1. What this page covers
This page explains the cookies and similar browser storage used by soloop. It sits next to the Privacy Policy, which covers the larger data picture: account data, project context, files, connected accounts, agents, logs, and deletion.
Cookies and browser storage are small records stored by your browser. They can keep you signed in, remember product state, complete OAuth flows, protect the service, and help us debug failures.
2. Cookies we use today
The current product uses necessary cookies for login, session refresh, account checks, OAuth completion, and security. Turning them off can break sign-in, connected-account setup, or workspace access.
soloop uses first-party analytics and Google Analytics 4 to measure public-page views, sessions, active time, traffic sources, and explicitly labelled interactions. This helps evaluate technical performance, SEO, navigation, and the signup journey.
Google Ads conversion measurement can store click or visitor identifiers and receives a conversion event after a confirmed registration. We use that information to understand campaign performance and avoid treating a page visit as a completed signup.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| sb-* auth cookies | Supabase and soloop | Keeps you signed in, refreshes sessions, and lets protected workspace routes check account access. | Session-based. Cleared by sign-out, expiry, or browser cleanup. |
| OAuth state records | soloop server | Finishes account connection flows for Twitter/X, Reddit, GitHub, Stripe, and similar integrations. | Short-lived. Used to complete or reject the connection attempt. |
| soloop_analytics_visitor | soloop | Connects public-page events within the same pseudonymous browser journey and supports registration attribution. | Up to 90 days, or until browser cleanup. |
| _ga | Google Analytics | Stores a first-party pseudonymous client identifier used to distinguish visitors and measure usage across sessions. | Up to 2 years by default, subject to browser limits, deletion, and Google tag settings. |
| _ga_P1ERPDN42H | Google Analytics | Persists session state for the Soloop Production GA4 web data stream. | Up to 2 years by default, subject to browser limits, deletion, and Google tag settings. |
| Request and security logs | soloop and infrastructure providers | Records IP address, user agent, path, timestamp, errors, and performance data for security, abuse checks, and debugging. | Kept only as long as needed for operation, security, billing, support, or legal reasons. |
3. Browser storage
soloop also uses local browser storage for lightweight interface state. This is not used to sell data or build ad profiles.
Clearing browser storage can reset UI state. It should not delete server-side projects, chats, tasks, files, connected-account records, or billing records.
Anonymous analytics session
After analytics permission, session storage holds a random session ID, landing path, referrer host, and last-seen time. It rotates after 30 minutes of inactivity and is cleared when analytics is rejected.
Workspace state
Active thread, sent-task drawer state, inbox read markers, auto-mode preference, and column width.
Start and setup state
Landing-page project input and pending GitHub project setup state so a flow can resume after sign-in or authorization.
Registration measurement state
A pseudonymous registration-derived marker prevents the same browser from reporting the same confirmed registration more than once to Google Ads and Google Analytics.
Debug or preview state
Local-only state used by development or preview surfaces, such as paid preview state in debug pages.
4. Third-party providers
soloop uses services such as Google Analytics, Google Ads, Supabase, AI model providers, TokenRouter, Anthropic, Vercel Sandbox, Stripe, X/Twitter, Reddit, GitHub, Apify, hosting providers, and email providers.
Google processes analytics and conversion-measurement data under its own terms and privacy documentation. The Google tag is configured for the Soloop Production GA4 stream and Soloop's Google Ads conversion destination.
Stripe processes subscription billing on Stripe-hosted Checkout and Billing Portal pages. We do not receive or store full card numbers or CVC. Stripe may set or read its own cookies on those pages under its policy.
When a feature needs one of those services, the provider may receive request data and may set or read cookies on its own site. Its own policy controls that provider-side behavior.
If you approve a connected-account action, the external service can also keep logs, tokens, account records, rate-limit data, or abuse-prevention records under its own rules.
5. Analytics and conversion measurement
soloop measures public-page paths, active-time increments, explicitly labelled clicks, signup funnel steps, and permitted source attribution. These events exclude form values, free-form page text, passwords, verification codes, uploaded content, and authenticated workspace activity.
soloop does not sell personal data or cookie identifiers. The current product does not configure third-party interest-based advertising or build retargeting audiences from workspace content.
The Google Ads tag is used for conversion measurement. If we enable new advertising uses, audiences, or providers, we will update this page.
6. Your choices
You can block or clear cookies in your browser. Necessary cookies are tied to login and workspace access, so blocking them can sign you out or stop the app from working.
Blocking or clearing Google Analytics or Google Ads cookies can reduce the accuracy of session, traffic-source, and conversion reporting. You can also use Google's browser opt-out tools and the privacy controls available in your Google account. soloop does not currently provide a separate in-site analytics-cookie toggle.
You can clear local browser storage to reset local UI state. You can revoke connected accounts in the external service, and you can ask soloop to disconnect or delete related records through the product's support channel.
We retain cookie-linked security and billing logs only as long as needed for operation, fraud prevention, accounting, disputes, or legal duties. When those records are no longer needed, we delete or anonymize them where feasible.
7. Changes
We update this Cookie Policy when the product, integrations, cookie use, browser storage, or legal requirements change.
If a change affects your choices, we will post the updated page or use an in-product notice.
8. Contact
For cookie, privacy, security, deletion, export, or account-access requests, use the email link below.
Soloop, Inc. is responsible for this policy. Postal address: 6357 Joaquin Murieta Ave, Newark, CA 94560, United States. Email: [email protected].
admin@soloop.io