Cookies, session recording and ad conversion measurement improve the product. Before you accept we measure page views and anonymous interactions, with no cookies, no recording and no profile. Reject keeps it that way. Cookie policy

Vetoo
ManifestoLive reviewAgent panelMemory & trustPricing
Resources
Competitor comparisonLearn centerDocs
Sign up
Sign inSign up
Legal

Cookie Policy

Everything vetoo.dev and the app store on your device, checked against the running product rather than against what we meant to build.

Last updated · 2026-09-02
01Before you choose

Nothing is stored until you decide

Opening this site puts nothing on your device. Not a cookie, not an entry in your browser’s storage. Product analytics run in a cookieless mode: they count page views and anonymous interactions, keep no identifier for your device, discard your IP address and build no profile of you. Performance monitoring collects nothing at all.

One technical detail belongs here because a cookie scanner will report it. Our performance monitoring tool writes a probe cookie when it starts, purely to learn whether cookies work in your browser, and deletes it immediately. It holds the word test.

02Your decision

The one cookie your choice creates

Choosing either way writes vetoo_cookie_consent. It is ours, it is scoped to .vetoo.dev so your choice carries from this site into the app, and it lasts 12 months. It holds two things: which way you chose, and when. If we change this policy in a way that matters, that record stops counting and we ask you again.

03If you accept

What accepting turns on

ph_<project id>_posthog
PostHog, our analytics provider. Scoped to .vetoo.dev, 12 months. Identifies your browser and your session so we can count returning visitors, and holds the campaign you arrived from.
_dd_s_v2
Datadog, our performance monitor. This site only, expiring after 15 minutes of inactivity and after 4 hours at the outside. Groups your page loads into one session so a slow page or an error can be traced back to what caused it.
_gcl_au and _gcl_aw
Google Ads conversion measurement. Scoped to .vetoo.dev, 90 days. _gcl_au is written when the tag loads; _gcl_aw only if you arrived from one of our ads, and holds the click identifier from that ad so Google can count a sign-up, a connected repository or a purchase against it. Google receives the page address and that identifier. Google also sets its own cookie on doubleclick.net, in its own context under Google’s policy, so a sign-up can be credited to an ad you saw on YouTube or another site. We do not use any of it for personalised advertising or remarketing.

Accepting also starts session recording, with every input you type masked, and inside the app it links your account to your analytics profile. Reject, and the site works exactly the same way, cookieless.

04If you reject

Rejecting, and changing your mind

Rejecting writes your decision to the consent cookie above, plus one entry in your browser’s local storage recording that analytics stay switched off. Nothing else is stored, and nothing about you is sent anywhere.

You can change your mind whenever you like, from Manage cookies in the footer of this site or on your profile page in the app. Withdrawing clears the analytics and Google conversion cookies, stops recording and conversion measurement, and puts you back in the cookieless state described above.

Your browser can overrule us entirely. Every major browser will clear the cookies for a site or block them outright, usually under privacy settings, and blocking ours costs you nothing beyond the analytics described above. You can block the strictly necessary cookies in the next two sections as well, but signing in and paying will stop working, because those cookies are how they work.

05Signing in

Strictly necessary: staying signed in

These are set when you sign in to the app, by Clerk, who run our sign-in, and by Cloudflare, who shield Clerk from abuse. They are strictly necessary: without them you cannot stay signed in, so there is no consent to give or withhold.

__session
Clerk. The app domain only, about one minute and continuously renewed. The token that proves a request is yours.
__client_uat
Clerk. Scoped to .vetoo.dev. Records that you are signed in, so the server knows what to show before the page loads. It is not a credential.
__client
Clerk. Scoped to clerk.vetoo.dev. Keeps your sign-in alive between visits.
__clerk_handshake
Clerk. The app domain only, lasting a single redirect. Carries state while an expired sign-in is renewed.
__cf_bm and _cfuvid
Cloudflare, set on clerk.vetoo.dev and on a domain Cloudflare owns, for 30 minutes and 7 days. Bot and abuse protection in front of the sign-in service. A third copy of __cf_bm is set on challenges.cloudflare.com when you create an account, where a bot check runs. We do not read any of them.
06Paying

Strictly necessary: taking a payment

Stripe handles every payment, and their code loads only on a page where you are actually paying. If you never open billing, none of this reaches your browser. Both cookies exist to detect fraud, which makes them strictly necessary to the payment itself.

__stripe_mid
Stripe. 12 months. Recognises your browser across payments so Stripe can spot fraud.
__stripe_sid
Stripe. 30 minutes. Identifies a single checkout for the same purpose.

Stripe also runs its own fraud checks inside a frame served from m.stripe.network, which stores data in its own context under Stripe’s policy rather than ours.

07Not cookies

Storage that is not a cookie

The rules that govern cookies govern anything stored on your device, so these belong here on the same footing.

Finishing what you started
The plan you picked, the onboarding step you are on and the workspace you just brought online. Held in session storage and gone when you close the tab. Necessary to complete the thing you asked for.
The announcement bar
Whether you dismissed it, kept in local storage so it stays dismissed on your next visit. Written only when you dismiss it.
The campaign you arrived from
Written to session storage only if you accepted, and cleared the moment it is used. If you rejected, it is never written.
Your analytics identifier
Kept in local storage beside the PostHog cookie if you accepted. If you rejected, a single entry recording that choice sits there instead.
08Questions

Ask us anything about this

Email support@support.vetoo.dev to ask what a cookie does, to see what we hold about you, or to have it deleted. People read that inbox, not a ticket queue.

We revise this page whenever what we store actually changes.

Version history

  • 2026-09-02in force
TermsPrivacySub-processorsCookiesLegal notice

Clear the review queue
before it forms.

Connect your first repository and let Vetoo do the rest.

Connect your repository
Vetoo

Product

ManifestoLive reviewAgent panelMemory & trustPricingFAQ

Resources

All resourcesWhat is AI code review?Code review checklistVetoo vs CodeRabbitVetoo vs GreptileVetoo vs Bugbot

Developers

Docs

Company

Contact

Legal

PrivacyTermsSub-processorsCookie PolicyLegal notice