Cookie Policy

Last updated: 2 October 2026

1. About this policy

This Cookie Policy explains how Automaton Limited ("Automaton", "film.fun", "we", "us", "our") uses cookies and similar technologies on film.fun and every film.fun product, including Splice, Studio, Arena, Signal, Canon and Unreel on their *.film.fun addresses, and ReelKit at reelkit.fun. It should be read together with our Privacy Policy and Terms of Service.

2. What cookies and similar technologies are

A cookie is a small text file that a website stores in your browser so it can remember something about you, such as the fact that you are signed in. Similar technologies work in the same way: local storage and session storage keep small pieces of data in your browser, and scripts or pixels from other companies can collect information about your visit. In this policy we call all of these "cookies".

Some cookies are set by us (first-party cookies). Others are set by the companies whose services we use (third-party cookies). Some last only until you close your browser (session cookies); others stay until they expire or you delete them (persistent cookies).

3. The types of cookies we use

Strictly necessary. These make film.fun work and are always on. They sign you in and keep your session secure, remember access codes for invite-only products, protect against fraud and abuse, process card payments at checkout, and remember your cookie choices. You can block them in your browser, but parts of film.fun will then stop working.

Analytics. These help us understand how people use our products so we can improve them, for example which pages are visited, how people found us, and where something went wrong. They include product analytics, Google Analytics, Vercel Web Analytics and session replay. They are off until you accept them.

Marketing. These measure our advertising campaigns, for example ad pixels, conversion tags, retargeting, and attribution that sets third-party cookies. They are off until you accept them. We do not run any advertising pixels today; if we add any, they will only load with your consent and we will list them below.

4. How consent works

When you first visit a film.fun product we ask whether you accept analytics and marketing cookies. Nothing in those categories loads, and none of their cookies are set, until you say yes. You can accept all, reject everything that is not essential, or choose category by category.

Your choice is stored in a single cookie called ff_consent on the film.fun domain, so one choice applies on www.film.fun and on every *.film.fun product. ReelKit uses its own address (reelkit.fun), so it asks separately and stores the same kind of record there.

We keep your choice for 180 days, after which we ask again. We also ask again if you clear your cookies. You can change your mind at any time using the button below or the "Cookie settings" link in the footer of every film.fun page. If you withdraw consent we stop the tools in that category and delete the cookies of theirs that we can reach.

5. Cookies used across film.fun

The tables below list the cookies, storage and third-party tools used across film.fun products. Not every product uses every item; "Used on" shows where each one is used. Durations set by a third party are that company's published defaults and may change. Rows marked * depend on the provider's or our production settings.

Strictly necessary

  • ff_consent

    Remembers your cookie choices across all film.fun sites.

    Provider
    film.fun
    Duration
    180 days
    Used on
    All film.fun products (host-only on reelkit.fun for ReelKit)
  • privy-token, privy-refresh-token, privy-id-token, privy-session; privy:* (local storage) *

    Signs you in and keeps your session and connected wallet secure.

    Provider
    Privy
    Duration
    About 1 hour (access token) up to about 30 days (session), set by Privy
    Used on
    Community, Splice, Studio, Signal, Arena, Canon
  • sb-<project>-auth-token (cookie or local storage) *

    Keeps you signed in where a product uses Supabase sign-in (for example email magic links).

    Provider
    Supabase
    Duration
    Until you sign out, up to 400 days (Supabase default)
    Used on
    Studio, Arena, Unreel; possibly Community and Splice
  • unreel_access_token

    Keeps creators signed in to Unreel creator pages.

    Provider
    film.fun
    Duration
    7 days
    Used on
    Unreel
  • signal_access, access-code-bypass; ff_access_validated (local storage)

    Remembers that you entered a valid access code for an invite-only product.

    Provider
    film.fun
    Duration
    30 days (Signal), 7 days (Arena), until cleared (Studio)
    Used on
    Signal, Arena, Studio
  • signal_login_day

    Records a sign-in once per day, so daily rewards are not counted twice.

    Provider
    film.fun
    Duration
    2 days
    Used on
    Signal
  • maintenance-bypass *

    Lets staff reach the site during planned maintenance.

    Provider
    film.fun
    Duration
    Session
    Used on
    Splice
  • sidebar:state

    Remembers whether you left the sidebar open or closed.

    Provider
    film.fun
    Duration
    7 days
    Used on
    Studio, Arena
  • __stripe_mid, __stripe_sid

    Fraud prevention when you pay by card.

