge
- Opera
Blocking Cloudflare's domain will stop the bot check from completing, and the forms will then refuse to submit rather than accepting a message we cannot verify.
Changes
We may update this policy. The effective date at the top always reflects the current version. Because nothing here relies on your consent, changes take effect when published — but if we ever add something that does require consent, we will ask first.
Contact
Questions about this policy: privacy@max.app
Tzar.Tech Ltd., 16 Blaga Dimitrova, 1505, Sofia, Bulgaria
Questions — the contact form reaches a person. All legal notices.