Cookie policy

Policy version 2026-07-22

This is the complete list of cookies this website sets. Two things make it short: we run no third-party trackers — no advertising pixels, no social-media tags, no fingerprinting, no session recording — and our page analytics are first-party and cookieless by default (aggregate counts with no identifier and no stored IP addresses).

CookieCategoryLifetimePurpose
ownsig_sessionStrictly necessary14 daysKeeps you signed in. HttpOnly, SameSite=Lax, Secure in production.
ownsig_social_stateStrictly necessary10 minutesCSRF protection during Sign in with Google / Apple (OIDC state).
ownsig_consentStrictly necessary12 monthsRemembers your cookie choice and the policy version it was made under. SameSite=Lax, Secure in production.
ownsig_vidAnalytics (consent-gated)12 monthsFirst-party anonymous visitor id enabling multi-session analytics and signup attribution. HttpOnly, SameSite=Lax, Secure in production. Set only after Accept in opt-in regions (EU/UK/CH/CA/BR), or by default under the opt-out model elsewhere (honouring Global Privacy Control). Deleted immediately when you withdraw consent.
ownsig_localeFunctional / preference12 monthsRemembers the marketing-site language you chose via the language switcher (or ?lang=). Not used for advertising.
ownsig_annual_nudge_snoozeFunctional (signed-in users)30 daysRemembers that you dismissed the annual-billing suggestion in the app.

Regional behaviour

  • EU, UK, Switzerland, Canada, Brazil: the analytics cookie is off until you opt in via the banner. Rejecting is one click and just as prominent as accepting.
  • United States and elsewhere:the analytics cookie is on by default under an opt-out model. Country is detected from the edge IP geo header (Cloudflare, Vercel, or App Engine). Use the notice's Opt out control or Do Not Sell or Share My Personal Information to turn it off. We honour the Global Privacy Control (Sec-GPC: 1) server-side — if your browser sends it, analytics stay off without you touching a banner.
  • Unknown location: we apply the strictest (EU opt-in) regime until we can detect a country.

Consent receipts

Every consent choice is recorded server-side (timestamp, region, policy version, choice) against a one-way hash of the visitor id, so we can evidence compliance without the receipt log identifying you. Withdrawing consent deletes the visitor cookie immediately; already-aggregated counts contain no identifier to delete.

Changes

If this policy changes materially, the version string above changes and you will be asked again. Questions: .