Cookie policy
This page lists the cookies and similar storage the Cyshel websites and apps use, what each one does, and how to change your choices. Last updated: September 16, 2026.
What cookies and similar storage are
Cookies are small files a browser stores on your device at a website's request. Similar tools exist alongside them: browser local storage, and identifiers set by software development kits (SDKs) inside apps. In this policy, "cookies" covers all of them.
Our websites and apps also use first-party local storage for the service's own state: your active session, display preferences and unsent drafts. That storage does not follow you across other websites.
Three categories
Necessary storage: it exists to deliver the service you asked for, so it has no toggle in the consent panel. It covers your sign-in, the record of your consent choice itself, and the accessibility settings you chose.
Analytics: usage measurement, meaning which pages are read and how visitors reach them. On services that show the consent panel, it runs only with your consent.
Marketing: advertising measurement, meaning whether a visit came from an ad and what happened after it. On services that show the consent panel, it runs only with your consent.
Necessary storage
The following storage is required to operate the service, so it does not depend on consent. Each line gives the name, the vendor, the purpose and the retention period.
cyshel.consent (Cyshel): Stores your consent choices on cyshel.com, the version you answered, and when you decided. Retention: 12 months.
nails-platform.consent (Cyshel): Stores your consent choices, the version you answered, and when you decided. Retention: 12 months.
nails-platform.a11y (Cyshel): Stores the accessibility display settings you chose, so they apply before the page paints. Retention: Until you clear it.
nails-platform.* (Cyshel): First-party service storage: your active session, studio choice, unsent drafts and display preferences. Retention: For the session, or until cleared.
CognitoIdentityServiceProvider.* (Amazon Web Services): Holds your sign-in tokens so you do not have to sign in again on every visit. Retention: Until sign-out or token expiry.
Analytics cookies
On services that show the consent panel, the following cookies load only if you agreed to the analytics category; if you refused, they are never set. On services where the panel has not shipped yet, they load when the service starts, and the browser and device controls described below are the way to limit them.
_ga, _ga_* (Google Analytics): Usage measurement: which pages are read and how visitors reach them. Retention: Up to 24 months.
mp_* (Mixpanel): Product analytics: which actions in the service are used and how often. In the Lineapp and Commander apps this includes session replay, meaning a recording of your screen interactions in the app. Retention: Up to 12 months.
__mpq_* (Mixpanel): Usage events not yet sent, held until there is a connection to send them. Retention: Until the events are sent.
looks_attr.first (Cyshel): The campaign or site that first brought you to Looks, the page you arrived on and the date, so we can tell which promotions bring bookings. Retention: Until you withdraw consent or sign out.
Marketing cookies
On services that show the consent panel, the following cookies load only if you agreed to the marketing category; they are used for advertising measurement alone. On services where the panel has not shipped yet, the browser and device controls described below are the way to limit them.
_fbp, _fbc (Meta): Advertising measurement: whether a visit came from an ad and what happened after it. Retention: Up to 90 days.
How consent works
The consent panel ships on the Looks sites (lookstime.com and nails.cyshel.com) and on cyshel.com. We are extending it to the rest of the Cyshel services; a service it has not reached yet collects no consent record, and measurement there is limited through the browser and device settings instead.
Where the panel is shown, nothing optional runs until you decide. Analytics and marketing can be refused separately from each other, and refusing is presented as prominently as accepting.
Your choice is stored together with a timestamp and the version of the request you answered. It is valid for 12 months; after that we ask again. If the list of purposes ever grows, we ask again before running anything.
Withdrawing consent does more than stop collection from that point on: when you withdraw a category, we also delete what that category already stored on your device.
The consent panel reads the Do Not Track and Global Privacy Control browser signals when choosing its opening state. Those signals never override an explicit choice you made, and since everything optional is off by default, they do not switch anything on.
Changing your choices
Wherever the panel is shown, the cookie settings control in the footer reopens it at any time and lets you change any choice.
You can also clear or block cookies in your browser settings (Chrome, Safari, Firefox and Edge all offer this), and limit advertising identifiers in the device settings on iOS and Android.
If you refuse
The services work in full without analytics and without marketing. Refusing stops only usage measurement and ad attribution; no capability in the service is withheld.
Nothing necessary sits behind the toggles: what the service needs in order to work is never presented as a choice.
Updates and contact
When we update this policy, we will post the new text here with a new effective date. A material change to the consent categories leads to a fresh consent request.
For questions about this policy, contact Cyshel Creative Ltd, Gartziani 6, Tel Aviv, Israel, by email at legal@cyshel.com.