Cookie Policy
What cookies are
Cookies are small text files placed on your device when you visit a website or use an application. Similar technologies include browser storage (localStorage and sessionStorage), pixels, and software development kits. They let the Service remember your session and preferences and help us operate, secure, and improve the Service. This policy lists every one the Service sets or loads, by name.
How your choice works
When you first visit, a banner asks you to accept or decline. Until you accept, the Service sets only the items listed below as strictly necessary or functional; nothing in the Analytics or Advertising and measurement categories loads, and no marketing cookie is set. Declining — or simply not choosing — keeps it that way.
If you accept, the analytics and advertising/measurement technologies listed below load, and the two marketing cookies (vl_vid and velira_attr) may be set. Where a vendor's tag is not configured for the Service, accepting loads nothing from that vendor. If you later decline, those two cookies are removed at once; a tag that has already loaded in the page you are on stops with the next page you open.
Your choice is stored on your device under the key velira_cookie_consent so we can honour it on return visits. To change it, open Do Not Sell or Share My Personal Information — linked in our site footer, on every legal page, from your account screen and from the banner itself. That page opts you out in one click, or clears the stored choice so the banner asks again. You can also block cookies in your browser settings, though blocking strictly necessary cookies may prevent the Service from working.
If your browser sends a Global Privacy Control signal, we honour it as a standing opt-out for that browser: the analytics and advertising items below stay off, the banner stops asking, and a choice stored on the device earlier gives way to the signal. Turn the signal off and the stored choice applies again.
The advertising and cross-site measurement tags load only on our public marketing pages. Every page you reach by signing in sits outside that scope, so the pages you open inside the Velira app stay between you and us.
Cookies and storage we set
Strictly necessary — always on. These make the Service work and cannot be switched off in our systems. velira_cookie_consent (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): remembers whether you accepted or declined non-essential cookies, so your choice is honoured on return visits; you can change or clear it at any time from Do Not Sell or Share My Personal Information. velira_demo (cookie; 1 hour): marks the public demo walkthrough you opened so it is served sample data rather than a sign-in wall; readable only by our server. velira_plaid_link_token (browser storage; until the connection completes, or until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): holds the short-lived connection token while you are sent to your bank and back, so the account connection you started can finish. velira_onboarding_id (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): the id of the setup you started, so you can resume it and so it can be attached to your account when you sign in. velira_claim_tried (tab storage; this browser tab only): remembers, for this tab only, that we already tried to attach a finished setup to your account, so it is not retried on every page.
Functional — always on. Preferences and progress kept on your device by our own code and read only by our own pages; none of them identifies you to anyone else. jarvis.theme (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): your light or dark theme. jarvis.kbr-theme (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): your member-app light or dark theme. jarvis.skin (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): your appearance (skin) setting. velira:advanced (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): whether advanced view mode is switched on. velira:advanced-hint-seen (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that you have seen the advanced-mode hint. velira_chat_pinned (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): whether the Ask Velira panel is pinned open. velira_chat_first_open_seen (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that the Ask Velira welcome has been shown. velira.customize.* (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): which cards you hid on a screen (one key per screen, for example velira.customize.home). velira.order.* (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): the order you gave the cards on a screen (one key per screen). velira_onboarding_data (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): your setup answers, saved on your device so you can pick up where you left off. velira_referral_ref (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): the referral code from the link you arrived on, so the person who referred you is credited when you finish setup. velira_coachmarks_seen_v1 (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that you have completed the guided tour. velira_guided_setup_collapsed (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): whether the guided-setup panel is collapsed. velira:first-plan-seen (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that your first plan has been shown to you. velira.member.nav.collapsedSections (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): which navigation sections you collapsed. velira.member.nav.expandedGroups (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): which navigation groups you expanded. velira:referral-prompt-seen (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that the referral prompt has been shown. velira.member.tracked (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): a local copy of the budget categories you track, so the page can draw them at once. velira.wakeword.enabled (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): whether the voice wake word is switched on. velira.wakeword.autoOfferBriefing (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): whether the voice assistant offers a briefing automatically. velira_exit_offer_v1 (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that the one-time “before you go” offer has been shown, so it is never shown again. velira_privacy (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): whether amounts are blurred on screen. velira_privacy_hint (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that the blur hint has been shown. velira.install-offer.dismissed.v1 (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): that you dismissed the “Install Velira” prompt.
Analytics — only after you accept cookies. vl_vid (cookie; 1 year): a random, anonymous id that keeps you in the same variant of a page experiment (an A/B test); it contains nothing about you and is hashed on our server before it is stored.
