# Cookie Policy | Aglyn

> The cookies and similar technologies Aglyn uses, and the choices you have.

Legal

# Cookie Policy

What Aglyn stores in your browser, why we store it, and how to change your choices.

**Last updated: August 23, 2026**

This Cookie Policy explains how **Aglyn LLC** (“**Aglyn**,” “**we**,” “**us**”) uses cookies and similar technologies on our own websites and the console (**aglyn.com**, **app.aglyn.com**, **docs.aglyn.com**). It supplements the **Privacy Policy**.

**Note on tenant sites.** Websites you build and publish through the Services (***.aglyn.app** and custom domains) may set their own cookies. As the operator of your Host, **you** are responsible for your own cookie notice and consent toward your End Users. This includes advertising tags: a Host operator can enable an advertising tag on their own site using their own advertising account. Aglyn does not receive that data and is not the controller of it — the Host operator is.

## **1. What are cookies?**

Cookies are small text files stored on your device. We also use similar technologies such as local storage, tokens, and pixels. Cookies may be “session” (deleted when you close your browser) or “persistent” (remain until they expire or are deleted), and “first-party” (set by us) or “third-party” (set by our providers).

## **2. Categories of cookies we use**

* **Strictly necessary** — required to operate the Services, including authentication and session management (the __session cookie and its companions listed in the table below), security, load balancing, and fraud/bot protection (Google reCAPTCHA). These cannot be disabled without breaking core functionality.
* **Preferences / functional** — remember your settings, such as your light/dark theme choice.
* **Analytics / performance** — we use Google Analytics on our own websites and the console (aglyn.com, app.aglyn.com, and docs.aglyn.com) to measure how they are used. This is a single GA4 property, and Google’s advertising features are enabled on it: the property is linked to Aglyn’s Google Ads account with personalized advertising enabled, and Google signals and ads personalization are allowed in every region, so analytics data may also be used to build and export advertising audiences. Granular location and device data collection is on, and data retention is 14 months. What the property permits is not what runs for every visitor: where we ask you about advertising, your answer is carried to Google’s tag through consent mode, and the advertising signals — ad storage, ad user data, and ads personalization — stay denied unless advertising cookies are active for you. The cookies it sets are listed below. Our own error and performance collector remains first-party and cookieless: it sets no cookie and stores no visitor identifier.
* **Marketing / advertising** — with your consent, we use advertising and measurement cookies and similar technologies from third-party advertising platforms, such as Google, Meta, and LinkedIn, on our own sites, so that we can show you Aglyn ads elsewhere and understand whether they worked. The cookies they set are listed below. This includes the console: these tags run on app.aglyn.com while you are signed in, not only on the sign-in and signup pages. Like any advertising tag they report the address of the page you are on, and console addresses contain your organization’s identifier, identify the site you are working in, and name the area of the product you are in — so the platforms named above can infer that your organization is an Aglyn customer, and can see roughly which parts of the console your people use. You can stop that at any time using “Your Privacy Choices” in the console account menu. On our documentation site these tags run only if you have already made a privacy choice in the console, because that site has no privacy control of its own and reads the choice you made there; if you have never used the console, they do not load for you at all. Where the law requires us to ask first (the EU, the UK, and anywhere we cannot determine your region) they do not load until you accept; elsewhere they run from your first visit and you can turn them off whenever you like. Either way they do not load at all if your browser sends Global Privacy Control. Withdrawing consent through “Your Privacy Choices” signals the platforms to stop and clears the related cookies we can reach. Cookies a platform sets on its own domain — LinkedIn’s, for example — are outside what a page on our site can read or clear, and you can remove them with your browser controls.

