Home
Cookies and browser storage
The default service uses only first-party, strictly necessary browser technologies. It does not load optional third-party browser scripts or show a consent banner.
Authentication session
The secure, HttpOnly session cookie keeps an authenticated account signed in for the configured idle and absolute session limits.
Language preference
After you deliberately choose a language, a first-party locale cookie remembers that choice for up to 13 months. You can change it at any time.
Anonymous-upload security token
Anonymous guest uploads can use a narrow first-party security token to apply abuse and rate controls. It is not used for advertising, profiling, or cross-site tracking.
Event setup during sign-in
Immediately before you continue to an identity provider, the current event form can be kept in this tab for up to ten minutes so setup can resume when you return. It is removed after the event is created or it expires, is not shared across tabs, and contains no sign-in token, provider identity, private guest link, photo, filename, or analytics attribution.
Landing attribution handoff
When you follow a creation link from a Daytold landing page, a host-wide first-party, HttpOnly browser-session cookie carries the signed, allowlisted acquisition attribution to the setup page. It is removed when the page opens and contains no raw campaign input, referrer URL, account identifier, or event identifier.
Optional technology
Optional browser technology is disabled by default. If it is ever enabled, it remains blocked until you make a specific choice and can be withdrawn from Privacy settings.