Skip to content

Cookie Policy

A short list, because we keep it short: the cookies that sign you in, the preferences your browser remembers for you, and how this website counts visits without cookies.

Effective
September 24, 2026
Last updated
September 24, 2026
Version
1.1 (early access)
On this page
  1. About this policy
  2. What we use, in brief
  3. Cookies in the apps
  4. Local and session storage in the apps
  5. Session storage on this website
  6. Cookieless measurement on this website
  7. This website
  8. Third-party sign-in
  9. Why there is no cookie banner
  10. How to control cookies and storage
  11. Changes and contact

1.About this policyLink to section 1

This Cookie Policy explains the cookies and similar browser storage used by LiteSurface, Inc. on this website and in LiteSurface (the web application and the admin console). It supplements our Privacy Policy.

A cookie is a small text file a website asks your browser to keep and send back on later requests. Local storage is a similar browser feature that keeps data on your device; it is not sent to our servers automatically. Session storage works the same way but is cleared when you close the browser tab.

2.What we use, in briefLink to section 2

  • This marketing website sets no cookies and loads no third-party analytics, advertising, or social media scripts.
  • This website counts visits without cookies: anonymous, first-party events sent to our own server, with no identifier. They stop if your browser sends Do Not Track or Global Privacy Control. See cookieless measurement.
  • This website keeps up to three items in session storage, cleared when you close the tab: where your visit came from, for sign-up links, and whether you dismissed two notices. See session storage.
  • The apps use only strictly necessary cookies, to sign you in and keep your session secure.
  • The apps keep two appearance preferences in local storage so the interface looks the way you left it.
  • We do not use third-party cookies, and we do not track you across other websites.

3.Cookies in the appsLink to section 3

These cookies are set by our authentication service when you use the web application or admin console. All are first-party, are marked HttpOnly so page scripts cannot read them, use SameSite=Lax, and in production are marked Secure and carry a __Secure- prefix (for example, __Secure-if.session_token).

Strictly necessary cookies
NamePurposeWhen it is setDuration
if.session_tokenIdentifies your signed-in session so you stay signed in across pages and apps.When you sign inUp to 30 days; renewed as you use the Service; removed when you sign out
if.session_dataA signed, short-lived copy of your session details that avoids a database lookup on every request.When you sign in5 minutes, refreshed while you are active
if.dont_rememberRecords that you chose not to stay signed in, so your session ends when you close the browser.Only if you sign in without staying signed in, where that option is offeredBrowser session
if.stateProtects a sign-in with Google or GitHub against cross-site request forgery.Only while you sign in with a third-party providerUp to 10 minutes

We do not set a separate cross-site request forgery (CSRF) token cookie. Instead, the authentication service checks that requests come from our own trusted origins, and the SameSite attribute limits when browsers send cookies.

4.Local and session storage in the appsLink to section 4

Local storage (preferences)
KeyPurposeWhereDuration
if.themeYour light or dark theme choice. Not stored when you follow your system setting.Web application and admin consoleUntil you change it or clear site data
if.appearanceYour layout preferences, such as menu style, header style, and accent color.Web application and admin consoleUntil you change it or clear site data

These values stay in your browser, are never sent to our servers, and contain no personal data.

Session storage (sign-up)
KeyPurposeWhereDuration
if.signupIntentThe plan, call to action, referral code, and campaign parameters carried by the sign-up link you followed. When you create an account, these values are saved with it so we know which page or campaign led to sign-up.Web application sign-upUntil the tab is closed or sign-up completes

5.Session storage on this websiteLink to section 5

Session storage on this website
KeyPurposeContentsDuration
if.attributionRemembers how this visit started, so that a sign-up link you click later can carry it to the app. The same values accompany the anonymous events described below.Campaign parameters from the link you arrived by (utm_source, utm_medium, utm_campaign, utm_term, utm_content), a ref code if the link had one, and the host name of the referring website. No identifier.Until you close the tab
if.announcement.dismissedKeeps the early-access note closed after you dismiss it.The value 1Until you close the tab
if.stickyCta.dismissedKeeps the mobile sign-up bar closed after you dismiss it.The value 1Until you close the tab

if.attribution is not written at all when your browser sends Do Not Track or Global Privacy Control. Its values leave your browser only as query parameters on the sign-up link you click (for example utm_source=newsletter) and inside the anonymous events below.

6.Cookieless measurement on this websiteLink to section 6

To learn which pages help people decide, this website counts a few events: a page view, a click on a sign-up or other call-to-action link, use of the scorecard demo, viewing the sample evaluation, submitting the updates form, and clicking an email address. Each event is one small request from your browser to this website’s own /api/e endpoint, never to a third party.

What an event contains
SentNot sent or stored
The event name; the page path without any query string; the referring website’s host name (first page of a visit only); the campaign parameters above; for clicks, which link, where on the page, where it leads, and the plan chosenCookies, device or user identifiers, your IP address, your browser’s user agent, anything typed into forms, or anything that lets events be joined into a profile of you

Our server drops events from browsers that send Do Not Track or Global Privacy Control, from known bots, and from other websites, then stores the rest as anonymous rows that we read only as counts. We keep them for up to 24 months. Your IP address reaches our servers as part of every web request, as described in the Privacy Policy, but it is not stored with these events.

7.This websiteLink to section 7

This website does not set cookies or use local storage; it uses the session storage and cookieless measurement described above. Our hosting provider receives standard technical information with each request, such as your IP address and browser type, to deliver pages and protect against abuse; that is covered by the Privacy Policy. Links to sign up or sign in take you to the web application, where the cookies above apply. Because the apps and this website can share a parent domain, a browser that is signed in to the apps may also send the session cookie with requests to this website; this website does not read or use it.

8.Third-party sign-inLink to section 8

If you choose to sign in with Google or GitHub, you are briefly redirected to that provider, which may set its own cookies on its own domain under its own policies. LiteSurface does not control those cookies.

10.How to control cookies and storageLink to section 10

You can view, block, or delete cookies and site data in your browser settings. Browser makers publish instructions, for example for Chrome (opens in a new tab), Firefox (opens in a new tab), Safari (opens in a new tab), and Edge (opens in a new tab).

What happens if you block them

Blocking or deleting the strictly necessary cookies signs you out and prevents sign-in. Clearing local storage resets your theme and layout preferences to their defaults.

To switch off this website’s measurement and sign-up attribution, turn on Global Privacy Control or Do Not Track in your browser. Closing the tab clears session storage.

We treat Global Privacy Control signals as a request to opt out of the sale or sharing of personal data, and as a request to switch off this website’s measurement and attribution; we do not sell or share personal data in any case.

11.Changes and contactLink to section 11

We will update this policy, and the tables above, before we change the cookies or storage we use, and record the change in the changelog. Questions: privacy@litesurface.com.

Questions about this document

Write to legal@litesurface.com for legal questions or privacy@litesurface.com for privacy requests. Postal notices go to LiteSurface, Inc., [Registered address to be confirmed].