← Back to Scriptly
S
Scriptly

Cookie Policy

Last updated: September 2026

Plain-language summary: Scriptly uses exactly two cookies, both strictly necessary to sign you in and keep your session secure — nothing else. There is no advertising cookie, no cross-site tracking cookie, and no analytics cookie. We also use your browser's local storage to remember preferences on your device; that isn't a cookie, but we explain it here too since it works similarly.

1. What cookies we use

NamePurposeTypeLifetime
scriptly_session Identifies you as signed in, so the Service knows which account is making a request. Strictly necessary Up to 30 days, or until you sign out
g_oauth_state A short-lived value used only during Google Sign-In to confirm the sign-in response actually came from a request this browser started (CSRF protection). Strictly necessary 15 minutes, cleared automatically once sign-in completes

Both cookies are set with HttpOnly (not readable by page scripts), Secure (sent only over HTTPS), and SameSite=Lax flags. Neither is used for advertising, cross-site tracking, or shared with any third-party ad network.

2. Why we don't ask for cookie consent on every visit

Because both cookies above are strictly necessary for the Service to function — you cannot sign in or stay signed in without them — they don't require the opt-in consent banner used for optional/advertising cookies under laws like the EU's ePrivacy Directive and GDPR. We still disclose them fully here for transparency.

3. Local storage (not a cookie, but similar)

Separately from cookies, your browser's local storage is used to remember things on your own device, such as:

Local storage data stays on your device — it is never transmitted to our servers except where the feature it supports explicitly requires it (for example, sending a document you've opened to the AI for analysis). Clearing your browser's site data for Scriptly removes it.

4. Third-party cookies

Signing in uses Google's own sign-in flow, which may set its own cookies on Google's domain, governed by Google's cookie policy. Making a payment uses Stripe's checkout, which may set its own cookies on Stripe's domain during that process, governed by Stripe's cookie policy. We don't control these third-party cookies and recommend reviewing those providers' own policies if you have questions about them.

5. Managing cookies

Most browsers let you view, delete, or block cookies through their settings. Because scriptly_session is required to stay signed in, blocking or deleting it will sign you out. Blocking g_oauth_state will prevent Google Sign-In from completing.

6. Changes to this policy

If the cookies or local-storage values we use change materially, we'll update this page and, where appropriate, note it in the app.

7. Contact

Questions about this policy can be directed to the Service operator through the contact channel provided within the app.