Cookie Policy
Categories of cookies we use
- Strictly necessary. Authentication and security storage, all of it placed by Clerk and by Cloudflare. Where it is stored on the statetilt.com domain it is first-party with respect to StateTilt; on Clerk's own domain it is third-party.
- Analytics. StateTilt uses Umami, a cookieless analytics service, to measure aggregate site traffic and where visitors arrive from. It sets no cookies and stores nothing on the device. Umami's published documentation states that it collects no personally identifiable information and does not track visitors across other sites. No cookie-consent banner is shown for analytics.
- Functional. StateTilt sets none: the product has no colour-theme, language or personalisation setting to remember.
- Marketing and advertising. StateTilt sets none and permits none to be set on its behalf.
Consent
In the European Economic Area and the United Kingdom, e-Privacy Directive Article 5 requires informed consent before anything that is not strictly necessary is stored on a visitor's device.
- StateTilt treats the security items placed by Cloudflare as strictly necessary and exempt from consent.
- The authentication items placed by Clerk are strictly necessary in the role they exist for. Because the site header shows sign-in state, Clerk's script runs on every page and these items are placed before any sign-in, whether or not the visitor ever signs in. StateTilt does not assert the strictly-necessary exemption for that case, and does not treat this page as settling it.
- The browser-storage entry saves a request rather than being necessary for the site to work; StateTilt does not claim it as strictly necessary.
If StateTilt introduces storage that is not strictly necessary and not described above, a consent mechanism meeting the applicable e-Privacy and GDPR standards will be implemented before it is written.
How to control cookies
Most browsers let a visitor view, restrict or delete cookies and browser storage in their settings, and most offer a mode that discards everything when the session ends. Storage placed on a vendor's own domain is reviewed and removed the same way. Blocking or clearing it signs a signed-in visitor out and prevents signing in; every public page of this site remains readable. StateTilt shows no cookie-consent banner, so there is no in-page control to withdraw a consent given that way.
Retention
The period for which a signed-in session stays valid before a visitor must authenticate again is set in the session configuration of StateTilt's own Clerk instance. This policy states no figure for it: the lifetimes above are measured storage lifetimes, not that setting.
Changes to this policy
StateTilt may revise this policy when what the site stores changes or when the law changes. Material changes are posted here with a revised “Last updated” date and announced through the channel a subscriber has registered with.
Version 1.1 of this Cookie Policy is subject to revision following professional review at the launch milestone. For privacy questions write to privacy@statetilt.com.