Legal

Cookie Policy

This policy lists every cookie Insight Driven Ads sets, what each one is for and how long it lasts. There are four, all of them strictly necessary to sign you in and keep the session safe. We set no advertising, profiling or cross-site tracking cookies.

Last updated
September 9, 2026
Effective
September 9, 2026
Applies to
Insight Driven Ads

The short version

A summary for orientation only. The numbered sections below are the binding text.

Four cookies, all essential

Each one exists to sign you in, return you to the right page, or block a specific attack. None of them profile you.

Our analytics are cookieless

We run a self-hosted Umami instance that counts page views in aggregate. It sets no cookie and assigns you no cross-site identifier.

No advertising trackers

No Google Analytics, no ad pixels, no remarketing tags, no data brokers, no fingerprinting.

That is why there is no banner

Strictly necessary cookies do not require consent, so we do not interrupt you to ask for something we do not need.

1.What cookies are

A cookie is a small text file a website asks your browser to store and send back on later requests. Because HTTP has no memory of its own, a cookie is how a site recognises that the request it just received came from the same browser as the last one — which is what makes staying signed in possible.

Cookies are described by who sets them and how long they last. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain and is the kind normally used to follow people between sites. A session cookie is discarded when you close the browser; a persistent one has a fixed expiry.

Related technologies include local storage and similar browser storage. We do not use any of them.

2.Our position

Strictly necessary cookies only

We set four cookies. Every one is required for authentication or security. If they were blocked, you could not sign in and the site could not defend itself against forged requests. We do not set cookies for advertising, remarketing, profiling, A/B testing, social sharing or cross-site measurement.

The table in the next section is the complete list. It is generated from the same constants the application uses, so it cannot silently fall out of date the way a hand-written list does.

3.Cookies we set

Cookie

__Secure-authjs.session-token

What it does

Keeps you signed in. Holds a signed token identifying your session — not your password. HttpOnly, so scripts on the page cannot read it.

Lifetime

7 days, refreshed daily while you stay active

Category

Strictly necessary

Cookie

__Host-authjs.csrf-token

What it does

Blocks cross-site request forgery: proves a submission came from our site and not from another page acting as you.

Lifetime

Session — removed when you close the browser

Category

Strictly necessary

Cookie

__Secure-authjs.callback-url

What it does

Remembers the page you were heading to, so signing in returns you there instead of the dashboard root.

Lifetime

Session — removed when you close the browser

Category

Strictly necessary

Cookie

__Secure-authjs.human-grant

What it does

Set only during sign-up. Records that a bot check was already solved, so creating an account and being signed in a second later does not demand a second challenge. Bound to one email address.

Lifetime

5 minutes

Category

Strictly necessary

A note on the names

The __Secure- and __Host- prefixes are not decoration. They are instructions to your browser: a __Secure- cookie is refused unless it arrives over HTTPS, and a __Host- cookie additionally cannot be set by a subdomain — which is what stops another host from planting a session on you. Over plain HTTP in local development the prefixes are absent, and the names appear without them.

All four are HttpOnly, so JavaScript running on the page cannot read them, and all are marked SameSite=Lax, so they are not sent on cross-site requests that could be used to act as you.

4.Analytics

We want to know which pages and tools people use, and we would rather learn that without tracking anyone. So we run our own Umami instance on infrastructure we control, instead of sending visitors to a third-party analytics company.

  • It sets no cookies at all.
  • It assigns no persistent or cross-site identifier, so it cannot follow you to another website.
  • It records aggregate counts — page views, referrer, rough country, device type — not individual profiles.
  • The data stays on our infrastructure and is not sold, shared or used for advertising.

We also run a self-hosted error tracker to capture crashes and faults. It sends technical diagnostics with authentication cookies and credentials removed before transmission, and it is not used to build a profile of you.

5.Third-party contexts

Two third parties can set their own cookies when you interact with the feature they power. They do so in their own context and under their own policy, not ours:

Stripe

When you open checkout or the billing portal, Stripe sets the cookies it needs to process the payment and detect fraud. These are governed by Stripe's own privacy policy.

Read their privacy policy

Cloudflare Turnstile

The bot check on our sign-up, sign-in and password-reset forms may store a short-lived token confirming the challenge was solved. Turnstile is designed not to track users across sites.

Read their privacy policy

Both are there for a functional reason — taking a payment, and telling a human from a bot — and neither is used by us for advertising. We have no advertising or social-media pixels on the site.

7.Managing cookies

You are always in control of your browser. Every major browser lets you view, delete and block cookies from its privacy or site-settings panel, and you can usually manage them for one site independently of the rest.

Blocking these cookies will break sign-in

Because ours are the cookies that carry your session and its CSRF protection, blocking or deleting them signs you out. If you block them entirely, you will not be able to sign in at all — the browser will discard the session as soon as it is issued. Nothing is lost from your account; you simply cannot reach it until they are allowed again.

  • Signing out clears your session cookie deliberately, which is the cleanest way to end a session on a shared computer.
  • Private or incognito windows discard all cookies when closed, so you will be signed out each time.
  • Clearing site data for this domain removes all four cookies at once.

8.Do Not Track and Global Privacy Control

There is still no agreed standard for how sites should respond to a browser Do Not Track header, so like most sites we do not act on it. In practice this changes nothing here: we do not track you across sites whether or not the header is sent.

We honour Global Privacy Control signals as a valid opt-out where the law treats them as one. Since we do not sell or share personal information — see our Privacy Policy — there is no sharing for such a signal to stop.

9.Changes and contact

If we add, remove or change a cookie, we will update this page and its revision date. A change that introduces a non-essential cookie will be accompanied by a consent mechanism, not applied quietly.

This policy forms part of our Privacy Policy and is governed by the laws of the State of Florida, United States.

If you find a cookie on this site that is not listed above, we would genuinely like to know — tell us at info@insightdrivenads.com.

Questions about this policy?

Questions about a specific cookie, or something you found that is not on the list — write to us and a person will answer.

info@insightdrivenads.com

See also Privacy Policy · Terms of Service · Cookie Policy