policy
Cookies and local storage
Last updated 19 August 2026
Separated the same way the privacy policy separates them, because the answers are genuinely different: what this marketing site puts on your device, and what our script puts on your visitors' devices when you install it.
This website
This marketing site sets no analytics cookies and runs no third-party tracking. There is no consent banner because there is nothing to consent to.
If you sign up for the beta, the form is hosted by Splitform and may set cookies necessary for the form to function. Their policy governs that, and we will name them in our sub-processor list.
We run our own product on this site. If what we collect here changes, this page changes and the date at the top changes with it.
The tracking script, when you install it
The script can run in two modes and the difference is worth understanding, because it changes what lands on your visitors' devices.
Cookieless mode
No cookie is set. A visitor is identified by an anonymous value derived from a rotating daily salt combined with request characteristics. The salt is destroyed after 24 hours, which means the identifier cannot be reconstructed afterwards and a visitor cannot be followed across days.
That is a genuine privacy property and a real measurement limitation. A visitor who returns tomorrow is a new person as far as the system is concerned, and any funnel spanning more than a day will undercount.
First-party cookie mode
A single first-party cookie is set, containing an opaque identifier and nothing else. No personal data, no email, no cross-site identifier, and it is never shared with a third party.
It has to be set server-side from a genuine first-party origin. Safari's tracking prevention caps cookies set by JavaScript at 7 days, while a cookie set server-side from a real first-party origin can persist far longer. We do not use CNAME cloaking to fake a first-party origin, which some vendors do and which we consider dishonest about what it is doing.
Global Privacy Control
The script honours the Sec-GPC header. A visitor whose browser signals Global Privacy Control does not get a cookie, regardless of which mode you have configured.
Whether you need a consent banner
That depends on your jurisdiction and your legal basis, and it is your assessment rather than ours. What we will say is that cookieless does not automatically mean consent-free. The European Data Protection Board's October 2024 guidance covers storing or accessing information on a device by various means, not only cookies.
The longer version of that argument, and why we refuse to make the convenient claim, is in the privacy policy.
Questions about any of this go to privacy@paidamplification.com. Our other policies: Privacy, Terms, Cookies, Security, Sub-processors.