Cookie Policy
Last updated
Written from how the product actually works. If anything here is wrong or unclear, tell us at help@pressypress.com and we will fix it.
Every cookie this site sets, by name. Not a category summary — the actual strings you would find if you opened your browser’s cookie list for pressypress.com, so you can check this page against reality rather than take it on trust.
This covers our site. A WordPress site running on a Pressy sets whatever its own theme and plugins set, which is yours to declare — the privacy policy §8 explains the split.
Strictly necessary
These are set whatever you choose, because without them the thing you asked for does not happen — you cannot stay signed in, a form cannot prove it came from us, and the page cannot know which theme to paint before it paints it. The law does not require consent for cookies that are genuinely necessary, and we have kept the list to ones that genuinely are.
- What it does
- Keeps you signed in. HTTP-only, so no script on the page can read it.
- How long
- 30 days, refreshed while you keep using the dashboard
- What it does
- Proves a form submission came from our own page, not from somewhere else pretending to be you.
- How long
- Until the browser closes
- What it does
- Remembers which page you were heading to, so signing in returns you there instead of to the dashboard root.
- How long
- Until the browser closes
- What it does
- Set only if you sign in with Google. Ties the response from Google to the request that started it.
- How long
- 15 minutes
- What it does
- Set only if you sign in with Google, for the same reason as the one above.
- How long
- 15 minutes
- What it does
- Whether you chose light or dark. Read on the server so the first paint is already right, rather than flashing the wrong one.
- How long
- 1 year
__Secure-authjs.session-token
__Host-authjs.csrf-token
__Secure-authjs.callback-url
__Secure-authjs.pkce.code_verifier
__Secure-authjs.state
theme
| Name | What it does | How long |
|---|---|---|
| __Secure-authjs.session-token | Keeps you signed in. HTTP-only, so no script on the page can read it. | 30 days, refreshed while you keep using the dashboard |
| __Host-authjs.csrf-token | Proves a form submission came from our own page, not from somewhere else pretending to be you. | Until the browser closes |
| __Secure-authjs.callback-url | Remembers which page you were heading to, so signing in returns you there instead of to the dashboard root. | Until the browser closes |
| __Secure-authjs.pkce.code_verifier | Set only if you sign in with Google. Ties the response from Google to the request that started it. | 15 minutes |
| __Secure-authjs.state | Set only if you sign in with Google, for the same reason as the one above. | 15 minutes |
| theme | Whether you chose light or dark. Read on the server so the first paint is already right, rather than flashing the wrong one. | 1 year |
None of these follows you anywhere. They are set by pressypress.com and readable only by pressypress.com.
Analytics
We use Google Analytics to understand how people find us and which pages are worth keeping — which source brought you, which page you landed on, and whether the thing you came for was findable. These are set only if you agree. Decline and no analytics cookie is written, no identifier is created, and the site works identically.
- What it does
- Google Analytics. Distinguishes one browser from another so a returning visit is not counted as a new person.
- How long
- 2 years
- What it does
- Google Analytics. Keeps the state of the current visit — where you arrived from, and whether this is one session or two.
- How long
- 2 years
_ga
_ga_<container>
| Name | What it does | How long |
|---|---|---|
| _ga | Google Analytics. Distinguishes one browser from another so a returning visit is not counted as a new person. | 2 years |
| _ga_<container> | Google Analytics. Keeps the state of the current visit — where you arrived from, and whether this is one session or two. | 2 years |
Google acts as our processor for this, and the data may be handled in the United States — see the privacy policy §4.
Changing your mind is the same amount of work as agreeing in the first place, which is what the law asks and what we would want anyway. Use the cookie settings link in the footer; refusing later also clears what was already set.
What we have never set
No advertising or retargeting cookies. No social-media pixels. No session recording, heatmaps or mouse tracking. No fingerprinting to work around a refusal. No data broker gets anything, because none of them gets anything at all.
Refusing them in your browser
Every browser can block or delete cookies, and you can use that on us without asking. Be aware of the trade: blocking the strictly necessary ones above means you cannot stay signed in, so the dashboard will bounce you back to the sign-in page each time.
Blocking third-party cookies, or using a tracker blocker, will not break anything here — worth saying because on many sites it does.
Questions
Ask at help@pressypress.com. If you find a cookie set by this site that is not listed above, that is a bug in this page and we want to know.