    Provider
    Stripe
    Duration
    1 year / 30 minutes
    Used on
    Splice, Arena (payment pages)
  • __cf_bm (on privy.io); Cloudflare Turnstile

    Bot and abuse protection for sign-in. Set on Privy's domain when the sign-in service loads.

    Provider
    Cloudflare (via Privy)
    Duration
    30 minutes
    Used on
    Community, Splice, Studio, Signal, Arena, Canon (Privy sign-in)
  • privy:caid (local storage); Privy usage events (auth.privy.io)

    Part of the Privy sign-in service: a client ID and usage events Privy needs to run sign-in and wallets, sent as soon as sign-in loads. It cannot be switched off without removing sign-in. Privy's embedded-wallet frame also sends browser security (CSP) reports to Datadog.

    Provider
    Privy
    Duration
    Until cleared
    Used on
    Community, Splice, Studio, Signal, Arena, Canon (Privy sign-in)
  • base-acc-sdk.store, wc@2:* (local storage)

    Keeps your wallet connection working when you connect an external wallet.

    Provider
    Coinbase (Base account SDK), WalletConnect
    Duration
    Until cleared
    Used on
    Signal, Canon and other products with Privy wallet connection
  • etch_token, etch_wallet (local storage)

    Keeps your Etch session (the Signal launch service) signed in to your wallet.

    Provider
    film.fun
    Duration
    Until cleared
    Used on
    Signal
  • walletName (local storage)

    Remembers which wallet you connected so it can reconnect.

    Provider
    Solana wallet adapter
    Duration
    Until cleared
    Used on
    Arena and other wallet-enabled products
  • ff_pending_referral, ff_pending_badge_claim, ff_just_claimed_badge, newsletter and dismiss flags (local storage)

    Keeps an invite code, badge claim or dismissed notice until you finish what you started.

    Provider
    film.fun
    Duration
    7 days (referral codes); until cleared (others)
    Used on
    Community, Splice, Canon, Signal, ReelKit dashboard
  • Sentry error monitoring

    Reports crashes and errors so we can fix them. Sets no cookies.

    Provider
    Sentry
    Duration
    n/a
    Used on
    Splice, Studio, Arena

Analytics

  • _ga, _ga_<container-id>

    Counts visits and shows which pages and features are used. Set on .film.fun, so one visitor id spans the film.fun sites.

    Provider
    Google Analytics 4
    Duration
    2 years
    Used on
    Community, Splice
  • Vercel Web Analytics

    Aggregate page view counts. Sets no cookies.

    Provider
    Vercel
    Duration
    n/a
    Used on
    Community, Splice, Arena
  • ff_anon_id (local storage); ff_session_id, ff_last_touch_ts (session storage)

    First-party attribution: records how you found us (campaign tags, referring site, invite code) so we can link it to your account if you sign up.

    Provider
    film.fun
    Duration
    Until cleared (ff_anon_id); session (others)
    Used on
    Community, Splice, Studio, Arena
  • Sentry Session Replay (sentryReplaySession, session storage)

    Records a masked replay of a sample of sessions to help us debug problems.

    Provider
    Sentry
    Duration
    Session
    Used on
    Splice, Studio, Arena
  • __insp_* (for example __insp_wid, __insp_nv) *

    Session recording and heatmaps, when enabled.

    Provider
    Inspectlet
    Duration
    Up to 1 year
    Used on
    Studio (only when enabled)

Marketing

We do not currently use any marketing cookies.

Other third parties

Some pages load content from these providers. They set no cookies for us, but your browser sends them your IP address when it fetches the content:

  • Google Fonts: Serves web fonts. Your IP address reaches Google. Used on ReelKit (reelkit.fun), Canon landing page.
  • Mux: Streams video. Your IP address reaches Mux. Used on ReelKit (reelkit.fun).

Third-party embedded content. When a creator's page includes a video hosted on YouTube or Vimeo and you play it, that provider may set its own cookies under its own privacy policy. We use YouTube's privacy-enhanced mode where we can. Signal's trade pages show a price chart from GeckoTerminal, which may also set its own cookies under its own privacy policy.

6. Controlling cookies in your browser

Besides the choices above, most browsers let you see, block and delete cookies and site data. Blocking strictly necessary cookies will stop sign-in and other features from working. Your browser's help pages explain how:

You can also opt out of Google Analytics on every site with the Google Analytics opt-out browser add-on.

7. Changes to this policy

We will update this policy when the cookies we use change, and update the "Last updated" date above. If a change needs your consent, we will ask you again.

8. Contact us

If you have questions about how we use cookies, please contact us by email at privacy@film.fun