Cookie Policy

Last updated 6 August 2026

Persona Kit sets only the cookies required to sign you in and keep you signed in. There is no analytics, no advertising, and no third-party tracking on this site — which is why you have never seen a consent banner here.

Summary

A cookie is a small file a site stores in your browser. Under the GDPR and the ePrivacy Directive, cookies that are strictly necessary to deliver a service you asked for may be set without consent; anything else — analytics, advertising, personalisation — requires it.

Every cookie Persona Kit sets is strictly necessary. We run no analytics product, no advertising pixels, no session-recording, and no third-party tags. We therefore do not show a cookie consent banner, because there is nothing to consent to.

What we set

All of our cookies are first-party and prefixed with pk. so they are easy to identify in your browser’s inspector.

CookiePurposeLifetime
pk.session_tokenIdentifies your signed-in session. Without it you would have to re-authenticate on every page. HTTP-only, so scripts cannot read it.Until the session expires or you sign out
pk.session_dataCaches basic session details so pages render without an extra round trip to the database.Same as the session
pk.dont_rememberRecords that you chose not to stay signed in, so the session ends when you close the browser.Session only
pk.stateSet only during a Google or GitHub sign-in. Carries the OAuth state value that protects against cross-site request forgery on the callback.A few minutes, during sign-in

Local storage

Separately from cookies, we store one value in your browser’s local storage: a theme key remembering whether you chose light or dark mode. It never leaves your browser and is not sent to us. Clearing site data removes it, and the interface simply reverts to the default theme.

Cookies inside personas

This is a distinction worth being clear about, because Persona Kit is a product about cookies as well as one that uses them.

When you run a browsing session for a persona, the sites that persona visits set their own cookies, and we capture and store those cookies as persona data — that is the feature. Those cookies belong to the persona’s browsing profile, not to persona-kit.com, and they are not set in your own browser. They are covered by the Privacy Policy as persona content: stored in our database, visible to you in the dashboard, and deleted when you delete the persona or its sessions.

Third-party cookies

No third party sets cookies on persona-kit.com itself. Two services set cookies on their own domains when you are redirected to them:

  • Stripe — during checkout and in the billing portal, on checkout.stripe.com and billing.stripe.com. These are necessary for payment processing and fraud prevention, and are governed by Stripe’s privacy policy.
  • Google and GitHub — on their own sign-in pages, if you choose to authenticate with them, and governed by their respective policies.

Managing cookies

You can delete or block cookies in your browser settings. Because all of ours are strictly necessary, blocking them for persona-kit.com means you will not be able to sign in or stay signed in — the site will still load, but the dashboard will be unreachable.

Signing out clears your session cookies. You can also review and revoke individual sessions from your account settings, which invalidates them server-side even if the cookie is still present in another browser.

Changes

If we ever add a cookie that is not strictly necessary — analytics, for example — we will update this page, ask for your consent before setting it, and give you a way to withdraw that consent.

Contact

Questions about this policy: [email protected].