Skip to main content
StillOnTour

Cookies

There is no banner because there is nothing to consent to. Everything here is either how sign-in works or a preference you set yourself.Last updated 2026-08-21

Draft — not yet reviewed by counsel. Wording may change before it is relied on.

1. The cookies

NameWhat it doesSet whenLifetimeSent to
SSESS…Keeps you signed in. A random session id; the session itself lives on our server.When you sign in23 days idle, or until you sign outOur server, over HTTPS only
sot_themeRemembers whether you chose the light or dark scheme, so the page renders in it before any script runs.When you pick a scheme1 yearOur server (read only to render the right scheme)
sot_railRemembers whether the left rail is expanded or collapsed, so it does not flash on load.When you toggle the rail1 yearOur server (read only to render the rail state)
sot_inviteCarries an invite code from a /join link to the sign-up form, so the member who invited you gets connected to your account. It holds the code and nothing else.When you open an invite link7 daysOur server, at sign-up only
sot_gateRecords that the age question on the sign-up form has already been answered, so it cannot be re-answered by going back. It holds no age and no value worth reading.When you submit the sign-up formUntil you close the browserOur server; HttpOnly, so no script can read it

Cross-site request forgery protection uses a token fetched by the page and sent in a header; it is not a cookie. Cloudflare may set a short-lived challenge cookie (cf_clearance or similar) if it needs to tell a browser from a bot; that is Cloudflare’s, is strictly necessary for the site to be reachable, and is described in their policy.

2. Local storage

These live in your browser and are never sent to us. Clearing your browser storage removes them. They are listed individually because “a couple of preferences” is not an answer when one of them holds your unsaved writing.

KeyWhat it holds
sot_rail_foldsWhich sections of the left rail you have folded shut.
sot.feed.modeWhether you last read the wall ranked, newest-first, or most-seconded.
sot.profile.themesWhether you have allowed other members’ custom profile colours to render for you.
sot-meetup-safety-seenThat you have already been shown the one-time meetup safety notice.
sot.wall.getstartedWhich getting-started suggestions you have skipped or hidden on your wall.
sot.builder.lastThe last show you had open in the setlist builder, so it reopens where you left it.
sot.builder.draft:…Unsaved setlist drafts, one key per show. This is your own writing, kept in your browser so a closed tab does not lose it. It stays until you submit the draft or clear your browser storage.
sot_seen_authA single flag that records you were signed in on this device, so that when you sign out the offline cache is cleared for the next person on a shared computer. It holds no identity — just that a session existed — and is removed at sign-out.

3. Counting visits

We use Cloudflare Web Analytics to count page views. It is worth being exact about what that does and does not do, because “analytics” usually means something worse than this.

It sets no cookie, writes nothing to your browser’s storage, and creates no identifier that persists between visits or follows you to any other site. Your IP address reaches Cloudflare, as it already does for every request they serve on our behalf, and is not retained against a profile. It reports the page you landed on, where you arrived from, your browser and rough country, and how quickly the page loaded. Two visits from you are not knowable as being from the same person. There is no profile, no session replay, and nothing that can be joined back to your account. We chose it over Google Analytics for exactly these reasons.

4. What there is not

  • No analytics cookies. The analytics we do run sets none.
  • No advertising cookies.
  • No third-party scripts that set cookies. GIF search is proxied through our server so the provider never sees your browser.
  • No cookie banner. The reasoning, so you can judge it: a banner exists to obtain consent for storing things on your device or reading what is already there. Nothing here stores anything beyond the strictly necessary, and the analytics measure the site in aggregate rather than identifying anyone — which is the basis on which European regulators exempt audience measurement from consent. If that assessment is ever shown to be wrong, a banner goes up and this page says so.

5. If that changes

If anything is ever added that stores something on your device or identifies you between visits, this page will list it first, and where the law requires consent before it is set, consent will be asked for — with an equally easy no. The Privacy Notice is the rest of the story.