Legal

Cookies and browser storage

This notice lists every cookie and browser-storage item that CLItrail’s own pages use. It also lists the items that CLItrail’s website tag uses on customers’ websites, which the customer controls.

Operator
Vulture Labs, Inc.
Status
In effect
Effective
24 September 2026
Applies to
clitrail.com, and the CLItrail tag on customers’ websites
On this page

Summary

clitrail.com
One cookie, attr_session, set only after you sign in to the dashboard. It keeps you signed in, so it is strictly necessary.
No analytics or advertising
No analytics, advertising or tracking cookies, and no third-party scripts except Google’s sign-in helper on the dashboard.
Display choices
A few display choices are kept in your browser’s local storage, and an unsent support request in session storage. They never leave your browser.
On customers’ websites
The CLItrail tag sets no cookies. It reads a few first-party cookies and uses browser storage under the website’s control (below).
NameSet byPurposeAttributesLifetime
attr_sessionclitrail.com, when you sign in to the dashboardKeeps you signed in. It holds a random token; the server keeps only its hash.HttpOnly, SameSite=Strict, Path=/, and Secure on https7 days, or until you sign out or revoke the session

Browser storage on clitrail.com

These items stay in your browser. CLItrail’s pages read them, but never send them to us. The home page, legal pages and installer page store nothing.

WhereKeyStorageWhat it holdsLifetime
Docs and support pageclitrail-docs-themeLocalYour light or dark theme choiceUntil you clear site data
Docsclitrail-docs-tabsLocalThe code tab you picked in each group (for example npm or Homebrew)Until you clear site data
Docsclitrail-docs-recentLocalThe last six documentation pages you openedUntil you clear site data
Docsclitrail-docs-foldedLocalThe navigation groups you foldedUntil you clear site data
Support pageclitrail-support-draftSessionThe topic and message of a request you have not sent yet. Diagnostics are never kept.Until you send it or close the tab
Dashboardclitrail:orgLocalThe organisation you last openedUntil you clear site data
Dashboardclitrail:daysLocalThe date range you picked (7, 30 or 90 days)Until you clear site data
Dashboardclitrail:modelLocalFirst-touch or last-touch viewUntil you clear site data
Dashboardclitrail:pathLocalThe install path you picked in SetupUntil you clear site data
Dashboardclitrail:frameworkLocalThe website framework you picked in SetupUntil you clear site data
Dashboardclitrail:inviteSessionAn invitation link’s token, kept while you sign inRemoved once used, or when you close the tab
Dashboardclitrail:google-redirectSessionMarks a Google sign-in that went through a full-page redirectRemoved on return
DashboardEntries named with a firebase: prefixSessionFirebase’s record of a sign-in in progressFirebase signs out once the sign-in becomes a CLItrail session; closing the tab removes the rest
Dashboardclitrail:emailForSignInLocalThe email address you asked a sign-in link for, when you asked, and an invitation you were acceptingUntil you finish signing in; discarded after 24 hours

Google sign-in and Stripe pages

  • Google. Signing in with Google runs Google’s pages, in a pop-up or redirect and in a hidden frame from our Firebase project’s sign-in domain. These pages can set Google’s own cookies and storage on Google’s domains, under Google’s privacy policy. On Safari and on mobile browsers, the dashboard loads Google’s helper as soon as its sign-in screen, or a page that can ask for a fresh sign-in, opens. On other browsers it loads the helper when you choose to sign in.
  • Email sign-in link. The email comes from Google’s Firebase on our behalf; opening the link finishes the sign-in on clitrail.com.
  • Stripe. Checkout and the billing portal are Stripe’s own pages on Stripe’s domain. Stripe may set its own cookies there, under Stripe’s cookie policy. Our pages load no Stripe code.

The CLItrail tag on customers’ websites

The website that installs the tag decides whether the tag runs and which providers it covers. The website can keep the tag inactive (enabled: false) until a visitor consents. When the tag is inactive, it reads and stores nothing. It sets no cookies. When it runs, it uses the items below.

Customers can copy this table into their own cookie notice.

ItemStoragePurposeLifetime
opfs-install-attribution.<website>.<page>.jsonOrigin Private File System (the website’s private browser storage)The visit receipt: a random 256-bit value, website and page IDs, origin, creation and expiry timesValid for 30 days. The file stays until site data is cleared or a newer visit replaces it.
clitrail_sourceSession storageThe campaign source (UTM values and external referrer) for the current tabUntil the tab closes
google_session_attributesLocal storageGoogle’s session attributes from a Google Ads landing page (the same key Google’s own helper uses)Until replaced by a newer Google Ads landing, or site data is cleared
clitrail_ttclidLocal storageThe last TikTok click ID and when it arrivedUntil replaced by a newer click, or site data is cleared
clitrail_twclidLocal storageThe last X click ID and when it arrivedUntil replaced by a newer click, or site data is cleared

The tag also reads, but never sets or changes, these first-party cookies for the providers the website keeps enabled:

  • _gcl_aw (Google Ads);
  • _fbp and _fbc (Meta);
  • _ttp and ttclid (TikTok);
  • _twclid (X).

It asks the website’s own GA4 tag for its client and session IDs, and GA4 reads its own cookies for that.

A website that starts the tag in handoff mode saves nothing in the browser.

In the EEA and the UK, storing these items and reading these cookies can require the visitor’s consent. Our terms make that the website’s responsibility.

  • Clearing. Clearing a website’s data in your browser removes everything listed for that website. For clitrail.com this also signs you out.
  • Blocking. You can block cookies for clitrail.com in your browser settings, but the dashboard then cannot keep you signed in.
  • Global Privacy Control. On customers’ websites, CLItrail records a GPC signal and keeps that visit away from advertising platforms (privacy policy §07).

We will update this notice, with a new date, before we add a cookie or a storage item. Questions: founders@pilotprotocol.network.