Nothing is stored until you decide
Opening this site puts nothing on your device. Not a cookie, not an entry in your browser’s storage. Product analytics run in a cookieless mode: they count page views and anonymous interactions, keep no identifier for your device, discard your IP address and build no profile of you. Performance monitoring collects nothing at all.
One technical detail belongs here because a cookie scanner will report it. Our performance monitoring tool writes a probe cookie when it starts, purely to learn whether cookies work in your browser, and deletes it immediately. It holds the word test.
The one cookie your choice creates
Choosing either way writes vetoo_cookie_consent. It is ours, it is scoped to .vetoo.dev so your choice carries from this site into the app, and it lasts 12 months. It holds two things: which way you chose, and when. If we change this policy in a way that matters, that record stops counting and we ask you again.
What accepting turns on
- ph_<project id>_posthog
- PostHog, our analytics provider. Scoped to .vetoo.dev, 12 months. Identifies your browser and your session so we can count returning visitors, and holds the campaign you arrived from.
- _dd_s_v2
- Datadog, our performance monitor. This site only, expiring after 15 minutes of inactivity and after 4 hours at the outside. Groups your page loads into one session so a slow page or an error can be traced back to what caused it.
- _gcl_au and _gcl_aw
- Google Ads conversion measurement. Scoped to .vetoo.dev, 90 days. _gcl_au is written when the tag loads; _gcl_aw only if you arrived from one of our ads, and holds the click identifier from that ad so Google can count a sign-up, a connected repository or a purchase against it. Google receives the page address and that identifier. Google also sets its own cookie on doubleclick.net, in its own context under Google’s policy, so a sign-up can be credited to an ad you saw on YouTube or another site. We do not use any of it for personalised advertising or remarketing.
Accepting also starts session recording, with every input you type masked, and inside the app it links your account to your analytics profile. Reject, and the site works exactly the same way, cookieless.
Rejecting, and changing your mind
Rejecting writes your decision to the consent cookie above, plus one entry in your browser’s local storage recording that analytics stay switched off. Nothing else is stored, and nothing about you is sent anywhere.
You can change your mind whenever you like, from Manage cookies in the footer of this site or on your profile page in the app. Withdrawing clears the analytics and Google conversion cookies, stops recording and conversion measurement, and puts you back in the cookieless state described above.
Your browser can overrule us entirely. Every major browser will clear the cookies for a site or block them outright, usually under privacy settings, and blocking ours costs you nothing beyond the analytics described above. You can block the strictly necessary cookies in the next two sections as well, but signing in and paying will stop working, because those cookies are how they work.
Strictly necessary: staying signed in
These are set when you sign in to the app, by Clerk, who run our sign-in, and by Cloudflare, who shield Clerk from abuse. They are strictly necessary: without them you cannot stay signed in, so there is no consent to give or withhold.
- __session
- Clerk. The app domain only, about one minute and continuously renewed. The token that proves a request is yours.
- __client_uat
- Clerk. Scoped to .vetoo.dev. Records that you are signed in, so the server knows what to show before the page loads. It is not a credential.
- __client
- Clerk. Scoped to clerk.vetoo.dev. Keeps your sign-in alive between visits.
- __clerk_handshake
- Clerk. The app domain only, lasting a single redirect. Carries state while an expired sign-in is renewed.
- __cf_bm and _cfuvid
- Cloudflare, set on clerk.vetoo.dev and on a domain Cloudflare owns, for 30 minutes and 7 days. Bot and abuse protection in front of the sign-in service. A third copy of __cf_bm is set on challenges.cloudflare.com when you create an account, where a bot check runs. We do not read any of them.
Strictly necessary: taking a payment
Stripe handles every payment, and their code loads only on a page where you are actually paying. If you never open billing, none of this reaches your browser. Both cookies exist to detect fraud, which makes them strictly necessary to the payment itself.
- __stripe_mid
- Stripe. 12 months. Recognises your browser across payments so Stripe can spot fraud.
- __stripe_sid
- Stripe. 30 minutes. Identifies a single checkout for the same purpose.
Stripe also runs its own fraud checks inside a frame served from m.stripe.network, which stores data in its own context under Stripe’s policy rather than ours.
Storage that is not a cookie
The rules that govern cookies govern anything stored on your device, so these belong here on the same footing.
- Finishing what you started
- The plan you picked, the onboarding step you are on and the workspace you just brought online. Held in session storage and gone when you close the tab. Necessary to complete the thing you asked for.
- The announcement bar
- Whether you dismissed it, kept in local storage so it stays dismissed on your next visit. Written only when you dismiss it.
- The campaign you arrived from
- Written to session storage only if you accepted, and cleared the moment it is used. If you rejected, it is never written.
- Your analytics identifier
- Kept in local storage beside the PostHog cookie if you accepted. If you rejected, a single entry recording that choice sits there instead.
Ask us anything about this
Email support@support.vetoo.dev to ask what a cookie does, to see what we hold about you, or to have it deleted. People read that inbox, not a ticket queue.
We revise this page whenever what we store actually changes.
Version history
- 2026-09-02in force