A short cookie note.
We use as few cookies as we can get away with. These are the ones we do use.
Which cookies does CiteSurge use?
CiteSurge sets Auth.js session cookies only after sign-in. Google Analytics 4 and Mixpanel analytics operate only after analytics consent; Mixpanel is limited to the customer dashboard and does not record sessions. Stripe may set required fraud-protection cookies when a user opens billing or checkout. CiteSurge does not use marketing pixels, cross-site tracking, session-replay tools, or advertising-network cookies. The local cs:tweaks preference is stored in the browser, sends no network request, and is not a cookie.
Which cookies are strictly necessary?
cs:tweaks: a local-storage entry (not a cookie, but honest to mention) that remembers which chromatic signature and hero variant you picked. No identifiers, no tracking, no network traffic.
Auth.js session cookies: only set after you sign in to the agency workspace. Strictly necessary for authentication.
Which analytics does CiteSurge use?
_ga, _ga_*: Google Analytics 4. Aggregate, anonymized visitor counts. Only set if you accept analytics in the cookie banner.
mp_*: Mixpanel product analytics, stored in local storage (not a cookie), used only inside the customer dashboard to see which sections get used. EU-hosted, pseudonymous, no session recording. Only set if you accept analytics in the cookie banner.
Payments
Stripe cookies: set by stripe.com only when you reach the billing portal or a checkout page. Required for fraud protection.
What we do not use
- Marketing pixels.
- Cross-site tracking.
- Session-replay tools.
- Ad-network cookies.
Turning cookies off
Decline analytics in the cookie banner. You can also clear or block cookies in your browser at any time. The site will still work. The chromatic signature will reset to its default on next visit.
Contact
Questions: privacy@citesurge.com.