Cookie Policy
Last updated: 2 October 2026
1. About this policy
This Cookie Policy explains how Automaton Limited ("Automaton", "film.fun", "we", "us", "our") uses cookies and similar technologies on film.fun and every film.fun product, including Splice, Studio, Arena, Signal, Canon and Unreel on their *.film.fun addresses, and ReelKit at reelkit.fun. It should be read together with our Privacy Policy and Terms of Service.
2. What cookies and similar technologies are
A cookie is a small text file that a website stores in your browser so it can remember something about you, such as the fact that you are signed in. Similar technologies work in the same way: local storage and session storage keep small pieces of data in your browser, and scripts or pixels from other companies can collect information about your visit. In this policy we call all of these "cookies".
Some cookies are set by us (first-party cookies). Others are set by the companies whose services we use (third-party cookies). Some last only until you close your browser (session cookies); others stay until they expire or you delete them (persistent cookies).
3. The types of cookies we use
Strictly necessary. These make film.fun work and are always on. They sign you in and keep your session secure, remember access codes for invite-only products, protect against fraud and abuse, process card payments at checkout, and remember your cookie choices. You can block them in your browser, but parts of film.fun will then stop working.
Analytics. These help us understand how people use our products so we can improve them, for example which pages are visited, how people found us, and where something went wrong. They include product analytics, Google Analytics, Vercel Web Analytics and session replay. They are off until you accept them.
Marketing. These measure our advertising campaigns, for example ad pixels, conversion tags, retargeting, and attribution that sets third-party cookies. They are off until you accept them. We do not run any advertising pixels today; if we add any, they will only load with your consent and we will list them below.
4. How consent works
When you first visit a film.fun product we ask whether you accept analytics and marketing cookies. Nothing in those categories loads, and none of their cookies are set, until you say yes. You can accept all, reject everything that is not essential, or choose category by category.
Your choice is stored in a single cookie called ff_consent on the film.fun domain, so one choice applies on www.film.fun and on every *.film.fun product. ReelKit uses its own address (reelkit.fun), so it asks separately and stores the same kind of record there.
We keep your choice for 180 days, after which we ask again. We also ask again if you clear your cookies. You can change your mind at any time using the button below or the "Cookie settings" link in the footer of every film.fun page. If you withdraw consent we stop the tools in that category and delete the cookies of theirs that we can reach.
5. Cookies used across film.fun
The tables below list the cookies, storage and third-party tools used across film.fun products. Not every product uses every item; "Used on" shows where each one is used. Durations set by a third party are that company's published defaults and may change. Rows marked * depend on the provider's or our production settings.
Strictly necessary
ff_consent
Remembers your cookie choices across all film.fun sites.
- Provider
- film.fun
- Duration
- 180 days
- Used on
- All film.fun products (host-only on reelkit.fun for ReelKit)
privy-token, privy-refresh-token, privy-id-token, privy-session; privy:* (local storage) *
Signs you in and keeps your session and connected wallet secure.
- Provider
- Privy
- Duration
- About 1 hour (access token) up to about 30 days (session), set by Privy
- Used on
- Community, Splice, Studio, Signal, Arena, Canon
sb-<project>-auth-token (cookie or local storage) *
Keeps you signed in where a product uses Supabase sign-in (for example email magic links).
- Provider
- Supabase
- Duration
- Until you sign out, up to 400 days (Supabase default)
- Used on
- Studio, Arena, Unreel; possibly Community and Splice
unreel_access_token
Keeps creators signed in to Unreel creator pages.
- Provider
- film.fun
- Duration
- 7 days
- Used on
- Unreel
signal_access, access-code-bypass; ff_access_validated (local storage)
Remembers that you entered a valid access code for an invite-only product.
- Provider
- film.fun
- Duration
- 30 days (Signal), 7 days (Arena), until cleared (Studio)
- Used on
- Signal, Arena, Studio
signal_login_day
Records a sign-in once per day, so daily rewards are not counted twice.
- Provider
- film.fun
- Duration
- 2 days
- Used on
- Signal
maintenance-bypass *
Lets staff reach the site during planned maintenance.
- Provider
- film.fun
- Duration
- Session
- Used on
- Splice
sidebar:state
Remembers whether you left the sidebar open or closed.
- Provider
- film.fun
- Duration
- 7 days
- Used on
- Studio, Arena
__stripe_mid, __stripe_sid
Fraud prevention when you pay by card.
