Cookie Policy
Effective Date: September 28, 2026. Last updated: 2026-09-28.
1. What This Policy Is For
Cookies are small text files a site stores in your browser. Sites can also use similar storage, such as your browser's local storage. This policy lists what amtil.co and the AMTIL Encyclopedia at app.amtil.co store, why, and for how long. If it conflicts with our Privacy Policy, the Privacy Policy controls.
The short version: we use only what is needed to run the sites, our analytics do not use cookies, and we run no advertising cookies or pixels.
2. Categories
- Strictly necessary: keeping you signed in, checking that you are human, taking payments, and remembering choices you made (such as declining analytics). The sites do not work without these, so they do not need consent.
- Preferences: remembering settings such as light or dark theme, in your browser's local storage.
- Analytics: aggregate measurement of how pages are used and how fast they load. Ours do not set cookies (see section 4).
- Advertising: none. We do not run advertising cookies or pixels on amtil.co or app.amtil.co.
3. What We Store
| Name | Site | Set by | Purpose | Lifetime | Category |
|---|---|---|---|---|---|
sb-…-auth-token (may be split into numbered parts) | .amtil.co (all AMTIL sites, including amtil.co) | Supabase (our sign-in provider) | Keeps you signed in to AMTIL apps | Up to 1 year, removed when you sign out | Necessary |
amtil_disclaimer_ack | app.amtil.co | AMTIL | Records that you acknowledged the educational disclaimer | 24 hours | Necessary |
preview_access | app.amtil.co | AMTIL | Lets a verified email open a shared preview without an account | 30 days | Necessary |
__stripe_mid, __stripe_sid | app.amtil.co (checkout) | Stripe | Fraud prevention during payment | Up to 1 year / 30 minutes | Necessary |
| Turnstile data | Both | Cloudflare | Checks that a sign-up, log-in, or form submission comes from a person | Short-lived | Necessary |
amtil-analytics-consent (local storage) | amtil.co | AMTIL | Remembers whether you accepted or declined analytics | Until you clear site data or use Cookie settings | Necessary |
amtil-consent-focus-banner (session storage) | amtil.co | AMTIL | Moves focus to the consent banner after Cookie settings reloads the page | Removed on the next page load | Necessary |
umami.disabled (local storage) | amtil.co | AMTIL | Tells our self-hosted analytics script to send nothing after you withdraw consent | Until you accept analytics again or clear site data | Necessary |
amtil-follow-bar-dismissed, amtil-followed (local storage) | amtil.co | AMTIL | Remembers that you closed or used the "Follow the build" bar, so it stops asking | Until you clear site data | Preferences |
| Theme and sign-in handshake data (local storage) | app.amtil.co | AMTIL / Supabase | Remembers light or dark theme; completes a sign-in securely | Until you clear site data | Preferences / Necessary |
userEmail (local storage) | app.amtil.co | AMTIL | Remembers the email you signed up with so the email-verification step can use it | Until you clear site data | Necessary |
4. Analytics and Error Monitoring
On amtil.co, we use Umami (self-hosted by AMTIL), Vercel Web Analytics, and Vercel Speed Insights. None of them set cookies, and none of them load unless you choose Accept on our analytics banner. If your browser sends a Global Privacy Control (GPC) signal, we treat it as Decline and do not show the banner. To change your choice at any time, use Cookie settings at the bottom of our pages; your previous answer is forgotten and the banner comes back (if your browser sends GPC, analytics simply stay off). Separately, our own server adds one to a running total when a page such as Pricing is viewed or a sign-up button is clicked; these totals carry no cookie, identifier, or IP address.
In the app (app.amtil.co), we use Vercel Web Analytics to count page views in aggregate, and Umami to count product events such as finishing a step in sign-up. Neither sets cookies or follows you to other sites, so they run without a banner, on the basis of our legitimate interest in improving the product. Umami events are not sent if your browser sends GPC. When something breaks, the app sends an error report to GlitchTip (the error, the page, and browser and device details); it does not record your screen. You can object to any of this by emailing privacy@amtil.co.
5. Signing In With Google, Discord, or Twitch
If you sign in with Google, Discord, or Twitch, that service may set its own cookies on its own website during sign-in. Those cookies are governed by that service's policy, not ours.
6. How to Manage Cookies
You can clear or block cookies at any time in your browser settings:
If you block strictly necessary cookies, anything that needs you to sign in will stop working.
7. Do Not Track and Global Privacy Control
There is no agreed standard for the older Do Not Track signal, so we do not act on it. We do honor Global Privacy Control as described in section 4.
8. Changes
If we add, remove, or change what we store, we update this page and its "Last updated" date first. If the change affects what data is collected about you, we also update the Privacy Policy.
9. Contact
Email privacy@amtil.co with questions.