Cookie policy
Four things live in your browser: a sign-in session and three interface preferences. Nothing tracks you, here or anywhere else.
1The short version
Five things are in your browser whatever you decide. One keeps you signed in, three remember a setting so the interface opens the way you left it, and one remembers your answer to the question below. None of them follows you anywhere.
The rest is what the banner asks about, and none of it runs unless you press Allow — “none” meant literally: refuse and no script is fetched, no request leaves your browser, and no cookie is set. There is no cookieless ping and no “essential analytics” carve-out.
Google Analytics counts visits and tells us which pages are worth keeping.
Refusing is one click, the same size as accepting, and it costs you nothing on this site — every part of the product works identically either way. You can change your mind by clearing itc.consent.marketing from this browser’s storage, which makes the banner ask again.
There is still no advertising pixel, no social widget and no cross-site identifier. Ad personalisation and Google Signals are switched off explicitly, so even with analytics on, nothing here is used to follow you to another site.
2Exactly what is stored
| Name | Type | What it is for | How long |
|---|---|---|---|
| Firebase Authentication session | Strictly necessary · IndexedDB and local storage | Keeps you signed in between visits and lets the app prove to the API that a request is yours. Set by the Firebase SDK, not by us. | Until you sign out, or the session expires |
| itc-theme | Preference · local storage | Remembers whether you chose the dark or the light theme. | Until you clear it |
| itc-sidebar-collapsed | Preference · local storage | Remembers whether you collapsed the sidebar in the app. | Until you clear it |
| itc-active-preset | Preference · local storage | Remembers which render preset you last worked with, so a new job opens on the one you use. | Until you clear it |
| itc.consent.marketing | Strictly necessary · local storage | Remembers whether you said yes or no on the banner, so you are asked once rather than on every page. It is written whichever way you answered — a refusal has to be remembered too, or the banner would keep coming back. | Until you clear it |
| _ga, _ga_<id> | Analytics · cookies, set by Google — only if you agree | Google Analytics. Counts visits and tells us which pages people arrive on and which they leave from. Neither exists until you press Allow: refuse, and the Google script is never fetched at all. | Up to 2 years, or until you clear them |
3What third parties can set
- Google (Analytics), only with your consent. If you press Allow, your browser loads a script from googletagmanager.com and sends Google the pages you visit, along with the IP address the request comes from. Google acts as our processor for this. Press No thanks and none of it happens.
- Google (Firebase Authentication). Storage used to hold your sign-in session and, during sign-in, to protect against automated abuse.
- Stripe. When you open the checkout or the billing portal you are on Stripe’s own page, where Stripe sets what it needs for payment and fraud prevention. That is governed by Stripe’s policies, not this one.
- Cloudflare. Delivery of this site may involve security cookies set at the edge to distinguish a browser from an attack. These are strictly necessary and contain no profile of you.
These providers are described on the sub-processors page.
4Clearing it
- Signing out removes the session. Clearing site data in your browser removes everything on the list.
- Blocking storage for this site entirely is your right, and the site will still read — but you will not be able to stay signed in, so the app itself will not work.
- If we ever add anything that is not on this list, it will appear here first and, where the law requires it, behind a consent request.
Questions to intheclips.business@gmail.com. How the rest of your data is handled is in the privacy policy.
The contract: accounts, plans, billing, your content, and where our liability ends.
What is processed, why, on which legal basis, for how long, and your rights over it.
What you may not run through the pipeline, and what happens if you do.
Every provider that can see customer data, what it sees, and where it runs.
What a score is and is not, and what the output does not promise.
For people we wrote to first: where the address came from, why it was yours, and how to make it stop.
Questions about any of this — including a request about your own data — go to intheclips.business@gmail.com.