Cookie Policy
Last updated:
Summary. DesAIgner uses the cookies it needs to sign you in, keep your account secure and remember your cookie choice, plus a few small settings that remember how you like the app to look and work. We use analytics (PostHog) only if you accept them in our cookie banner; rejecting is as easy as accepting, and you can change your mind at any time under "Cookie settings". If your browser sends a Global Privacy Control or Do Not Track signal, analytics stay off. We don't use advertising cookies, and no third party sets cookies on our site.
1. What cookies and local storage are
A cookie is a small text file a website stores in your browser, which your browser sends back with each request to that site. Local storage and session storage are similar places in your browser where a website can keep small settings; unlike cookies, they are not sent to the server. Session storage is cleared when you close the tab.
2. The cookies we use
These cookies and storage items are set only by DesAIgner, on our own domain (first-party).
Strictly necessary
The Service can't work without these, so they don't need your consent. The sign-in cookies are set by the sign-in library we use (Auth.js). On a secure (HTTPS) connection their names start with __Secure- or __Host-.
| Name | What it does | How long it lasts |
|---|---|---|
authjs.session-token | Keeps you signed in. It holds an encrypted token that identifies your account. Scripts on the page can't read it. If it gets large, it may be split into several cookies ending in .0, .1 and so on | 30 days. It is renewed at most once a day while you use the Service, and deleted when you sign out |
authjs.csrf-token | Protects the sign-in and sign-out process against cross-site request forgery | Until you close your browser |
authjs.callback-url | Remembers which page to take you back to after you sign in | Until you close your browser |
authjs.pkce.code_verifier | Used only when you sign in with Google: a one-time security code that ties Google's answer to the sign-in you started. Scripts on the page can't read it | 15 minutes, and removed when the sign-in completes |
dsg_verify_token | Session storage (not a cookie): used only when you open an email-confirmation link while signed out. It holds that one-time link while you sign in, so we can finish confirming your email address afterwards. It is never sent to our server as a cookie | Removed as soon as it is used, whether or not the confirmation succeeds, and at the latest when you close the tab |
dsg_consent | Remembers your cookie choice (whether you accepted or rejected analytics, and when), so we don't ask again on every page. It contains no identifier | 6 months; then we ask again |
Preferences
These remember a choice you made in the interface. They are set only when you make that choice, and they contain nothing that identifies you.
| Name | Type | What it does | How long it lasts |
|---|---|---|---|
theme | Local storage | Remembers whether you chose the light, dark or system theme | Until you clear your browser's site data |
desaigner:plan-view | Local storage | Remembers whether you last used the Simple or Advanced view when reviewing a plan | Until you clear your browser's site data |
desaigner:proto-keys | Local storage | Remembers whether you turned single-key shortcuts off in the prototype player | Until you clear your browser's site data |
Analytics (only with your consent)
These are set by PostHog, our analytics provider, only after you choose "Accept analytics", and never while your browser sends a Global Privacy Control or Do Not Track signal. They help us understand how people use DesAIgner so we can improve it (see the Privacy Policy). In the names below, <key> is our PostHog project key, which is the same for every visitor.
| Name | Type | What it does | How long it lasts |
|---|---|---|---|
ph_<key>_posthog | Local storage | Holds a random analytics ID (a pseudonymous ID derived from your account once you sign in), the current analytics session and PostHog's settings | Until you withdraw consent (we then delete it) or clear your browser's site data |
ph_<key>_window_id and ph_<key>_primary_window_exists | Session storage | Tell apart visits in different browser tabs | Until you close the tab |
__ph_opt_in_out_<key> | Local storage | Set only if you withdraw consent after accepting: remembers that analytics are off. It contains no identifier | Until you clear your browser's site data |
If your browser blocks local storage, PostHog may keep ph_<key>_posthog in a first-party cookie of the same name instead, for up to 1 year or until you withdraw consent.
Shared projects
These are used on pages that a project owner has shared through a link (addresses starting with /p/). Each is set only when you do what its row describes.
| Name | Type | What it does | How long it lasts |
|---|---|---|---|
share_unlock | Cookie, strictly necessary | Set only after you enter the correct password for a password-protected link, so you don't have to enter it on every page of that link. It is limited to that one link, scripts on the page can't read it, and it contains no personal data | 12 hours. It stops working sooner if the owner changes or removes the password or turns the link off |
desaigner:share-visitor | Local storage | Remembers the name and email address you entered when you first commented on a shared project, so you don't have to type them again. It stays on your device and is sent to us only as part of a comment you post | Until you clear your browser's site data |
desaigner:comment-pins | Local storage | Remembers whether you hid the comment pins on screens, on a shared page or in your own project | Until you clear your browser's site data |
3. What we don't use
We don't use:
- advertising, retargeting or social-media cookies or pixels;
- third-party cookies of any kind on our website;
- analytics of any kind unless you have accepted them;
- session recording: we don't record your screen, mouse movements or what you type.
Our error monitoring (Sentry) sets no cookies and stores nothing in your browser. It sends technical error reports, cleaned of personal data, as described in the Privacy Policy.
4. Your choice and how to change it
The law (the EU ePrivacy Directive and its national implementations) requires consent for cookies and similar storage unless they are strictly necessary to provide a service you explicitly asked for. The strictly necessary items and the preference items above don't need consent. Analytics do, so we ask first.
- The cookie banner. When analytics are switched on for our website and you haven't made a choice yet, a banner at the bottom of the page offers three buttons of equal size and style: "Accept analytics", "Reject analytics" and "Settings". Nothing analytics-related loads until you accept. Closing or ignoring the banner is not consent.
- Settings. "Settings" lets you turn analytics on or off on its own. The strictly necessary items are always on.
- Change your mind at any time. Open "Cookie settings" at the bottom of our website or in your account menu. If you withdraw consent, PostHog stops straight away and we delete its local storage from your browser.
- Browser privacy signals. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a refusal: analytics stay off, the banner is not shown, and the analytics switch in "Cookie settings" is off and can't be turned on.
- How long we remember. Your choice is kept in the
dsg_consentcookie for 6 months. After that, or if we add a new purpose, we ask again.
The items for shared projects work the same way: share_unlock is strictly necessary to open a password-protected link you asked to see, and the local storage entries only keep, on your own device, what you typed or chose yourself.
5. Checkout
When you buy a plan or a credit pack, we send you to the checkout page of our reseller, Creem, on Creem's own website. That page may set its own cookies, for example for payment security and fraud prevention, under Creem's own policies (Creem's Privacy Notice). These cookies are set by Creem, not by us. We don't load any Creem script on our own pages.
6. How to control cookies
Besides "Cookie settings", you can delete cookies and local storage, or block them, in your browser settings. If you block or delete the strictly necessary cookies, you won't be able to sign in. If you delete the preference items or the dsg_consent cookie, the Service simply forgets your choice and asks again.
7. Changes and contact
We will update this policy whenever we change the cookies we use. The date at the top shows when it last changed. Questions: faris@elevatesolutions.ba. For how we handle personal data in general, see our Privacy Policy.