Skip to main content
Legal · Cookie Policy

Cookie Policy

Last updated: 2026-09-06Version 1.1Subject to revision at launch
I

What cookies are

Cookies are small data items a website, or a service embedded in it, stores on a visitor's device. Browsers offer related storage, such as localStorage and sessionStorage; this policy covers both and calls all of it “cookies”. The Privacy Policy describes how personal data more generally is processed.

II

Categories of cookies we use

  • Strictly necessary. Authentication and security storage, all of it placed by Clerk and by Cloudflare. Where it is stored on the statetilt.com domain it is first-party with respect to StateTilt; on Clerk's own domain it is third-party.
  • Analytics. StateTilt uses Umami, a cookieless analytics service, to measure aggregate site traffic and where visitors arrive from. It sets no cookies and stores nothing on the device. Umami's published documentation states that it collects no personally identifiable information and does not track visitors across other sites. No cookie-consent banner is shown for analytics.
  • Functional. StateTilt sets none: the product has no colour-theme, language or personalisation setting to remember.
  • Marketing and advertising. StateTilt sets none and permits none to be set on its behalf.
III

Cookies set by StateTilt and embedded vendors

StateTilt sets no cookies of its own, and its own page code writes nothing to a visitor's browser storage. Everything below was placed by an embedded service and recorded from a live visit in a browser that had never visited this site and was not signed in.

What is storedPlaced byWhereWhat it is forLifetime
__clientClerkclerk.statetilt.comIdentifies this browser to Clerk's authentication service and holds its session. Clerk calls it the client token.Persists across visits, renewed on each visit; measured as expiring about thirteen months after the latest visit
__client_uatClerkstatetilt.comRecords whether and when a sign-in last happened, so the page can show signed-in or signed-out state without asking Clerk's service again. For a visitor who has not signed in, it records that no sign-in has happened, and holds nothing else.As above
__client_uat_LUMCTR8qClerkstatetilt.comThe same record, tagged to StateTilt's own Clerk instance.As above
__cf_bmCloudflareclerk.statetilt.comCloudflare's bot-management cookie, which distinguishes automated traffic from people.About thirty minutes from when it is set
_cfuvidCloudflareclerk.statetilt.comCloudflare's rate-limiting cookie, which tells apart visitors sharing a network address.Ends when the browser session ends
__clerk_environment — browser storage, not a cookieClerkstatetilt.comHolds a copy of the settings Clerk's page code needs. It contains nothing about the visitor.Not expired by the browser; stays until cleared or replaced by Clerk's page code

Cloudflare appears here because Clerk's service runs behind its network, not because StateTilt uses Cloudflare; StateTilt has no agreement with Cloudflare. Clerk maintains the current list of the providers it engages, reached from the sub-processors link on the privacy page. Clerk documents its cookies at clerk.com/docs/guides/how-clerk-works/cookies and the client token at clerk.com/docs/guides/how-clerk-works/overview; its data-processing terms are at clerk.com/legal/dpa. Cloudflare documents its cookies at developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/.

V

How to control cookies

Most browsers let a visitor view, restrict or delete cookies and browser storage in their settings, and most offer a mode that discards everything when the session ends. Storage placed on a vendor's own domain is reviewed and removed the same way. Blocking or clearing it signs a signed-in visitor out and prevents signing in; every public page of this site remains readable. StateTilt shows no cookie-consent banner, so there is no in-page control to withdraw a consent given that way.

VI

Retention

The period for which a signed-in session stays valid before a visitor must authenticate again is set in the session configuration of StateTilt's own Clerk instance. This policy states no figure for it: the lifetimes above are measured storage lifetimes, not that setting.

VII

Changes to this policy

StateTilt may revise this policy when what the site stores changes or when the law changes. Material changes are posted here with a revised “Last updated” date and announced through the channel a subscriber has registered with.

Version 1.1 of this Cookie Policy is subject to revision following professional review at the launch milestone. For privacy questions write to privacy@statetilt.com.