Skip to main content
Legal

Cookie Policy

Effective 17 August 2026 · Version 1.2

This policy explains the cookies and similar storage CoreLoop uses, who sets them, and how long they last. CoreLoop is operated by Melange Oy (VAT FI27760448), Pitkäkalliontie 9, 01800 Klaukkala, Finland.

We keep this short and specific. If a cookie is not listed here, we do not set it.

What we store, and why there is no banner

We set two kinds of cookie: the ones the service needs to work at all, and the ones that remember a preference you expressed. There is no third kind. We set no advertising cookies, no cross-site tracking cookies, and nothing that profiles you.

We used to show a cookie banner asking you to accept or decline analytics. Our analytics no longer stores anything in your browser — no cookie, no local storage, no session storage — so the banner was offering a choice over an empty set. We removed it rather than keep asking a question with nothing behind it.

Worth stating plainly: our error-monitoring tool (Sentry) runs on every page. It sets no cookies and no browser storage, and it empties the fields of a report that would identify you before the report is sent.

Cookies we set to run the service

These sit on the domain you are visiting. All but the last are set by CoreLoop; the last is set by Google's sign-in prompt running on our sign-in page. None is used for advertising, and none is shared with an advertising network.

CookieWhat it doesLifetime
cl_theme, cl_theme_resYour light/dark appearance choice, and what “auto” resolved to, so the page does not flash the wrong theme.1 year
NEXT_LOCALEThe language you are reading the site in.1 year
cl_preferred_authWhich sign-in method to offer first, so you do not have to hunt for it next time.1 year
cl_previewSet only if you followed a preview link while the site was behind its pre-launch gate, so you can keep browsing without the link. Necessary — it is the only thing letting you past the gate.30 days
g_stateSet by Google’s sign-in prompt, and only on our sign-in and sign-up pages. It remembers that you closed the prompt so it does not reappear at every visit. Nothing else reads it, and it plays no advertising role.Up to 6 months (Google sets it, so the length is theirs)

The last row deserves a sentence of its own. On our sign-in and sign-up pages we show Google’s one-tap sign-in prompt, loaded by our authentication provider. Displaying it means your browser contacts accounts.google.com, so Google sees your network address and that you were on our sign-in page — the same as visiting any Google page. If you tap it, you are signing in with Google and your Google account details reach us through our authentication provider. If you close it, g_state is what stops it asking again.

Signing in also sets cookies from Clerk, our authentication provider, on clerk.coreloop.so. They hold your session and are strictly necessary — without them you cannot stay signed in. Their names are __session, __refresh, __client_uat, and others beginning with __clerk_. Clerk sets and controls these directly.

Analytics — nothing stored in your browser

We use Vercel Web Analytics to see which pages are visited and which features are opened. It sets no cookie, writes nothing to your browser's local or session storage, and reads nothing that is already there.

To count a visitor once instead of once per page, it derives a value from the request your browser makes — the network address and browser details every request carries anyway. That value is computed with a secret that changes daily and is specific to this site, so the same visitor is a different value tomorrow and cannot be matched to a visit on any other site. It is not stored on your device and cannot be read back from it.

A handful of product events are recorded the same way — for example, that an onboarding step was viewed, or that a setup task was marked done. They carry at most a short label such as which step it was. They are not attached to your name or email address, and they are not attached to a stored identifier.

Other browser storage

We keep a small amount of interface state in your browser's local storage: whether you have seen a particular first-time hint, whether you dismissed a banner, and the light/dark preference for a public business page. It never leaves your browser.

Nothing else writes to your browser: our analytics provider stores no entries of its own, and we use no session storage, no IndexedDB, no cache storage and no service workers. Our fonts are served from our own servers, so displaying a page makes no request to a font provider.

Public business pages

A published CoreLoop page — the public page for a business — is measured without cookies. We count page views using a value derived from the visitor's network address and browser, salted with a secret that changes every day, so the same visitor cannot be recognised across days and the value cannot be traced back to them. No cookie is set and none is read.

When a business serves its CoreLoop page on its own domain, we set no CoreLoop cookies at all on that domain.

Questions

Write to support@coreloop.so. How we handle personal data more generally is covered in our Privacy Policy.