Cookie Policy
Cookies used by SiteRevenue: essential session (sr_sid), share flash, Stripe on the pay page. Analytics opt-in. No ads pixels.
Last updated: 2026-09-17
Product: SiteRevenue (siterevenue.ai)
Controller: GigaSolo LLC, a Wyoming limited liability company, operating SiteRevenue
Contact: hello@siterevenue.ai
This Cookie Policy explains how SiteRevenue uses cookies and similar technologies. It should be read with our Privacy Policy.
1. What are cookies?
Cookies are small text files stored on your device by a website. Essential cookies are required for core security and product features you request.
Browser storage: SiteRevenue authentication and workspace binding use HttpOnly cookies only (sr_sid, and briefly sr_share_flash). We do not store session tokens, API keys, or magic-link secrets in localStorage or sessionStorage for authentication. Appearance preference (sr-theme) and, when PostHog is configured, sr-posthog-workspace-id live in localStorage — see §3.2.
2. Analytics and advertising technologies
As of the last-updated date, SiteRevenue does not load Google Analytics (GA4/gtag), Google AdSense, or other advertising or social tracking pixels.
When PUBLIC_POSTHOG_PROJECT_TOKEN is configured, we load the PostHog product-analytics snippet. PostHog sets first-party analytics cookies and storage (see §3.3). This is product analytics, not an advertising pixel.
Cloudflare Web Analytics (when enabled) does not set SiteRevenue marketing cookies. It is privacy-oriented pageview measurement at the edge.
We display a cookie consent banner on first visit. Necessary cookies (session, share flash, and Stripe on the pay page) always run so audits and payment work. Analytics cookies (PostHog or GA4, only when those products are configured) stay off until you choose Accept analytics. You can also choose Necessary only, or control cookies in your browser as described in §5.
3. Cookies we set
| Name | Type | Purpose | Duration | Flags (typical) |
|---|---|---|---|---|
sr_sid | Essential / first-party | Signed session binding your browser to a SiteRevenue workspace (sites, audits, entitlements, account). Contains an opaque signed payload (workspace id, optional email, expiry)—not your password. | Up to 90 days (Max-Age; signed exp also enforced server-side). Magic-link recovery may issue a session up to 30 days. | Path=/; HttpOnly; SameSite=Lax; Secure on non-local HTTPS deploys |
sr_share_flash | Essential / first-party | One-shot flash after you create a share link in the HTML UI: carries the share URL briefly so it is not left in the query string. Cleared after read or max age. | About 120 seconds (Max-Age=120), then cleared | Path=/; HttpOnly; SameSite=Lax; Secure on non-local HTTPS deploys |
__stripe_mid | Essential / first-party (Stripe.js) | Fraud prevention when you open the pay page (js.stripe.com). Set by Stripe, not by our session code. | About 1 year | Set by Stripe.js on this origin after you start Checkout |
__stripe_sid | Essential / first-party (Stripe.js) | Short Stripe fraud session, same as above | About 30 minutes | Set by Stripe.js on this origin after you start Checkout |
Stripe may also set cookies on Stripe-controlled domains (stripe.com, checkout.stripe.com, js.stripe.com, m.stripe.com) as part of payment. We load Stripe.js only on the pay page after you choose Unlock — not on marketing HTML. We do not block Stripe behind “Accept analytics”; payment is a service you requested.
3.1 What we do not set
- Google Analytics (GA4/gtag) cookies
- Google AdSense or other advertising cookies
- Social network tracking cookies
- Marketing-preference cookies beyond the first-visit necessary / analytics choice (
localStoragekeysr-consent)
Cloudflare or the browser may process standard network/edge data independently of our named application cookies; that is infrastructure, not additional SiteRevenue marketing cookies.
3.2 Other first-party storage (not cookies)
| Name | Type | Purpose | Duration |
|---|---|---|---|
sr-theme | First-party localStorage | Light or dark appearance preference. Values: light or dark. Not used for authentication, advertising, or cross-site tracking. | Until you clear site data or change the theme toggle |
sr-consent | First-party localStorage | Your cookie choice (v: 1 and whether analytics is on). Necessary cookies do not wait on this. | Until you clear site data |
sr-posthog-workspace-id | First-party localStorage | Remembers the last PostHog distinct_id (workspace id) so we can reset() if you later use a different email-bound workspace on this browser. Not a session cookie; not an API key. | Until you clear site data or we reset identity |
These are not HttpOnly cookies. sr-theme is a display preference. sr-posthog-workspace-id only exists when PostHog is configured.
3.3 PostHog (when configured)
The PostHog JavaScript snippet (loaded from the configured ingest host, currently PostHog US Cloud) sets first-party cookies and storage on this origin. Names typically start with ph_. They remember an anonymous visitor id, session, and (after identify) the workspace person.
PostHog may also capture pageviews, product events, and unhandled exceptions. We send checkout/magic email to PostHog only after the workspace is email-bound. Anonymous teasers stay anonymous.
This is product analytics — not Google Analytics and not an advertising pixel. The snippet loads only after you choose Accept analytics. See Privacy Policy §7.
4. Why these cookies are essential
| Cookie | Why essential |
|---|---|
sr_sid | Without a session, multi-page audit flows, “My Audits”, account/API keys, checkout return binding, and workspace isolation cannot function securely. |
sr_share_flash | Allows safe delivery of a newly minted share URL to the next page without putting a long-lived secret in the URL bar or history longer than necessary. |
__stripe_mid / __stripe_sid | Stripe fraud detection so we can take $19 (and other) payments without storing card numbers. Loaded only on the pay page. |
5. Managing cookies
You can delete or block cookies in your browser settings. If you block sr_sid:
- You may lose access to in-progress workspace history in that browser
- Paid audits may still be recoverable via email magic link when that feature is configured (Open with email)
Blocking sr_share_flash only affects the immediate post-mint share UX; share links themselves use URL tokens with their own expiry (~14 days), not this cookie.
6. Related lifetimes (not always cookies)
These are not permanent browser cookies but matter for privacy:
| Mechanism | Lifetime | Storage |
|---|---|---|
| Magic-link email token | ~20 minutes | Server-side hash in database |
Share link token (/s/:token) | ~14 days unless revoked | Server-side hash; raw token only in the link |
| API keys | Until you revoke | Server-side hash; raw key shown once |
7. Changes
If we add, rename, or reclassify cookies, we will update this page and the Last updated date. Material introduction of non-essential cookies will be accompanied by appropriate notice or consent mechanisms where required by law.
8. Contact
Questions: hello@siterevenue.ai
Controller: GigaSolo LLC (Wyoming, United States)
Related: Privacy Policy · Terms of Service · Acceptable Use Policy