Cookie policy
Last updated: 18 August 2026
Cookies are small values a site stores in your browser; we also use similar browser storage (localStorage). Jarville splits them into two groups: essential (the site cannot work safely without them, so they are always on) and analytics and advertising, which are set only if you accept them in the consent banner.
Where you are decides whether we ask first. If you are visiting from the European Union or the EEA (including EU territories with their own country code, such as Åland, Réunion or Martinique), the United Kingdom, Gibraltar or the Crown dependencies, Switzerland, Monaco, Andorra, San Marino, Turkey, Brazil, China, Vietnam, Thailand, Indonesia, South Korea, Nigeria, Saudi Arabia, or Quebec (places whose law requires your permission before analytics or advertising cookies are set), you see the consent banner and nothing non-essential runs until you answer it. Elsewhere, the law asks for notice and an easy way to say no rather than a yes first, so those cookies are on from your first page and you can switch them off at any time with the Cookie preferences link below or in the footer. Advertising is treated more carefully than analytics in that case: where you were never asked, our Google tag is limited to counting conversions, with personalised advertising switched off. We work out your country from your IP address on our hosting provider’s edge, use only the two-letter country code, and store neither. If the country cannot be determined, we ask.
If you decline, we do not stop measuring entirely. We measure in a way that stores nothing on your device and cannot identify you or follow you between days. That is described in full under If you decline below, so you can judge it for yourself rather than take our word for it.
You can change your choice any time, in either direction: (re-opens the prompt). It is also in the site footer on every page, and under Your data on your account page if you are signed in. Turning analytics back on after declining is exactly as easy as declining was.
We remember whichever way you answered for 6 months, then ask again. We do not re-ask sooner because you said no. Your browser can also block or delete cookies wholesale, though blocking the essential ones will break sign-in. We honour the Global Privacy Control signal: browsers sending it get analytics declined automatically, and the anonymous measurement below is switched off for them too.
Essential
| Name | What it does | Lifetime |
|---|---|---|
| Session cookie (better-auth) | Keeps you signed in | Session length |
| jv_device | Free-tier rate limiting and abuse protection (server-issued, HttpOnly) | 1 year |
| jv_consent | Remembers your cookie choice, whichever way you answered. Outside the opt-in regions listed above it holds implied until you make an explicit choice, which always replaces it | 6 months |
| jv_visitor | Browser identifier used only to meter free runs and block abuse (see below) | 1 year |
Analytics and advertising: only with your consent
| Name | What it does | Lifetime |
|---|---|---|
| jv_anon (+ newco_anon_id) | Anonymous visitor id, so your pre-signup activity connects to your account | 1 year |
| jv_session (+ newco_session) | Groups one visit into a session | Hours |
| jv_campaign (+ newco_campaign) | Remembers which campaign link brought you here | Session |
| ph_* (PostHog, EU-hosted) | Product analytics: page views, interactions, session recordings. Recordings never capture what you type; every input is masked before the recording leaves your browser | Up to 1 year |
| _gcl_* (Google Ads) | Tells us which of our ads led to a signup. Where you were not asked for consent it runs in Google’s restricted mode: conversion measurement only, no personalised advertising | Up to 90 days |
| _fbp (Meta) | Tells us which of our Meta ads led to a visit. The pixel does not run on the sign-in page, so an email address you type there is never read by it | Up to 90 days |
Declining means none of the above are set, no session recording happens and no advertising tag loads. The tools themselves (including the free layer) work exactly the same either way.
If you decline: anonymous measurement
We still need to know basic things like how many people visited, which pages they landed on and whether the free tools finished successfully. If you decline cookies we measure that without storing anything on your device at all.
Instead, our server turns your IP address and browser user-agent into a one-way code, mixed with a secret that changes every day. The code cannot be turned back into your IP address. Because the secret rotates, you get a completely different code tomorrow, so this can count a visit but cannot follow you over time or build a profile. Nothing is written to or read from your browser, and no session recording, autocapture or feature-flag data is collected.
Where you land in the world (country-level, from your IP) and which browser and device type you used are recorded alongside those counts. If you would rather not be counted at all, send the Global Privacy Control signal from your browser, or email us at the address below.
Fraud and abuse prevention
The free tools are metered per browser, which needs a way to recognise the same browser returning. We use Fingerprint for this: it runs on the pages where a free run can be started (the tool pages) before and regardless of your cookie choice, and stores a jv_visitor identifier in your browser. It does not run on the rest of the site. It is used only to enforce free-run limits, never for analytics, advertising or profiling. We treat it as strictly necessary to provide the free tools without them being drained by automated abuse, which is why it is scoped to the tools rather than to every page you look at.
Questions
See the privacy policy for how analytics data is used, or email privacy@jarville.biz.