- Provider
- Stripe
- Duration
- 1 year / 30 minutes
- Used on
- Splice, Arena (payment pages)
__cf_bm (on privy.io); Cloudflare Turnstile
Bot and abuse protection for sign-in. Set on Privy's domain when the sign-in service loads.
- Provider
- Cloudflare (via Privy)
- Duration
- 30 minutes
- Used on
- Community, Splice, Studio, Signal, Arena, Canon (Privy sign-in)
privy:caid (local storage); Privy usage events (auth.privy.io)
Part of the Privy sign-in service: a client ID and usage events Privy needs to run sign-in and wallets, sent as soon as sign-in loads. It cannot be switched off without removing sign-in. Privy's embedded-wallet frame also sends browser security (CSP) reports to Datadog.
- Provider
- Privy
- Duration
- Until cleared
- Used on
- Community, Splice, Studio, Signal, Arena, Canon (Privy sign-in)
base-acc-sdk.store, wc@2:* (local storage)
Keeps your wallet connection working when you connect an external wallet.
- Provider
- Coinbase (Base account SDK), WalletConnect
- Duration
- Until cleared
- Used on
- Signal, Canon and other products with Privy wallet connection
etch_token, etch_wallet (local storage)
Keeps your Etch session (the Signal launch service) signed in to your wallet.
- Provider
- film.fun
- Duration
- Until cleared
- Used on
- Signal
walletName (local storage)
Remembers which wallet you connected so it can reconnect.
- Provider
- Solana wallet adapter
- Duration
- Until cleared
- Used on
- Arena and other wallet-enabled products
ff_pending_referral, ff_pending_badge_claim, ff_just_claimed_badge, newsletter and dismiss flags (local storage)
Keeps an invite code, badge claim or dismissed notice until you finish what you started.
- Provider
- film.fun
- Duration
- 7 days (referral codes); until cleared (others)
- Used on
- Community, Splice, Canon, Signal, ReelKit dashboard
Sentry error monitoring
Reports crashes and errors so we can fix them. Sets no cookies.
- Provider
- Sentry
- Duration
- n/a
- Used on
- Splice, Studio, Arena
| Name | Provider | Purpose | Duration | Used on |
|---|---|---|---|---|
| ff_consent | film.fun | Remembers your cookie choices across all film.fun sites. | 180 days | All film.fun products (host-only on reelkit.fun for ReelKit) |
| privy-token, privy-refresh-token, privy-id-token, privy-session; privy:* (local storage) * | Privy | Signs you in and keeps your session and connected wallet secure. | About 1 hour (access token) up to about 30 days (session), set by Privy | Community, Splice, Studio, Signal, Arena, Canon |
| sb-<project>-auth-token (cookie or local storage) * | Supabase | Keeps you signed in where a product uses Supabase sign-in (for example email magic links). | Until you sign out, up to 400 days (Supabase default) | Studio, Arena, Unreel; possibly Community and Splice |
| unreel_access_token | film.fun | Keeps creators signed in to Unreel creator pages. | 7 days | Unreel |
| signal_access, access-code-bypass; ff_access_validated (local storage) | film.fun | Remembers that you entered a valid access code for an invite-only product. | 30 days (Signal), 7 days (Arena), until cleared (Studio) | Signal, Arena, Studio |
| signal_login_day | film.fun | Records a sign-in once per day, so daily rewards are not counted twice. | 2 days | Signal |
| maintenance-bypass * | film.fun | Lets staff reach the site during planned maintenance. | Session | Splice |
| sidebar:state | film.fun | Remembers whether you left the sidebar open or closed. | 7 days | Studio, Arena |
| __stripe_mid, __stripe_sid | Stripe | Fraud prevention when you pay by card. | 1 year / 30 minutes | Splice, Arena (payment pages) |
| __cf_bm (on privy.io); Cloudflare Turnstile | Cloudflare (via Privy) | Bot and abuse protection for sign-in. Set on Privy's domain when the sign-in service loads. | 30 minutes | Community, Splice, Studio, Signal, Arena, Canon (Privy sign-in) |
| privy:caid (local storage); Privy usage events (auth.privy.io) | Privy | Part of the Privy sign-in service: a client ID and usage events Privy needs to run sign-in and wallets, sent as soon as sign-in loads. It cannot be switched off without removing sign-in. Privy's embedded-wallet frame also sends browser security (CSP) reports to Datadog. | Until cleared | Community, Splice, Studio, Signal, Arena, Canon (Privy sign-in) |
| base-acc-sdk.store, wc@2:* (local storage) | Coinbase (Base account SDK), WalletConnect | Keeps your wallet connection working when you connect an external wallet. | Until cleared | Signal, Canon and other products with Privy wallet connection |
| etch_token, etch_wallet (local storage) | film.fun | Keeps your Etch session (the Signal launch service) signed in to your wallet. | Until cleared | Signal |
| walletName (local storage) | Solana wallet adapter | Remembers which wallet you connected so it can reconnect. | Until cleared | Arena and other wallet-enabled products |
| ff_pending_referral, ff_pending_badge_claim, ff_just_claimed_badge, newsletter and dismiss flags (local storage) | film.fun | Keeps an invite code, badge claim or dismissed notice until you finish what you started. | 7 days (referral codes); until cleared (others) | Community, Splice, Canon, Signal, ReelKit dashboard |
| Sentry error monitoring | Sentry | Reports crashes and errors so we can fix them. Sets no cookies. | n/a | Splice, Studio, Arena |
Analytics
_ga, _ga_<container-id>
Counts visits and shows which pages and features are used. Set on .film.fun, so one visitor id spans the film.fun sites.