Advertising and measurement — only after you accept cookies. velira_attr (cookie; 90 days): the campaign that brought you here — the utm parameters and the Google Ads or Meta click identifier (gclid, fbclid) from the link you arrived on — so a later signup or purchase is credited to that campaign; a click identifier can be matched back to the ad platform that served the click.
Set only for Velira staff signed in to the operator or admin consoles — never on a member's or visitor's device: jarvis_session (cookie; 24 hours, or 90 days if the operator chose to stay signed in): the sign-in session for the operator console; readable only by our server. velira_staff (cookie; 7 days): a staff sign-in session for the admin console; readable only by our server. velira_admin_impersonate (cookie; 30 minutes): labels a staff support session while a staff member views a member's account with permission; readable only by our server. velira_impersonation (cookie; up to 30 minutes): the signed authorisation for that support session; readable only by our server. velira_admin_demo (cookie; 30 days): an admin-console toggle that shows sample data instead of live data. vadm:nav:collapsed (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): which admin-console navigation sections are collapsed. vadm:theme (browser storage; until you clear it from Do Not Sell or Share My Personal Information, or clear this site's data in your browser): the admin-console theme.
Cookies and scripts from our providers
The providers below set their own cookies or run their own scripts on the Service. Where a provider names, sets and expires a cookie itself, the names and lifetimes given are the provider's, quoted from its documentation. The advertising and measurement providers may use what they set to recognise your device across sites; they never receive your balances, holdings, or plan.
Clerk (sign-in) — Strictly necessary, always on. Where it loads: every page, whenever sign-in is configured. Sets sign-in session cookies that keep you signed in and protect sign-in against forgery; Clerk names, sets and refreshes them (for example __session and __client_uat) for the life of your sign-in.
Stripe (payments) — Strictly necessary, always on. Where it loads: the checkout page only. Sets fraud-prevention and checkout-session cookies through Stripe's payment script (Stripe names them, for example __stripe_mid and __stripe_sid, and documents their lifetimes as about one year and about thirty minutes respectively).
Plaid (bank connections) — Strictly necessary, always on. Where it loads: only while you connect a bank or card account. May set its own cookies or storage inside the bank-connection window to complete the connection you start; Plaid names them and sets their lifetimes.
Sentry (error monitoring) — Strictly necessary, always on. Where it loads: every page. Reports failures so we can fix them; it sets no cookie, and an error report carries the page address and browser type with cookies and any form contents stripped before it is sent.
Vercel Web Analytics — Analytics, only after you accept cookies. Where it loads: every page, only after you accept. Counts page views and referrers; it sets no cookie — Vercel identifies a visit by a short-lived hash of the request rather than by anything stored on your device.
Vercel Speed Insights — Analytics, only after you accept cookies. Where it loads: every page, only after you accept. Measures how fast pages load for you (Core Web Vitals); it sets no cookie.
Sentry (performance report) — Analytics, only after you accept cookies. Where it loads: every page, only after you accept. Reports the same Core Web Vitals to Sentry for about one page load in ten; it sets no cookie.
Google Analytics 4 — Analytics, only after you accept cookies. Where it loads: our public marketing pages only, and then only when we have configured it and only after you accept. Provides usage analytics from Google; Google sets its own cookies (for example _ga and _ga_*, which Google documents as lasting up to two years).
Google Ads conversion tracking — Advertising and measurement, only after you accept cookies. Where it loads: our public marketing pages only, and then only when we have configured it and only after you accept. Tells Google which of its ads led to a signup or purchase; Google sets its own cookies (for example _gcl_au, which Google documents as lasting about three months) and may recognise your device across sites.
Meta Pixel — Advertising and measurement, only after you accept cookies. Where it loads: our public marketing pages only, and then only when we have configured it and only after you accept. Tells Meta which of its ads led to a signup or purchase; Meta sets its own cookies (for example _fbp, which Meta documents as lasting about three months) and may recognise your device across sites.
Managing cookies
Non-essential cookies and scripts are off until you turn them on, and everything in the Analytics and Advertising and measurement categories loads only after you accept cookies. To decline after accepting, open Do Not Sell or Share My Personal Information and choose Opt out of sale and sharing; the marketing cookies we set are removed the moment you decline. The same page can clear the stored choice entirely, which brings the banner back so you can choose again.
One limit, stated plainly: a script that has already loaded in the tab you are using stays in that page. An opt-out takes effect from the next page you open, and the same is true when you move from a marketing page into the Velira app in the same tab.
Changes and contact
We may update this Cookie Policy as our practices change; because the inventory above is generated from the code that sets each item, it changes when the code does. Questions? Contact Velira, LLC at privacy@velirafinance.com. See also our Privacy Policy.
Questions about this document? Contact us at hello@velirafinance.com.