Cookie Policy
Categories of cookies we use
The categories below describe what is stored today.
- Strictly necessary. This is the category into which authentication and security storage conventionally falls. StateTilt's own servers set no cookies, and StateTilt's own page code writes nothing to a visitor's browser storage. What is stored comes from the authentication service StateTilt uses, Clerk, and from the network Clerk's own service sits behind. It keeps a signed-in visitor authenticated, operates the sign-in flow, protects that flow against automated abuse, and holds a cached copy of the settings the sign-in code needs. Where it is stored on the statetilt.com domain it is first-party with respect to StateTilt; where it is stored on Clerk's own domain it is third-party. The section below names every item, and the Consent section sets out what StateTilt does and does not claim about each of them.
- Analytics. StateTilt uses Umami, a cookieless analytics service, to measure aggregate site traffic and where visitors arrive from. It sets no cookies and stores nothing on the visitor's device. Umami's published documentation states that it collects no personally identifiable information and does not track visitors across other sites. Because nothing is stored on the device, StateTilt shows no cookie-consent banner for analytics. If StateTilt later uses analytics that store data on a visitor's device or process personal data, this policy and a consent mechanism will be updated before that change takes effect.
- Functional. StateTilt sets no functional cookies. The product has no colour-theme, language or personalisation setting to remember, so nothing of that kind is stored.
- Marketing and advertising. StateTilt sets no marketing or advertising cookies and permits none to be set on its behalf.
Consent
For visitors located in the European Economic Area or the United Kingdom, e-Privacy Directive Article 5 requires informed consent before anything that is not strictly necessary is stored on a visitor's device.
StateTilt stores nothing of its own, and sets no analytics, marketing or preference storage. The analytics service it uses, Umami, is cookieless and stores nothing on the device, so no cookie-consent banner is shown for analytics or marketing.
The items in the table above are a different case, and StateTilt sets out its position on each rather than leaving it to be inferred.
- The security items placed by Cloudflare exist to protect Clerk's authentication service against automated abuse and to keep individual visitors apart for rate limiting. StateTilt treats these as strictly necessary and exempt from consent.
- The authentication items placed by Clerk are strictly necessary in the role they exist for: keeping a signed-in visitor authenticated and operating the sign-in flow. Because the site header shows sign-in state on every page, they are also placed for a visitor who has not signed in and may never sign in. StateTilt does not assert the strictly-necessary exemption for that case, and does not treat this page as settling it.
- The browser-storage entry holds a copy of the settings Clerk's page code needs. It contains nothing about the visitor. It is stored to save a request rather than because the site cannot work without it, and StateTilt does not claim it as strictly necessary.
What a visitor can do about any of it today is set out in the next section. This storage can be removed and blocked with ordinary browser controls, and nothing on the public side of this site depends on it: every page remains readable without it, and only signing in requires it.
Should StateTilt introduce storage that is not strictly necessary and is not described above, a consent mechanism meeting the applicable e-Privacy and GDPR consent standards will be implemented before that storage is written, and this policy will be revised accordingly.
How to control cookies
Most browsers let a visitor view, restrict, or delete cookies and browser storage through the browser settings, and most offer a mode that discards everything at the end of the browsing session. Storage placed on a vendor's own domain can be reviewed and removed with the same controls.
Blocking or clearing the storage described on this page has these effects. A signed-in visitor is signed out, and the next visit starts from a signed-out state. A visitor who blocks it cannot sign in or use an account. Every public page of this site remains readable exactly as before, including this policy, the privacy policy and the pricing page.
StateTilt shows no cookie-consent banner, so there is no in-page control to withdraw a consent given that way. The browser controls described here are the means of control this site relies on, and they are available to every visitor whether or not they have an account. If StateTilt introduces storage that requires consent, the mechanism described in the previous section will provide a way to give and withdraw it.
Retention
Storage that lasts only for a browser session is discarded when the visitor closes the browser. The table above states, for each item, whether it is of that kind or persists across visits, as recorded from a live visit in the browser. A few points about those figures are worth stating plainly. The authentication cookies are renewed on each visit, so their expiry is measured from the most recent visit, not from the earliest. And the browser-storage entry is not a cookie: the browser does not expire it, so it stays on the device until the visitor clears it, or until Clerk's page code replaces it.
The period for which a signed-in session stays valid before a visitor has to authenticate again is set in the session configuration of StateTilt's own Clerk instance — a setting StateTilt controls through its Clerk account, and whose behaviour Clerk documents in its published session documentation. This page states no figure for it, and the lifetimes in the table above are the storage lifetimes recorded from a live visit rather than a statement of that setting. A figure for it will be published here only once it has been read from that configuration and stated exactly as configured.
StateTilt sets no cookie of its own, so there is no StateTilt-set lifetime to state here.
Changes to this policy
StateTilt may revise this Cookie Policy when what the site stores changes, when the services it embeds change their storage behaviour, or when applicable law changes. Material changes will be posted on this page with a revised “Last updated” date and announced through the channel a subscriber has registered with.
Version 1.1 of this Cookie Policy is subject to revision following professional review at the launch milestone. For privacy questions write to privacy@statetilt.com.