Cookies

Every cookie and every browser key Demofy sets, what each is for, and which need consent.

This is every cookie and every browser-storage key Demofy sets, what each is for, and which of them wait for your permission. It is a complete list rather than a representative one: if something is not here, this site does not set it. This page covers what is stored in your browser; what is recorded about you and where it goes is the privacy policy.

Two categories, and only one of them asks

Strictly necessary — the things without which the product does not do what you just asked. These are set regardless, because a consent bar offering to switch off the cookie that signs you in would be offering to break the site.

Analytics — page counting. Nothing in this category loads until you accept. Declining does not degrade anything: the tags are simply not put on the page, so they make no request and set nothing.

There is no third category. Demofy runs no advertising, no retargeting and no cross-site tracking of any kind, so there is nothing to offer you a switch for.

Strictly necessary

NameSet byWhat it is forHow long
better-auth.session_token (__Secure- prefixed over HTTPS)Demofy, on app.demofy.ioKeeps you signed in. Read on every request that needs to know who you are.30 days
better-auth.state, better-auth.pkce_code_verifierDemofy, on app.demofy.ioOnly during a Google or Apple sign-in, to tie the redirect back to the request that started it. Deleted as soon as the sign-in completes.Minutes
demofy.consent.analytics.v1 (browser storage, not a cookie)DemofyRemembers whether you accepted or declined analytics, so you are asked once. It is deliberately not a cookie: it never needs to reach a server, and a cookie would be sent on every request for no reason.Until you clear site data
The icon rail’s expanded/collapsed state (browser storage)Demofy, in the studioRemembers whether you left the sidebar open. Carries no identifier.Until you clear site data
A step-editor draft (session storage)Demofy, in the editorKeeps unsaved edits if the tab reloads. Dies with the tab, on purpose.The tab
demofy_prompt_pref and the demofy_prompt_* counters (browser and session storage)DemofyRemembers whether you asked for tips and prompts to be switched off, which one you were last shown and when, how many times you have closed each, and how many times you have visited. It is what stops the same card appearing twice in one visit or ever again once you have waved it away three times. It carries no identifier and never leaves this browser.Until you clear site data, except the per-visit ones, which die with the tab

None of the last four is a cookie. They are listed anyway, because “we only set one cookie” is technically true and practically misleading, and this page is not for lawyers.

The prompt switch is in settings as Show tips and prompts. It is free for everyone and it is on until you turn it off; the cookie bar above is the one thing it cannot silence, because asking that question is not optional for us.

Analytics — only after you accept

NameSet byWhat it is forHow long
_ga, _ga_<container id>Google Analytics 4Tells a returning visit from a new one, so page counts are not everybody counted once per visit. Set to expire in 90 days rather than Google’s default two years.90 days
ph_<key>_posthog and its matching browser-storage entryPostHogThe same job for product analytics, when the deployment has a PostHog key.1 year
demofy.first_touch.v1 (browser storage, not a cookie)DemofyRemembers the campaign link you first arrived from, once, so a signup can be attributed to it. Written only after you accept, and never overwritten afterwards.Until you clear site data

All three are first-party. None is used for advertising: Google signals and ad-personalisation signals are switched off in the tag itself, and no identifier is shared between Google Analytics and your Demofy account.

Set by someone else, during checkout only

If you buy a plan, RevenueCat’s hosted checkout loads Stripe’s payment fields in Stripe’s own frames, and Stripe sets its own cookies there (__stripe_mid, __stripe_sid) for fraud prevention. Demofy neither sets nor reads them. They appear only on the upgrade page and only if you open checkout.

Changing your mind

The bar asks once, so this is where the answer is changed. The switch below reads the same stored answer the bar wrote and writes the opposite one, and the tags follow it in this visit: turning analytics off takes them off the page you are on, without a reload, and turning it on puts them there the same way.

Reading your saved answer…

Two honest caveats. The switch changes what loads from here on; it does not reach back and delete a cookie a tag already set, so if you have just turned analytics off and want the _ga pair gone as well, your browser’s own “cookies and site data” panel is the thing that removes them. And clearing this site’s storage still works and does something slightly different: it forgets the answer entirely rather than recording the opposite one, so the bar asks again from scratch.

A shared video is not measured at all

A public share link — and the same page embedded in someone else’s site — loads no analytics tag, shows no consent bar, reads no session and sets no cookie. What is recorded about a shared demo is a count per video and per moment reached, on our own server, with no viewer, no address, no session and no timestamp attached. There is nothing about a viewer to consent to, because nothing about a viewer is written down.