Skip to main content
Legal · Cookie Policy

Cookie Policy

Last updated: 2026-08-24Version 1.1Subject to revision at launch
I

What cookies are

Cookies are small data items that a website — or a service embedded in it — stores on a visitor's device. Browsers offer related storage, such as localStorage and sessionStorage, which works the same way for privacy purposes; this policy covers both and uses “cookies” as shorthand for all of it. Storage of this kind is used to keep a signed-in user authenticated, to remember a choice a visitor has made, or to operate an embedded service. This policy describes what is stored when somebody visits statetilt.com, who stores it, and how a visitor can control it. It complements the Privacy Policy, which describes how personal data more generally is processed.

II

Categories of cookies we use

The categories below describe what is stored today.

  • Strictly necessary. This is the category into which authentication and security storage conventionally falls. StateTilt's own servers set no cookies, and StateTilt's own page code writes nothing to a visitor's browser storage. What is stored comes from the authentication service StateTilt uses, Clerk, and from the network Clerk's own service sits behind. It keeps a signed-in visitor authenticated, operates the sign-in flow, protects that flow against automated abuse, and holds a cached copy of the settings the sign-in code needs. Where it is stored on the statetilt.com domain it is first-party with respect to StateTilt; where it is stored on Clerk's own domain it is third-party. The section below names every item, and the Consent section sets out what StateTilt does and does not claim about each of them.
  • Analytics. StateTilt uses Umami, a cookieless analytics service, to measure aggregate site traffic and where visitors arrive from. It sets no cookies and stores nothing on the visitor's device. Umami's published documentation states that it collects no personally identifiable information and does not track visitors across other sites. Because nothing is stored on the device, StateTilt shows no cookie-consent banner for analytics. If StateTilt later uses analytics that store data on a visitor's device or process personal data, this policy and a consent mechanism will be updated before that change takes effect.
  • Functional. StateTilt sets no functional cookies. The product has no colour-theme, language or personalisation setting to remember, so nothing of that kind is stored.
  • Marketing and advertising. StateTilt sets no marketing or advertising cookies and permits none to be set on its behalf.
III

Cookies set by StateTilt and embedded vendors

StateTilt sets no cookies of its own: its servers send no cookie with any page, and its own page code writes nothing to a visitor's browser storage. Everything in the table below is placed by a service StateTilt embeds. The table was recorded from a live visit to this site in a browser that had never visited it before and was not signed in, for the revision of this page dated at the top — so a visitor who opens their own browser's storage inspector should find the same items.

What is storedPlaced byWhereWhat it is forLifetime
__clientClerkclerk.statetilt.comIdentifies this browser to Clerk's authentication service and holds the session associated with it. Clerk's own documentation of how its service works describes this item, which it calls the client token.Persists across visits, and is renewed on each visit; measured for this revision as expiring about thirteen months after the most recent visit
__client_uatClerkstatetilt.comRecords whether and when a sign-in last happened, so the page can show signed-in or signed-out state without asking Clerk's service again. For a visitor who has not signed in, it records that no sign-in has happened, and holds nothing else.As above
__client_uat_LUMCTR8qClerkstatetilt.comThe same record, tagged to StateTilt's particular Clerk instance so it cannot be confused with another.As above
__cf_bmCloudflare, which operates the network in front of Clerk's own serviceclerk.statetilt.comCloudflare's bot-management cookie, which distinguishes automated traffic from people. Cloudflare's published cookie documentation is the authoritative description.About thirty minutes from when it is set
_cfuvidCloudflare, as aboveclerk.statetilt.comCloudflare's rate-limiting cookie, which tells apart visitors sharing a network address. Cloudflare's published cookie documentation is the authoritative description.Ends when the browser session ends
__clerk_environment — browser storage, not a cookieClerkstatetilt.comHolds a copy of the settings Clerk's page code needs, so it does not have to fetch them again. It contains nothing about the visitor.Browser storage of this kind is not expired by the browser: it stays on the device until the visitor clears it, or until Clerk's page code replaces it
NothingStateTiltStateTilt's own servers and its own page code write nothing at all to a visitor's deviceNot applicable

Cloudflare appears here because Clerk's own service runs behind Cloudflare's network, not because StateTilt uses Cloudflare. StateTilt has no agreement with Cloudflare. Clerk's own published cookie documentation identifies the _cfuvid cookie as Cloudflare's, and Clerk maintains the current list of the providers it engages, reached from the sub-processors link on the privacy page.

Clerk's script loads on every page of statetilt.com, not only on the sign-in pages, because the site header shows a different state to a signed-in visitor. It runs on this page too, and everything in the table above is placed when it runs — before any sign-in, and whether or not the visitor ever signs in.

Clerk describes the cookies it sets in its own documentation at clerk.com/docs/guides/how-clerk-works/cookies, and describes the client cookie its authentication service places — which it calls the client token — at clerk.com/docs/guides/how-clerk-works/overview. Its data-processing terms are at clerk.com/legal/dpa. Cloudflare publishes its own description of the cookies its network sets at developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/.

V

How to control cookies

Most browsers let a visitor view, restrict, or delete cookies and browser storage through the browser settings, and most offer a mode that discards everything at the end of the browsing session. Storage placed on a vendor's own domain can be reviewed and removed with the same controls.

Blocking or clearing the storage described on this page has these effects. A signed-in visitor is signed out, and the next visit starts from a signed-out state. A visitor who blocks it cannot sign in or use an account. Every public page of this site remains readable exactly as before, including this policy, the privacy policy and the pricing page.

StateTilt shows no cookie-consent banner, so there is no in-page control to withdraw a consent given that way. The browser controls described here are the means of control this site relies on, and they are available to every visitor whether or not they have an account. If StateTilt introduces storage that requires consent, the mechanism described in the previous section will provide a way to give and withdraw it.

VI

Retention

Storage that lasts only for a browser session is discarded when the visitor closes the browser. The table above states, for each item, whether it is of that kind or persists across visits, as recorded from a live visit in the browser. A few points about those figures are worth stating plainly. The authentication cookies are renewed on each visit, so their expiry is measured from the most recent visit, not from the earliest. And the browser-storage entry is not a cookie: the browser does not expire it, so it stays on the device until the visitor clears it, or until Clerk's page code replaces it.

The period for which a signed-in session stays valid before a visitor has to authenticate again is set in the session configuration of StateTilt's own Clerk instance — a setting StateTilt controls through its Clerk account, and whose behaviour Clerk documents in its published session documentation. This page states no figure for it, and the lifetimes in the table above are the storage lifetimes recorded from a live visit rather than a statement of that setting. A figure for it will be published here only once it has been read from that configuration and stated exactly as configured.

StateTilt sets no cookie of its own, so there is no StateTilt-set lifetime to state here.

VII

Changes to this policy

StateTilt may revise this Cookie Policy when what the site stores changes, when the services it embeds change their storage behaviour, or when applicable law changes. Material changes will be posted on this page with a revised “Last updated” date and announced through the channel a subscriber has registered with.

Version 1.1 of this Cookie Policy is subject to revision following professional review at the launch milestone. For privacy questions write to privacy@statetilt.com.