Last updated: August 23, 2026
This Cookie Policy explains how Aglyn LLC ("Aglyn," "we," "us") uses cookies and similar technologies on our own websites and the console (aglyn.com, app.aglyn.com, docs.aglyn.com). It supplements the Privacy Policy.
Note on tenant sites. Websites you build and publish through the Services (*.aglyn.app and custom domains) may set their own cookies. As the operator of your Host, you are responsible for your own cookie notice and consent toward your End Users. This includes advertising tags: a Host operator can enable an advertising tag on their own site using their own advertising account. Aglyn does not receive that data and is not the controller of it — the Host operator is.
Cookies are small text files stored on your device. We also use similar technologies such as local storage, tokens, and pixels. Cookies may be "session" (deleted when you close your browser) or "persistent" (remain until they expire or are deleted), and "first-party" (set by us) or "third-party" (set by our providers).
The cookies we set on our own properties (aglyn.com, app.aglyn.com, docs.aglyn.com):
| Cookie | Purpose | Duration | Party |
|---|---|---|---|
| __session | Keeps you signed in to the console (HttpOnly) | 14 days | First-party |
| __session_tenant | Records which sign-in context your session belongs to (HttpOnly) | 14 days | First-party |
| aglyn_session_activity | Last-activity timestamp, so idle sessions are signed out (HttpOnly) | 24 hours | First-party |
| aglyn_device | Recognizes a device you have used before, so we can alert you when your account is accessed from a new one (HttpOnly) | 365 days | First-party |
| __aglyn_handoff | Proves that the browser finishing a sign-in on a custom console domain is the one that started it (HttpOnly); set only on a custom console domain | 15 minutes, and cleared as soon as it is used | First-party |
| aglyn_editor | Marks the browser as one an Aglyn editor is signed in on, so a site you can edit offers the edit bar. Its value is the literal 1 — no personal data | 7 days, cleared on sign-out | First-party |
| theme-color-mode | Your light/dark theme preference | 365 days | First-party |
| aglyn-tenant-host | Operational: on preview and branch deployments, remembers which site a preview URL was pointed at | Session | First-party |
| _ga | Google Analytics — measures how our sites and the console are used | 2 years | First-party |
| _ga_YW5PG16YTM | Google Analytics — measures how our sites and the console are used | 2 years | First-party |
| _gid | Google Analytics — distinguishes visitors | 24 hours | First-party |
| _gac | Google Analytics — links a visit to a Google Ads click (the full cookie name adds your Google Ads account id); set only where you have allowed advertising cookies | ~90 days (set by Google) | First-party, set by Google's tag |
| _gcl_au | Google advertising — attributes an ad click to what you did on the site, and measures whether the ad worked; set only where you have allowed advertising cookies | ~90 days (set by Google) | First-party, set by Google's tag |
| _fbp | Meta Pixel — identifies your browser to Meta so we can show you Aglyn ads elsewhere and measure whether they worked; set only where you have allowed advertising cookies | ~90 days (set by Meta) | First-party, set by Meta's tag |
| _fbc | Meta Pixel — records the Meta ad click that brought you here; set only where you have allowed advertising cookies | ~90 days (set by Meta) | First-party, set by Meta's tag |
| __stripe_mid | Stripe fraud prevention, set when a payment form loads | ~1 year | Third-party (Stripe) |
| __stripe_sid | Stripe payment-session continuity | ~30 minutes | Third-party (Stripe) |
| _GRECAPTCHA (Google reCAPTCHA) | Bot protection for authentication and data access (via Firebase App Check); Google sets its own identifiers under its own policy | Set by Google | Third-party (Google) |
Browser storage on our own properties. When you make a choice in "Your Privacy Choices" on aglyn.com, we record that choice in your browser's local storage (under aglyn:consent: plus a site identifier) so that we do not ask again and can honour a withdrawal. It is storage rather than a cookie, and it is not sent to our servers. Clearing your browser storage removes it. The same record is used on sites built on Aglyn, as listed below.
Cookies and storage on sites you publish. Sites you build and publish through the Services set the following, as part of platform features you enable:
| Item | Purpose | Duration | Type |
|---|---|---|---|
| aglyn_cart_{siteId} | Keeps a visitor's shopping cart across visits (commerce; HttpOnly) | 90 days | Cookie, first-party to your site |
| aglyn_member_{siteId} | Keeps a member signed in to your site (memberships; HttpOnly) | 30 days | Cookie, first-party to your site |
| aglyn_edit_hint | Signed proof that an Aglyn editor is signed in, exchanged for edit access on a site you administer (HttpOnly) | 7 days | First-party |
| aglyn_editor | The browser-visible half of the same hint, on the aglyn.app domain | 7 days | First-party |
| theme-color-mode | Light/dark preference, on sites that offer a theme switcher | 365 days | First-party |
| __stripe_mid / __stripe_sid | Stripe, on every storefront that takes payment | ~1 year / ~30 minutes | Third-party (Stripe) |
| aglyn:visitor | A random, pseudonymous visitor identifier used to keep A/B test assignments consistent | Does not expire (persists until the visitor clears browser storage) | localStorage |
| Popup / announcement stamps | Remember that a visitor dismissed a popup or announcement bar, so it is not re-shown | Varies by frequency setting | localStorage |
| aglyn:consent:{siteId} | The privacy choices a visitor made on that site, so they are not asked again and a withdrawal can be honoured. It is not a cookie and is not sent to our servers | Until the visitor clears browser storage | localStorage |
| Google Analytics (_ga and its per-property variant, plus _gid) and, where you enable the advertising question and a visitor allows it, _gcl_au and _gac cookies | Only if you configure a Google Analytics tag for your site; Google's cookies are governed by Google's policies and your own cookie notice | Per Google | Third-party cookie |
| Advertising tags you add yourself | Cookies set by an advertising tag you enable on your own site with your own advertising account — for example Meta's _fbp and _fbc. Aglyn does not receive that data and is not the controller of it | Per vendor | Third-party cookie |
Our built-in site analytics are cookieless and store no visitor identifier. As the operator of your site, you remain responsible for your own cookie notice and any consent your visitors' jurisdictions require — including for the items above.
Some cookies or similar technologies are set by our providers to deliver the Services, including authentication (Google Firebase), security (Google reCAPTCHA), infrastructure (Vercel), payments (Stripe), analytics (Google Analytics), and — where you have consented — advertising and measurement (Google and Meta). These providers process data under their own policies. See our Subprocessors list for the full set of providers and what each handles.
We may update this Cookie Policy at any time by posting the updated version and revising the "Last updated" date.
Questions: privacy@aglyn.com.
© 2026 Aglyn LLC. All rights reserved.