Legal
Cookie Notice
1. About this notice
This Cookie Notice explains the cookies and similar terminal-equipment storage the Artor service (the "Service") uses. It is part of, and should be read with, our Privacy Policy.
A cookie is a small text file a website stores on your device. Most of the storage the Service uses is strictly necessary to provide features you ask for — signing in and viewing secure prototype previews. We also use analytics. How they are switched on depends on where you are: in the dashboard (dash.artor.app), analytics are off until you opt in; on our public website (artor.app — the marketing pages, docs, blog, and changelog), analytics run by default and you can opt out at any time.
2. Two kinds of storage: strictly necessary, and optional analytics
Strictly necessary storage. The cookies needed to sign you in and show you secure previews are strictly necessary. They set no advertising or cross-site tracking technology, and we do not use fingerprinting or device storage to build advertising profiles. Because they are strictly necessary to deliver features you request, they are exempt from prior-consent requirements under EU/UK ePrivacy rules — including the UK's Privacy and Electronic Communications Regulations (PECR) and Germany's § 25 TDDDG (the Telecommunication Digital Services Data Protection Act, formerly the TTDSG) — and do not depend on the banner. In Brazil, where there is no ePrivacy regime, they are processed under the LGPD on the legal bases of performance of a contract and legitimate interest.
Analytics in the dashboard (opt-in). To understand how the dashboard is used and improve it, we use one privacy-protective product-analytics provider, PostHog. In the dashboard, analytics are off by default. The banner offers Accept and Decline with equal prominence, and analytics load only if you click "Accept"; declining (or simply ignoring the banner) loads nothing. Until you accept, no analytics technology loads, no analytics identifier is created, and nothing is sent to PostHog. Because analytics are non-essential, we ask for your prior consent as required by EU/UK ePrivacy rules (§ 25 TDDDG, PECR) and, in Brazil, obtain your consent under the LGPD before loading them. You can change your choice at any time using Cookie settings, available in your account menu in the dashboard and in the footer of the sign-in page. If you decline (or later turn analytics off), we stop analytics capture and delete the analytics data stored in your browser. We identify you to PostHog with an opaque account identifier and your organization's id and slug, never your name or email.
Analytics on the public website (opt-out). On artor.app we use Google Analytics and PostHog to understand how the site is used. They run by default when you visit. A notice bar on your first visit tells you this and offers Opt out and Got it with equal prominence; you can change your choice at any time using Cookie settings in the footer of every page. Opting out stops analytics capture, tells Google Analytics to stop setting analytics cookies, and deletes the PostHog data stored in your browser. Google Analytics runs in its consent-mode configuration with all advertising signals permanently denied: we do not use Google Signals, advertising features, or cross-site tracking. You are never identified to either provider by name or email; the website has no accounts.
Session replay. PostHog session replay can cover the dashboard and the public website, never the separate preview origin that serves your prototypes (that origin loads no analytics at all). Replay masks everything you type — every input and text field is hidden before capture. In the dashboard, replay can still show other on-screen content, such as organization, project, and prototype names and comment text that was already visible on screen. On the public website, the only text on screen is our own; replay may show which pages you viewed and where you scrolled and clicked. See the Privacy Policy for what analytics data is collected and how it is used.
Global Privacy Control (GPC). We honor a browser GPC signal everywhere. In the dashboard, analytics require your affirmative opt-in, so with GPC set and no prior choice they simply stay off. On the public website, a GPC signal counts as an opt-out: with GPC set and no prior choice, analytics do not run and no analytics cookie is set. In both places an explicit Accept or Got it is honored as your override, and the Cookie settings dialog reflects the current state.
3. The storage we use
The sign-in and preview cookies are first-party and set with security protections (for example,
HttpOnly so page scripts cannot read them, and Secure over HTTPS). The preview cookies are
scoped to the cookie-isolated preview origin so prototype code cannot read your dashboard session.
| Name | Type | Provider | Purpose | Consent | Approx. lifetime |
|---|---|---|---|---|---|
better-auth.session_token (the authentication session cookie; a __Secure- prefix is added over HTTPS) | Cookie, strictly necessary | First party | Keeps you signed in to the dashboard you explicitly logged into; without it sign-in cannot work | Not required | Rolling: refreshed at most once a day, expires after ~7 days of inactivity |
| Short-lived sign-in state cookie (set only during Google/GitHub sign-in) | Cookie, strictly necessary | First party | Completes an OAuth sign-in securely (protects against cross-site request forgery); cleared once sign-in finishes | Not required | The sign-in exchange only (minutes) |
dn_pv | Cookie, strictly necessary | First party | Grants a signed-in organization member access to that organization's secure prototype previews after they request a preview; the preview cannot be served without it | Not required | ~1 hour |
dn_pub | Cookie, strictly necessary | First party | Required to serve the specific public preview the visitor chose to open and to keep that view inside its isolated runtime; without it the requested preview cannot be displayed. Sets no profile | Not required | ~5 minutes |
artor_consent | Cookie, strictly necessary | First party | Remembers your analytics choice so we do not ask again and honor it on every page. Set separately on the dashboard and on the public website, and scoped to that host only. Stores only your choice, a version number, and a timestamp | Not required (records your consent choice) | ~12 months |
PostHog analytics storage (ph_* keys in localStorage) | localStorage, non-essential | PostHog | Product analytics: remembers an opaque analytics identifier and queues usage events. In the dashboard, created only after you accept; on the public website, created by default and removed when you opt out | Dashboard: required (opt-in). Public website: opt-out | Until you opt out or clear site data |
_ga | Cookie, non-essential | Google Analytics | Public website only. Distinguishes one browser from another with a random identifier so page views can be counted per visit. Not set once you opt out | Opt-out (public website only) | ~2 years |
_ga_<ID> | Cookie, non-essential | Google Analytics | Public website only. Keeps the current visit's state for the same purpose. Not set once you opt out | Opt-out (public website only) | ~2 years |
The "stay signed in" lifetime of the session cookie is the duration needed to provide that
requested feature; if you prefer, you can sign out to end it. We do not use a PostHog cookie —
analytics state is kept in localStorage, so it is scoped to the origin that set it (the dashboard
or the public website) and never sent to the preview origin. The Google Analytics cookies are set
only on the public website.
4. Managing your choices
- Analytics in the dashboard: use Cookie settings (account menu in the dashboard, or the
sign-in page footer) to accept or decline at any time. Declining stops analytics capture and
deletes the
ph_*analytics storage from your browser. - Analytics on the public website: use Cookie settings in the footer of any artor.app
page to opt out or back in at any time. Opting out stops PostHog capture, deletes the
ph_*storage from your browser, and switches Google Analytics to a cookieless mode; the existing_gacookies are not renewed and expire on their own, or you can delete them in your browser. - Strictly necessary cookies: because these are required for sign-in and preview access, disabling them will break those features. You can still block or delete cookies through your browser settings, but the Service may not work correctly.
- Global Privacy Control (GPC): a GPC signal keeps analytics off with no action needed — in the dashboard because they never run without your opt-in, on the public website because we treat the signal as an opt-out. We honor your explicit Accept or Got it as an override. We do not separately detect the legacy "Do Not Track" browser header; it has no additional effect.
5. Changes
If we change the cookies or device storage we use — for example, if we add another analytics or non-essential technology — we will update this notice and, where the law requires, obtain your consent first. The "last updated" date below shows the current version.
Effective: September 8, 2026 · Version: 1.2