Last updated: September 2026
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
scriptly_session |
Identifies you as signed in, so the Service knows which account is making a request. | Strictly necessary | Up to 30 days, or until you sign out |
g_oauth_state |
A short-lived value used only during Google Sign-In to confirm the sign-in response actually came from a request this browser started (CSRF protection). | Strictly necessary | 15 minutes, cleared automatically once sign-in completes |
Both cookies are set with HttpOnly (not readable by page scripts), Secure (sent only over HTTPS), and SameSite=Lax flags. Neither is used for advertising, cross-site tracking, or shared with any third-party ad network.
Because both cookies above are strictly necessary for the Service to function — you cannot sign in or stay signed in without them — they don't require the opt-in consent banner used for optional/advertising cookies under laws like the EU's ePrivacy Directive and GDPR. We still disclose them fully here for transparency.
Separately from cookies, your browser's local storage is used to remember things on your own device, such as:
Local storage data stays on your device — it is never transmitted to our servers except where the feature it supports explicitly requires it (for example, sending a document you've opened to the AI for analysis). Clearing your browser's site data for Scriptly removes it.
Signing in uses Google's own sign-in flow, which may set its own cookies on Google's domain, governed by Google's cookie policy. Making a payment uses Stripe's checkout, which may set its own cookies on Stripe's domain during that process, governed by Stripe's cookie policy. We don't control these third-party cookies and recommend reviewing those providers' own policies if you have questions about them.
Most browsers let you view, delete, or block cookies through their settings. Because scriptly_session is required to stay signed in, blocking or deleting it will sign you out. Blocking g_oauth_state will prevent Google Sign-In from completing.
If the cookies or local-storage values we use change materially, we'll update this page and, where appropriate, note it in the app.
Questions about this policy can be directed to the Service operator through the contact channel provided within the app.