**The cookies we set on our own properties** (aglyn.com, app.aglyn.com, docs.aglyn.com):

| Cookie | Purpose | Duration | Party |
| :---- | :---- | :---- | :---- |
| __session | Keeps you signed in to the console (HttpOnly) | 14 days | First-party |
| __session_tenant | Records which sign-in context your session belongs to (HttpOnly) | 14 days | First-party |
| aglyn_session_activity | Last-activity timestamp, so idle sessions are signed out (HttpOnly) | 24 hours | First-party |
| aglyn_device | Recognizes a device you have used before, so we can alert you when your account is accessed from a new one (HttpOnly) | 365 days | First-party |
| __aglyn_handoff | Proves that the browser finishing a sign-in on a custom console domain is the one that started it (HttpOnly); set only on a custom console domain | 15 minutes, and cleared as soon as it is used | First-party |
| aglyn_consent | Carries the privacy choice you made in “Your Privacy Choices” between app.aglyn.com and auth.aglyn.com, so an answer given while signing in still applies once you are inside the console; scoped to aglyn.com and its subdomains, and not set on a custom console domain | 13 months | First-party |
| aglyn_editor | Marks the browser as one an Aglyn editor is signed in on, so a site you can edit offers the edit bar. Its value is the literal 1 — no personal data | 7 days, cleared on sign-out | First-party |
| theme-color-mode | Your light/dark theme preference | 365 days | First-party |
| aglyn-tenant-host | Operational: on preview and branch deployments, remembers which site a preview URL was pointed at | Session | First-party |
| _ga | Google Analytics — measures how our sites and the console are used | 2 years | First-party |
| _ga_YW5PG16YTM | Google Analytics — measures how our sites and the console are used | 2 years | First-party |
| _gid | Google Analytics — distinguishes visitors | 24 hours | First-party |
| _gac | Google Analytics — links a visit to a Google Ads click (the full cookie name adds your Google Ads account id); set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~90 days (set by Google) | First-party, set by Google’s tag |
| _gcl_au | Google advertising — attributes an ad click to what you did on the site, and measures whether the ad worked; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~90 days (set by Google) | First-party, set by Google’s tag |
| _fbp | Meta Pixel — identifies your browser to Meta so we can show you Aglyn ads elsewhere and measure whether they worked; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~90 days (set by Meta) | First-party, set by Meta’s tag |
| _fbc | Meta Pixel — records the Meta ad click that brought you here; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~90 days (set by Meta) | First-party, set by Meta’s tag |
| li_sugr | LinkedIn Insight Tag — a browser identifier LinkedIn uses to show you Aglyn ads on LinkedIn and measure whether they worked; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~90 days (set by LinkedIn) | Third-party (LinkedIn), set on linkedin.com |
| UserMatchHistory | LinkedIn Insight Tag — records when your browser was last matched to LinkedIn’s advertising systems; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~30 days (set by LinkedIn) | Third-party (LinkedIn), set on linkedin.com |
| AnalyticsSyncHistory | LinkedIn Insight Tag — records when your browser was last synchronized with LinkedIn’s ad analytics; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~30 days (set by LinkedIn) | Third-party (LinkedIn), set on linkedin.com |
| bcookie | LinkedIn Insight Tag — LinkedIn’s browser identifier, which recognizes your browser across the sites that carry the tag; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~1 year (set by LinkedIn) | Third-party (LinkedIn), set on linkedin.com |
| lidc | LinkedIn Insight Tag — routes your request to the right LinkedIn data center; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~24 hours (set by LinkedIn) | Third-party (LinkedIn), set on linkedin.com |
| li_gc | LinkedIn Insight Tag — stores the choice you gave LinkedIn about its own non-essential cookies; set when advertising cookies are active for you — in the UK, EU and EEA only after you agree, and elsewhere unless you turn them off | ~6 months (set by LinkedIn) | Third-party (LinkedIn), set on linkedin.com |
| __stripe_mid | Stripe fraud prevention, set when a payment form loads | ~1 year | Third-party (Stripe) |
| __stripe_sid | Stripe payment-session continuity | ~30 minutes | Third-party (Stripe) |
| _GRECAPTCHA (Google reCAPTCHA) | Bot protection for authentication and data access (via Firebase App Check); Google sets its own identifiers under its own policy | Set by Google | Third-party (Google) |

**Browser storage on our own properties.** When you make a choice in “Your Privacy Choices” on aglyn.com, we record that choice in your browser’s local storage (under **aglyn:consent:** plus a site identifier) so that we do not ask again and can honor a withdrawal. It is storage rather than a cookie, and it is not sent to our servers; in the console we also copy that record into the aglyn_consent cookie listed above, which is sent with requests to aglyn.com, so your choice carries between the console hostnames. Clearing your browser storage removes it. The same record is used on sites built on Aglyn, as listed below.

