Cookie Notice

Version
1.2
Effective date
July 14, 2026

This Cookie Notice explains what cookies are, which ones we use on Connekit, and how you can manage your preferences.

1. What cookies are

Cookies are small text files stored in your browser when you visit a website. They let the site recognize your device, keep preferences across visits, and enable basic functionality, such as keeping you signed in to your Account.

2. Cookie categories

The Analytics and Marketing categories already exist in our preferences panel and can be turned on or off by you at any time — but today, no analytics or marketing vendor is under contract, so no script from those categories loads even if you allow them. This only changes once a vendor is actually added, which requires an update to this Notice before any such script begins loading.

  • Essential: required for the Platform's basic operation (authentication, security, language). They cannot be disabled, since Connekit does not work without them.
  • Analytics: used to understand, in aggregate, how visitors use the site.
  • Marketing/advertising: used to show targeted ads or measure campaigns.

3. Behavior by region and the Global Privacy Control signal

The default behavior before you make a choice varies by your location, approximately detected from your IP address:

  • European Union, European Economic Area, United Kingdom and Brazil: opt-in mode — no non-essential cookie loads until you explicitly accept.
  • Other countries (e.g. United States): opt-out mode — non-essential cookies may load by default, and the notice lets you decline them at any time.

Global Privacy Control (GPC)

If your browser sends the Global Privacy Control (GPC) signal, we treat it as a request to automatically decline non-essential cookies, regardless of your region — the cookie notice is not shown in that case, since your choice has already been respected.

4. Cookies we use today

NameProviderPurposeDuration
connekit_localeConnekit (first-party)Remembers the language chosen in the interface1 year
authjs.session-tokenConnekit, via Auth.js (first-party)Keeps your session authenticatedUp to 30 days or logout (Auth.js default)
authjs.csrf-tokenConnekit, via Auth.js (first-party)Protection against CSRF attacks on login/signup formsBrowser session
ck_consentConnekit (first-party)Stores your cookie choice (accepted categories, notice version and date)1 year
ck_anon_idConnekit (first-party)Anonymous identifier used only to link your consent history when you are not signed in1 year

Local storage (sessionStorage) on Link-in-Bio pages

Besides cookies, your browser may keep information in other types of local storage. When you allow the Analytics category, public Link-in-Bio pages (connekit.me/bio/...) may write a marker to the browser's sessionStorage.

That marker only records that a page has already been counted in that tab, on that day, and it exists to prevent reloading the page from counting the same view multiple times. It contains no IP address, destination address, personal identifier, or any data about who is visiting, and it is never sent to our servers.

sessionStorage is not a cookie: it is normally cleared by the browser when that tab's session ends. If you do not allow the Analytics category, nothing is written.

5. How to manage your preferences

When the cookie notice appears, you can choose between "Accept all", "Reject non-essential", or "Customize" to decide category by category. You can reopen this panel at any time via the "Cookie preferences" link in the site footer or the button below, and review or change your choice whenever you want.

You can also block cookies directly in your browser settings, which may prevent login and other essential functionality.

6. Contact

Questions about this Notice can be sent to hello@connekit.me.