Legal

Cookie Policy

Effective:
September 3, 2026
Last updated:
September 3, 2026

This page lists every cookie YouTube Writer sets and explains what each one does. The short version: we only use cookies that are strictly necessary to keep you signed in and to protect the login pages from automated attacks, and our analytics are cookieless. There are no advertising trackers, which is why you see no cookie banner.

1. Summary

We use strictly necessary cookies only. We do not use advertising cookies, analytics cookies, social media cookies or any cross-site tracking technology. Our analytics are cookieless and use a single browser storage key, described in Section 5.

This Cookie Policy explains the cookies and similar technologies used on youtubewriter.com and in the YouTube Writer application (the "Service"), what each one does, and how you can control them. It supplements our Privacy Policy.

Because the only cookies we set are those required to deliver a service you have asked for, and our analytics set no cookies at all, we do not show a cookie consent banner. If we ever introduce a non-essential cookie, we will ask for your consent first and update this page before doing so. Section 5 explains how to switch analytics off if you would rather not be counted.

2. What Cookies Are

A cookie is a small text file that a website asks your browser to store and send back on later requests. Cookies set by the site you are visiting are called first-party cookies; cookies set by another domain are third-party cookies. A session cookie is deleted when you close your browser, while a persistent cookie remains until it expires or you delete it.

Related technologies include local storage and session storage, which also keep data in your browser but are not sent automatically with every request.

3. Cookies We Set

These first-party cookies are set by our authentication system. They are strictly necessary: without them we cannot tell that a request comes from a signed-in user, so you could not stay logged in.

CookiePurposeTypeExpires
better-auth.session_tokenHolds the signed token that identifies your login session. This is the cookie that keeps you signed in.First-party, strictly necessaryUp to 7 days from issue, or sooner if you sign out or the session is revoked
better-auth.session_dataHolds a short-lived cached copy of basic session data, so that not every page load has to query the database. Only set when session caching is enabled.First-party, strictly necessaryA few minutes
better-auth.dont_rememberRecords that a session should not persist beyond the current browser session, where that option was used at sign-in.First-party, strictly necessaryCurrent browser session

When the Service is served over HTTPS, these cookie names carry a __Secure- prefix, which instructs the browser to send them only over encrypted connections. They are also marked HttpOnly, so page scripts cannot read them, and SameSite, which limits when they are sent on cross-site requests.

4. Third-Party Cookies

The sign-in, sign-up and password-reset pages load a bot-protection challenge from our captcha provider. That provider may set its own cookies or use similar local storage in order to run the challenge, detect automated clients and remember that a challenge has recently been passed.

These are strictly necessary for the security of the credential endpoints: without them, those pages would be exposed to automated credential-stuffing attacks. The provider does not use them to build an advertising profile of you, and they are not set on ordinary pages of the Service. See the "Information We Collect" section of our Privacy Policy for the data the provider receives.

We do not embed advertising networks, social media widgets, session recording tools, heatmaps or A/B testing scripts, so none of those set cookies through the Service. Our analytics run on our own infrastructure and set no cookies — see Section 5.

5. Analytics Storage (No Cookies)

We measure aggregate site usage with Umami, which we run on our own infrastructure. It is cookieless by design: it sets no cookies at all.

It does use one browser local storage key, which is not a cookie and is never sent to a server:

KeyStoragePurposeExpires
umami.disabledLocal storageRead on each page load to check whether you have opted out of analytics. It is only ever read by the tracker, never written by it, and it exists only if you create it yourself.Never, until you clear it or clear site data

Turning analytics off

  1. Turn on Do Not Track in your browser. Our tracker is configured to respect it and records nothing for your visit.
  2. Or set umami.disabled to 1 in local storage for this site, which silences the tracker while it is set.
  3. Or block the analytics script with a content blocker. Nothing else on the site depends on it.

What the analytics collect, and what they deliberately do not, is set out in the Analytics section of our Privacy Policy.

6. What We Do Not Use

For the avoidance of doubt, the Service does not use:

  • advertising or retargeting cookies, or any cookie used to build a profile for marketing;
  • analytics or measurement cookies — our analytics are cookieless;
  • social media sharing or login cookies;
  • tracking pixels, web beacons, clear GIFs or fingerprinting scripts;
  • cross-device or cross-site tracking of any kind.

We do not sell or share information collected by cookies or by our analytics.

7. How to Control Cookies

You can control and delete cookies through your browser settings. Most browsers let you see what is stored, delete individual cookies or all of them, and block cookies from specific sites or in general. Look for "Cookies", "Site data" or "Privacy" in your browser settings or help pages.

Blocking or deleting our session cookie will sign you out, and you will not be able to sign back in until you allow it again. The Service cannot function without it.

You can sign out at any time to end your session, which invalidates the session cookie. You can also review and revoke your active sessions from your account settings.

Browser privacy modes, such as private or incognito windows, discard cookies when the window closes, which will sign you out at the end of each session.

8. Changes to This Policy

If we add, remove or change the cookies we use, we will update this page and revise the "Last updated" date at the top. If we introduce any cookie that is not strictly necessary, we will obtain your consent before setting it, in the way applicable law requires.

9. Contact Us

Questions about this Cookie Policy can be sent to privacy@youtubewriter.com, or by post to:

YouTube WriterAttn: Legal Department[STREET ADDRESS — PLACEHOLDER][CITY], Florida [ZIP]United States