**Cookies and storage on sites you publish.** Sites you build and publish through the Services set the following, as part of platform features you enable:

| Item | Purpose | Duration | Type |
| :---- | :---- | :---- | :---- |
| aglyn_cart_{siteId} | Keeps a visitor’s shopping cart across visits (commerce; HttpOnly) | 90 days | Cookie, first-party to your site |
| aglyn_member_{siteId} | Keeps a member signed in to your site (memberships; HttpOnly) | 30 days | Cookie, first-party to your site |
| aglyn_edit_hint | Signed proof that an Aglyn editor is signed in, exchanged for edit access on a site you administer (HttpOnly) | 7 days | First-party |
| aglyn_editor | The browser-visible half of the same hint, on the aglyn.app domain | 7 days | First-party |
| theme-color-mode | Light/dark preference, on sites that offer a theme switcher | 365 days | First-party |
| __stripe_mid / __stripe_sid | Stripe, on every storefront that takes payment | ~1 year / ~30 minutes | Third-party (Stripe) |
| aglyn:visitor | A random, pseudonymous visitor identifier used to keep A/B test assignments consistent | Does not expire (persists until the visitor clears browser storage) | localStorage |
| Popup / announcement stamps | Remember that a visitor dismissed a popup or announcement bar, so it is not re-shown | Varies by frequency setting | localStorage |
| aglyn:consent:{siteId} | The privacy choices a visitor made on that site, so they are not asked again and a withdrawal can be honored. It is not a cookie and is not sent to our servers | Until the visitor clears browser storage | localStorage |
| Google Analytics (_ga and its per-property variant, plus _gid) and, where you enable the advertising question and a visitor allows it, _gcl_au and _gac cookies | Only if **you** configure a Google Analytics tag for your site; Google’s cookies are governed by Google’s policies and your own cookie notice | Per Google | Third-party cookie |
| Advertising tags you add yourself | Cookies set by an advertising tag you enable on your own site with your own advertising account — for example Meta’s _fbp and _fbc. Aglyn does not receive that data and is not the controller of it | Per vendor | Third-party cookie |

Our built-in site analytics are cookieless and store no visitor identifier. As the operator of your site, you remain responsible for your own cookie notice and any consent your visitors’ jurisdictions require — including for the items above.

## **3. Third-party technologies**

Some cookies or similar technologies are set by our providers to deliver the Services, including authentication (Google Firebase), security (Google reCAPTCHA), infrastructure (Vercel), payments (Stripe), analytics (Google Analytics), and — where you have consented — advertising and measurement (Google, Meta, and LinkedIn). These providers process data under their own policies. See our Subprocessors list for the full set of providers and what each handles.

## **4. Your choices**

* **Browser controls:** most browsers let you block or delete cookies. Blocking strictly necessary cookies may prevent the Services from working.
* **Consent:** the cookies we set on our own properties are limited to what is needed to operate and secure the Services, remember your preferences, measure how the Services are used, and — where you have consented — advertising and measurement, as listed above. In the UK, the EU and the EEA — and anywhere we cannot determine your region — advertising cookies are set only after you agree. Everywhere else they are active from your first visit, and you can turn them off at any time using the “Your Privacy Choices” control on any page. The Google Analytics cookies listed above (**_ga**, **_ga_YW5PG16YTM** and **_gid**) are analytics rather than strictly necessary; you can block or delete them using the browser controls described above.
* **Signed-in use of the console.** When you are signed in to the console (**app.aglyn.com**) we measure how you use the console itself, so that we can operate, support, secure and improve it. That measurement is part of providing the Services to you as an account holder and is not governed by the choice above. Advertising is different, and it is governed by that choice: the advertising and measurement technologies described above also run on the console while you are signed in, and turning advertising off in “Your Privacy Choices” — the control is in the console account menu — stops them there too. Because the console shares the aglyn.com domain, its analytics cookies can reappear on our marketing site after you have cleared them there.
* **Do Not Track / Global Privacy Control:** we honor Global Privacy Control as an automatic opt-out of advertising and of “sharing” under U.S. state privacy laws. When your browser sends it, no advertising technology loads. Pages work the same whether or not your browser sends it.

## **5. Changes**

We may update this Cookie Policy at any time by posting the updated version and revising the “Last updated” date.

## **6. Contact**

Questions: **privacy@aglyn.com**.

*© 2026 Aglyn LLC. All rights reserved.*

---

Source: https://aglyn.com/legal/cookies
