Cookie & Storage Notice
Last updated: 15 June 2026
This notice explains what Self-Control stores on your device and why. It supplements our Privacy Policy. Self-Control is deliberately light on cookies: we do not use third-party advertising or cross-site tracking cookies.
How we keep you signed in
- Access token (in memory only). Your short-lived access token lives in the web app's memory and is never written to disk or a cookie. It disappears when you close the tab.
- Refresh cookie (HttpOnly). A single secure, HttpOnly cookie scoped to our API origin (
Path=/api/auth,SameSite=Lax,Secureover HTTPS) lets us renew your session without you signing in again. It is not readable by JavaScript and is not used for tracking.
On the mobile apps, the equivalent refresh token is held in the device's secure storage (Keychain / Keystore), not in cookies.
Categories of storage we use
| Category | Examples | Purpose | Set by |
|---|---|---|---|
| Strictly necessary | rt HttpOnly refresh cookie; in-memory access token | Authentication and security | Self-Control |
| Preferences | Local-storage UI settings (filters, timezone) | Remember your interface choices | Self-Control |
| Checkout | Cookies set during the payment flow | Process your subscription securely | Paddle |
Analytics and your choice
We set no analytics or advertising cookies, and no cross-site tracking. We do run our own first-party, cookieless usage analytics to understand how the Service is used and which channels bring people to it (for example, Product Hunt versus a search engine). As you move through the site we record anonymous, aggregate signals: the page you are viewing (as a fixed page name, never a full web address), the broad category of site that referred you (for example "a search engine" — never a full address), roughly how long a page stays open, whether the visitor is signed in, and how quickly the page loaded and responded (recorded only as a rating of "good", "needs improvement" or "poor" — the underlying timings stay in your browser and are never sent to us). When you create an account we also note your arrival's marketing campaign tags (UTM parameters). All of this is read from your browser and sent to us in the moment; nothing is stored on your device for it (no cookie, no local storage), it carries no persistent identifier that could follow you across visits, and it holds no special-category personal data.
If you arrive from an advertisement we run, the link may also carry the ad platform's click identifier (for example Google's gclid or Reddit's rdt_cid). We read it the same in-the-moment way — no cookie, no pixel, nothing stored on your device — and it names that one ad click, not you across visits. If, and only if, you create an account in that same session, we keep the identifier server-side for up to 90 days, solely to tell the ad platform, server to server, that its ad led to a sign-up or subscription so we can measure our advertising. That report never includes your name or email, and the identifier is deleted after 90 days at the latest — immediately if you delete your account.
Because this analytics is cookieless and anonymous it needs no consent — but you can still turn it off: we honor your browser's Do Not Track and Global Privacy Control signals, and signed-in users can switch it off under Settings → Your data. How we use these records is covered by our Privacy Policy.
Strictly necessary storage (the sign-in cookie and the in-memory token) cannot be switched off because the Service cannot function without it. You can clear cookies and local storage at any time in your browser settings.
Third-party notices
- Paddle (checkout) — see Paddle's own cookie and privacy notices, which apply during payment.
Contact
Questions about this notice: privacy@self-control.app.