Summary
- clitrail.com
- One cookie,
attr_session, set only after you sign in to the dashboard. It keeps you signed in, so it is strictly necessary. - No analytics or advertising
- No analytics, advertising or tracking cookies, and no third-party scripts except Google’s sign-in helper on the dashboard.
- Display choices
- A few display choices are kept in your browser’s local storage, and an unsent support request in session storage. They never leave your browser.
- On customers’ websites
- The CLItrail tag sets no cookies. It reads a few first-party cookies and uses browser storage under the website’s control (below).
The cookie on clitrail.com
| Name | Set by | Purpose | Attributes | Lifetime |
|---|---|---|---|---|
attr_session | clitrail.com, when you sign in to the dashboard | Keeps you signed in. It holds a random token; the server keeps only its hash. | HttpOnly, SameSite=Strict, Path=/, and Secure on https | 7 days, or until you sign out or revoke the session |
Browser storage on clitrail.com
These items stay in your browser. CLItrail’s pages read them, but never send them to us. The home page, legal pages and installer page store nothing.
| Where | Key | Storage | What it holds | Lifetime |
|---|---|---|---|---|
| Docs and support page | clitrail-docs-theme | Local | Your light or dark theme choice | Until you clear site data |
| Docs | clitrail-docs-tabs | Local | The code tab you picked in each group (for example npm or Homebrew) | Until you clear site data |
| Docs | clitrail-docs-recent | Local | The last six documentation pages you opened | Until you clear site data |
| Docs | clitrail-docs-folded | Local | The navigation groups you folded | Until you clear site data |
| Support page | clitrail-support-draft | Session | The topic and message of a request you have not sent yet. Diagnostics are never kept. | Until you send it or close the tab |
| Dashboard | clitrail:org | Local | The organisation you last opened | Until you clear site data |
| Dashboard | clitrail:days | Local | The date range you picked (7, 30 or 90 days) | Until you clear site data |
| Dashboard | clitrail:model | Local | First-touch or last-touch view | Until you clear site data |
| Dashboard | clitrail:path | Local | The install path you picked in Setup | Until you clear site data |
| Dashboard | clitrail:framework | Local | The website framework you picked in Setup | Until you clear site data |
| Dashboard | clitrail:invite | Session | An invitation link’s token, kept while you sign in | Removed once used, or when you close the tab |
| Dashboard | clitrail:google-redirect | Session | Marks a Google sign-in that went through a full-page redirect | Removed on return |
| Dashboard | Entries named with a firebase: prefix | Session | Firebase’s record of a sign-in in progress | Firebase signs out once the sign-in becomes a CLItrail session; closing the tab removes the rest |
| Dashboard | clitrail:emailForSignIn | Local | The email address you asked a sign-in link for, when you asked, and an invitation you were accepting | Until you finish signing in; discarded after 24 hours |
Google sign-in and Stripe pages
- Google. Signing in with Google runs Google’s pages, in a pop-up or redirect and in a hidden frame from our Firebase project’s sign-in domain. These pages can set Google’s own cookies and storage on Google’s domains, under Google’s privacy policy. On Safari and on mobile browsers, the dashboard loads Google’s helper as soon as its sign-in screen, or a page that can ask for a fresh sign-in, opens. On other browsers it loads the helper when you choose to sign in.
- Email sign-in link. The email comes from Google’s Firebase on our behalf; opening the link finishes the sign-in on clitrail.com.
- Stripe. Checkout and the billing portal are Stripe’s own pages on Stripe’s domain. Stripe may set its own cookies there, under Stripe’s cookie policy. Our pages load no Stripe code.
The CLItrail tag on customers’ websites
The website that installs the tag decides whether the tag runs and which providers it covers. The website can keep the tag inactive (enabled: false) until a visitor consents. When the tag is inactive, it reads and stores nothing. It sets no cookies. When it runs, it uses the items below.
Customers can copy this table into their own cookie notice.
| Item | Storage | Purpose | Lifetime |
|---|---|---|---|
opfs-install-attribution. | Origin Private File System (the website’s private browser storage) | The visit receipt: a random 256-bit value, website and page IDs, origin, creation and expiry times | Valid for 30 days. The file stays until site data is cleared or a newer visit replaces it. |
clitrail_source | Session storage | The campaign source (UTM values and external referrer) for the current tab | Until the tab closes |
google_ | Local storage | Google’s session attributes from a Google Ads landing page (the same key Google’s own helper uses) | Until replaced by a newer Google Ads landing, or site data is cleared |
clitrail_ttclid | Local storage | The last TikTok click ID and when it arrived | Until replaced by a newer click, or site data is cleared |
clitrail_twclid | Local storage | The last X click ID and when it arrived | Until replaced by a newer click, or site data is cleared |
The tag also reads, but never sets or changes, these first-party cookies for the providers the website keeps enabled:
_gcl_aw(Google Ads);_fbpand_fbc(Meta);_ttpandttclid(TikTok);_twclid(X).
It asks the website’s own GA4 tag for its client and session IDs, and GA4 reads its own cookies for that.
A website that starts the tag in handoff mode saves nothing in the browser.
In the EEA and the UK, storing these items and reading these cookies can require the visitor’s consent. Our terms make that the website’s responsibility.
Your choices
- Clearing. Clearing a website’s data in your browser removes everything listed for that website. For clitrail.com this also signs you out.
- Blocking. You can block cookies for clitrail.com in your browser settings, but the dashboard then cannot keep you signed in.
- Global Privacy Control. On customers’ websites, CLItrail records a GPC signal and keeps that visit away from advertising platforms (privacy policy §07).
Changes
We will update this notice, with a new date, before we add a cookie or a storage item. Questions: founders@pilotprotocol.network.