- Provider
- Google Analytics 4
- Duration
- 2 years
- Used on
- Community, Splice
Vercel Web Analytics
Aggregate page view counts. Sets no cookies.
- Provider
- Vercel
- Duration
- n/a
- Used on
- Community, Splice, Arena
ff_anon_id (local storage); ff_session_id, ff_last_touch_ts (session storage)
First-party attribution: records how you found us (campaign tags, referring site, invite code) so we can link it to your account if you sign up.
- Provider
- film.fun
- Duration
- Until cleared (ff_anon_id); session (others)
- Used on
- Community, Splice, Studio, Arena
Sentry Session Replay (sentryReplaySession, session storage)
Records a masked replay of a sample of sessions to help us debug problems.
- Provider
- Sentry
- Duration
- Session
- Used on
- Splice, Studio, Arena
__insp_* (for example __insp_wid, __insp_nv) *
Session recording and heatmaps, when enabled.
- Provider
- Inspectlet
- Duration
- Up to 1 year
- Used on
- Studio (only when enabled)
| Name | Provider | Purpose | Duration | Used on |
|---|---|---|---|---|
| _ga, _ga_<container-id> | Google Analytics 4 | Counts visits and shows which pages and features are used. Set on .film.fun, so one visitor id spans the film.fun sites. | 2 years | Community, Splice |
| Vercel Web Analytics | Vercel | Aggregate page view counts. Sets no cookies. | n/a | Community, Splice, Arena |
| ff_anon_id (local storage); ff_session_id, ff_last_touch_ts (session storage) | film.fun | First-party attribution: records how you found us (campaign tags, referring site, invite code) so we can link it to your account if you sign up. | Until cleared (ff_anon_id); session (others) | Community, Splice, Studio, Arena |
| Sentry Session Replay (sentryReplaySession, session storage) | Sentry | Records a masked replay of a sample of sessions to help us debug problems. | Session | Splice, Studio, Arena |
| __insp_* (for example __insp_wid, __insp_nv) * | Inspectlet | Session recording and heatmaps, when enabled. | Up to 1 year | Studio (only when enabled) |
Marketing
We do not currently use any marketing cookies.
Other third parties
Some pages load content from these providers. They set no cookies for us, but your browser sends them your IP address when it fetches the content:
- Google Fonts: Serves web fonts. Your IP address reaches Google. Used on ReelKit (reelkit.fun), Canon landing page.
- Mux: Streams video. Your IP address reaches Mux. Used on ReelKit (reelkit.fun).
Third-party embedded content. When a creator's page includes a video hosted on YouTube or Vimeo and you play it, that provider may set its own cookies under its own privacy policy. We use YouTube's privacy-enhanced mode where we can. Signal's trade pages show a price chart from GeckoTerminal, which may also set its own cookies under its own privacy policy.
6. Controlling cookies in your browser
Besides the choices above, most browsers let you see, block and delete cookies and site data. Blocking strictly necessary cookies will stop sign-in and other features from working. Your browser's help pages explain how:
You can also opt out of Google Analytics on every site with the Google Analytics opt-out browser add-on.
7. Changes to this policy
We will update this policy when the cookies we use change, and update the "Last updated" date above. If a change needs your consent, we will ask you again.
8. Contact us
If you have questions about how we use cookies, please contact us by email at privacy@film.fun
See also: Privacy Policy · Terms of Service