Approval-gated legal draft
Cookie Policy
Draft for Brandon/counsel review. Do not publish as final legal advice or a legal commitment until approved.
Template version: legal-pages/v1
Product: ContentCrafter AI
Contact: support@contentcrafter.ai
Review gate
This page adapts the EXC-279 cookie policy and consent standard for ContentCrafter AI. It documents the current cookie/provider inventory found in the codebase, but final legal publication and any new tracking provider remain approval-gated.
EXC-279 consent categories
Necessary
Category key: necessary
Always enabled for site operation, security, authentication, abuse prevention, consent storage, CMS/admin access, and checkout/account workflows where enabled.
Preferences
Category key: preferences
Optional settings that remember non-essential user choices. Current code uses local storage for the landing teaser UI and consent preferences; no separate preferences provider is approved.
Analytics
Category key: analytics
Optional product or marketing-site measurement. No standalone analytics cookie provider is currently approved; platform/security logs that are necessary for hosting remain outside optional analytics cookies.
Marketing
Category key: marketing
Optional advertising, retargeting, campaign attribution, affiliate pixels, or cross-site tracking. No marketing cookie provider is currently approved.
Current cookie and provider inventory
| Cookie or technology | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
| __session and Clerk session/client cookies | Clerk | necessary | Authenticate users, protect dashboard routes, and maintain account sessions. | Set by Clerk configuration/session lifetime. |
| Payload CMS/admin cookies and CSRF/session state | Payload CMS / app | necessary | Support authenticated CMS/admin/editor access and security controls. | Session or configured Payload lifetime. |
| cc_landing_teaser_used | ContentCrafter AI | necessary | HTTP-only abuse-prevention cookie that enforces the one-free-teaser limit on the public landing-page demo. | Up to one year. |
| contentcrafter-cookie-consent | ContentCrafter AI | necessary | Stores the user's cookie category choices locally so the banner does not reappear on every page load. | Until local storage is cleared or the consent revision changes. |
| contentcrafter-teaser-used | ContentCrafter AI | preferences | Local UI state that remembers the browser already used the landing teaser and should show the sign-up prompt. | Until local storage is cleared. |
| Vercel platform logs and request metadata | Vercel | necessary | Hosting, security, troubleshooting, and reliability logs. Not a browser marketing cookie controlled by the banner. | Per Vercel/project log retention configuration. |
| Sentry diagnostics (only when SENTRY_DSN is configured) | Sentry / Payload plugin | necessary | Server/app error diagnostics and reliability monitoring when enabled; no standalone browser analytics pixel is currently configured by this PR. | Per Sentry project retention configuration. |
| Stripe checkout/billing cookies (only during approved Stripe flows) | Stripe | necessary | Fraud prevention, checkout, billing portal, subscription, and metered-billing support when payment flows are enabled. | Set by Stripe. |
Managing choices
Use the cookie banner or the footer cookie preferences control to choose necessary-only mode or save category preferences. Necessary cookies stay enabled because the app cannot provide sign-in, security, abuse prevention, consent storage, billing/account flows, or CMS/admin access without them.