Legal · Cookies

A short cookie note.

We use as few cookies as we can get away with. These are the ones we do use.

Last updated · 7 August 2026

Which cookies does CiteSurge use?

CiteSurge sets Auth.js session cookies only after sign-in. Google Analytics 4 and Mixpanel analytics operate only after analytics consent; Mixpanel is limited to the customer dashboard and does not record sessions. Stripe may set required fraud-protection cookies when a user opens billing or checkout. CiteSurge does not use marketing pixels, cross-site tracking, session-replay tools, or advertising-network cookies. The local cs:tweaks preference is stored in the browser, sends no network request, and is not a cookie.

Which cookies are strictly necessary?

cs:tweaks: a local-storage entry (not a cookie, but honest to mention) that remembers which chromatic signature and hero variant you picked. No identifiers, no tracking, no network traffic.

Auth.js session cookies: only set after you sign in to the agency workspace. Strictly necessary for authentication.

Which analytics does CiteSurge use?

_ga, _ga_*: Google Analytics 4. Aggregate, anonymized visitor counts. Only set if you accept analytics in the cookie banner.

mp_*: Mixpanel product analytics, stored in local storage (not a cookie), used only inside the customer dashboard to see which sections get used. EU-hosted, pseudonymous, no session recording. Only set if you accept analytics in the cookie banner.

Payments

Stripe cookies: set by stripe.com only when you reach the billing portal or a checkout page. Required for fraud protection.

What we do not use

Turning cookies off

Decline analytics in the cookie banner. You can also clear or block cookies in your browser at any time. The site will still work. The chromatic signature will reset to its default on next visit.

Contact

Questions: privacy@citesurge.com.