Cookies
There is no banner because there is nothing to consent to. Everything here is either how sign-in works or a preference you set yourself.Last updated 2026-08-21
1. The cookies
| Name | What it does | Set when | Lifetime | Sent to |
|---|---|---|---|---|
SSESS… | Keeps you signed in. A random session id; the session itself lives on our server. | When you sign in | 23 days idle, or until you sign out | Our server, over HTTPS only |
sot_theme | Remembers whether you chose the light or dark scheme, so the page renders in it before any script runs. | When you pick a scheme | 1 year | Our server (read only to render the right scheme) |
sot_rail | Remembers whether the left rail is expanded or collapsed, so it does not flash on load. | When you toggle the rail | 1 year | Our server (read only to render the rail state) |
sot_invite | Carries an invite code from a /join link to the sign-up form, so the member who invited you gets connected to your account. It holds the code and nothing else. | When you open an invite link | 7 days | Our server, at sign-up only |
sot_gate | Records that the age question on the sign-up form has already been answered, so it cannot be re-answered by going back. It holds no age and no value worth reading. | When you submit the sign-up form | Until you close the browser | Our server; HttpOnly, so no script can read it |
Cross-site request forgery protection uses a token fetched by the page and sent in a header; it is not a cookie. Cloudflare may set a short-lived challenge cookie (cf_clearance or similar) if it needs to tell a browser from a bot; that is Cloudflare’s, is strictly necessary for the site to be reachable, and is described in their policy.
2. Local storage
These live in your browser and are never sent to us. Clearing your browser storage removes them. They are listed individually because “a couple of preferences” is not an answer when one of them holds your unsaved writing.
| Key | What it holds |
|---|---|
sot_rail_folds | Which sections of the left rail you have folded shut. |
sot.feed.mode | Whether you last read the wall ranked, newest-first, or most-seconded. |
sot.profile.themes | Whether you have allowed other members’ custom profile colours to render for you. |
sot-meetup-safety-seen | That you have already been shown the one-time meetup safety notice. |
sot.wall.getstarted | Which getting-started suggestions you have skipped or hidden on your wall. |
sot.builder.last | The last show you had open in the setlist builder, so it reopens where you left it. |
sot.builder.draft:… | Unsaved setlist drafts, one key per show. This is your own writing, kept in your browser so a closed tab does not lose it. It stays until you submit the draft or clear your browser storage. |
sot_seen_auth | A single flag that records you were signed in on this device, so that when you sign out the offline cache is cleared for the next person on a shared computer. It holds no identity — just that a session existed — and is removed at sign-out. |
3. Counting visits
We use Cloudflare Web Analytics to count page views. It is worth being exact about what that does and does not do, because “analytics” usually means something worse than this.
It sets no cookie, writes nothing to your browser’s storage, and creates no identifier that persists between visits or follows you to any other site. Your IP address reaches Cloudflare, as it already does for every request they serve on our behalf, and is not retained against a profile. It reports the page you landed on, where you arrived from, your browser and rough country, and how quickly the page loaded. Two visits from you are not knowable as being from the same person. There is no profile, no session replay, and nothing that can be joined back to your account. We chose it over Google Analytics for exactly these reasons.
4. What there is not
- No analytics cookies. The analytics we do run sets none.
- No advertising cookies.
- No third-party scripts that set cookies. GIF search is proxied through our server so the provider never sees your browser.
- No cookie banner. The reasoning, so you can judge it: a banner exists to obtain consent for storing things on your device or reading what is already there. Nothing here stores anything beyond the strictly necessary, and the analytics measure the site in aggregate rather than identifying anyone — which is the basis on which European regulators exempt audience measurement from consent. If that assessment is ever shown to be wrong, a banner goes up and this page says so.
5. If that changes
If anything is ever added that stores something on your device or identifies you between visits, this page will list it first, and where the law requires consent before it is set, consent will be asked for — with an equally easy no. The Privacy Notice is the rest of the story.