Skip to content

Cookie policy

A cookie is a small text file a site keeps in your browser. This page lists every cookie and similar entry CurlShot uses, so you know exactly what is stored and why.

Last updated

1. The short version

  • The cookies the site cannot work without (signing in, protecting forms from forgery, remembering your cookie choice) are always on.
  • Everything else is optional and stays off until you say yes: the cookie that remembers a referral link you followed. You are asked once, in the banner at the bottom of the page, and "Reject all" is one click, the same as "Accept all".
  • We set no advertising cookies and use no outside analytics or tracking service.
  • If you only read the site and never sign in, you get two security cookies that hold nothing about you and disappear when you close the browser, plus the cookie that remembers your choice.

to see or change your choice now.

2. Cookies we set

On the live site the names carry a __Secure- or __Host- prefix, which tells the browser to send them over an encrypted connection only. None of them can be read by scripts on the page.

Signing in

  • authjs.session-token: keeps you signed in. Set when you sign in, removed when you sign out, and otherwise expires after 30 days without use.
  • authjs.csrf-token: a random value that proves a sign-in or sign-out request really comes from this site. Set on your first visit, when the site checks whether you are signed in; lasts until you close the browser.
  • authjs.callback-url: remembers which page to return you to after signing in. Set on your first visit; lasts until you close the browser.
  • authjs.state, authjs.pkce.code_verifier, authjs.nonce: set only while you sign in through another provider, to make sure the answer that comes back belongs to your attempt. Each lasts 15 minutes at most.

Your cookie choice

  • cookie_consent: remembers what you allowed or refused and when, so we do not ask on every page. It holds the date and the names of the options you allowed, nothing else, and lasts 6 months; then we ask again.

Referral (optional, only with your permission)

  • ref_code: set only if you open someone's referral link and have allowed "Referral link". It holds the code of that link, so that you and the person who invited you get the bonus the link promises if you create an account. It lasts 30 days and holds nothing about you. If you refuse or later withdraw the permission, the cookie is not set, or is removed at once.

3. Other things kept in your browser

Browsers offer storage that works like a cookie but is never sent to our servers. We use it for two conveniences:

  • docs-language (local storage): the programming language you picked for code samples in the documentation, so the next page shows the same one. Kept until you clear it.
  • stale-build-reloaded-at (session storage): a timestamp that stops the page from reloading in a loop after we publish a new version of the site. Gone when you close the tab.

4. Cookies from other companies

  • Payment. When you buy a plan you are sent to the checkout page of Dodo Payments. That page is theirs and uses its own cookies, which it needs to take the payment and prevent fraud.
  • Sign-in providers. If you choose to sign in through another provider, you pass through its own sign-in page, which uses its own cookies.

Nothing else on the site loads content from another company that could set a cookie.

5. Page view counts

We count page views ourselves to see which pages are useful. The count uses no cookie and nothing stored in your browser, and it keeps no record that identifies you. The privacy policy describes how it works.

6. Your choice, and how to change it

  • Change or withdraw it at any time with "Cookie settings" at the bottom of every page, or with the button at the top of this page. Withdrawing is as easy as agreeing, takes effect at once, and removes the optional cookies we set.
  • Refusing costs you nothing. The whole site works without the optional cookies. The one exception is a form protected by the spam check: it asks for that permission when you send it, and you can write to us by email instead.
  • Browser privacy signals. If your browser sends a "Global Privacy Control" or "Do Not Track" signal, we take it as a refusal of everything optional and do not show the banner. You can still allow an option yourself in the cookie settings.
  • The same everywhere. We ask every visitor in the same way, whatever country they are in.
  • Proof. Your choice is recorded only in your own browser, in the cookie named above. We keep no list of who agreed to what.

You can also delete cookies and site data, or block them for this site, in the privacy settings of your browser. If you block the sign-in cookies you cannot sign in; everything that needs no account keeps working. Signing out removes the session cookie.

7. Changes and contact

When we add or remove a cookie, this page changes first and the date at the top changes with it. A new optional cookie always comes with a new question: your earlier answer does not cover it. Questions: use the contact form or [email protected]. How we handle personal data in general is described in the privacy policy.