Cookie Policy
This Cookie Policy explains how Saavo uses cookies and similar browser storage on our website, account pages, checkout, support tools, OAuth authorization flows, and template delivery services.
Last Updated: August 12, 2026
Complete Cookie Policy
This page describes the cookies and similar technologies currently relevant to Saavo.
1What Cookies and Similar Technologies Are
Cookies are small files stored by your browser. They can keep a user signed in, remember preferences, secure redirects, or help us understand how the website is used.
We also use similar browser storage, such as localStorage and sessionStorage, for interface preferences and enabled analytics behavior. This policy covers those technologies together because they affect your browser in a similar way.
2How Our Website Uses Cookies
Strictly necessary cookies
These are required for the service to work. They support login, session security, email verification, password reset, two-factor checks, account settings, dashboard access, checkout, billing portal access, support tickets, OAuth authorization, language detection, anonymous-use limits, rate limiting, fraud prevention, abuse prevention, and redirect messages. You cannot disable these through our cookie banner.
Functionality cookies and browser storage
These remember choices such as cookie consent, theme, and dashboard sidebar state. A referral-attribution cookie also remembers the first Affiliate link deliberately followed by a signed-out visitor for the current browser session. These technologies make repeated use of the site less repetitive, but they do not determine your entitlement to a paid Saavo product.
Analytics cookies
When analytics providers are configured and you consent, we may load analytics scripts to understand page views, referrers, device/browser information, feature usage, and conversion events. The configured consent system supports providers such as Google Analytics, Microsoft Clarity, Cloudflare Web Analytics, Umami, Plausible, PostHog, Seline, Ahrefs Web Analytics, DataFast, and OpenPanel, but only providers with active scripts are shown in the preference dialog.
Marketing cookies
If advertising is enabled and you consent, Google AdSense or similar advertising partners may use cookies or identifiers to display ads, measure ad performance, reduce ad fraud, and understand campaign effectiveness.
3Current Cookies and Browser Storage
The following table reflects the cookie and browser storage names used by the current website code or supported by current service integrations. Third-party providers may set additional cookies under their own domains.
| Name / Storage | Category | Purpose | Duration |
|---|---|---|---|
saavo_anonymous_idFirst-party signed HTTP-only cookie | Strictly necessary — security and abuse prevention | Recognizes this browser independently of account login so the service can enforce anonymous-use limits, rate limits, fraud controls, and abuse prevention. The signed value contains a randomly generated pseudonymous ID and is not used for cross-site advertising. | 365d; re-signed with the same logical ID when less than 30d remains. |
saas_sessionFirst-party HTTP cookie | Strictly necessary | Keeps you signed in and lets the website recognize your account for dashboard, checkout, billing portal, support tickets, OAuth authorization, and account settings. | 30 days, with renewal when an active session is close to expiration. |
saavo_affiliate_referralFirst-party HTTP-only session cookie | Functionality / referral attribution | Stores the first valid referral code followed by a signed-out visitor after confirming that the referring Affiliate is active. An inactive, missing, or malformed referral does not set the cookie. A later valid referral link does not replace the existing code. The referring Affiliate must still be active when the new account is created. This cookie is written independently of cookie-banner choices and is not used for cross-site advertising. | Current browser session or until successful account creation. A complete browser shutdown normally clears it, although browser session restoration may restore session cookies. |
auth_step_up_sessionFirst-party HTTP-only cookie | Strictly necessary | Remembers a recent identity check so sensitive account actions do not repeatedly ask for verification during the short verification window. | About 10 minutes. |
email_verification_sessionFirst-party HTTP cookie | Strictly necessary | Maintains the temporary email verification flow after signup, email changes, or verification-code requests. | About 10 minutes. |
password_reset_sessionFirst-party HTTP cookie | Strictly necessary | Maintains the temporary password reset flow, including email verification and any required two-factor step. | About 10 minutes. |
oauth_auth_sessionFirst-party HTTP cookie | Strictly necessary | Maintains a temporary OAuth authorization request when Saavo CLI or another approved client asks you to authorize access. | About 10 minutes. |
oauth2_github_stateFirst-party HTTP cookie | Strictly necessary | Protects GitHub sign-in redirects by matching the OAuth state value returned by GitHub. | About 10 minutes or until the callback completes. |
oauth2_google_stateFirst-party HTTP cookie | Strictly necessary | Protects Google sign-in redirects by matching the OAuth state value returned by Google. | About 10 minutes or until the callback completes. |
oauth2_google_code_verifierFirst-party HTTP cookie | Strictly necessary | Supports the PKCE security step used during Google sign-in. | About 10 minutes or until the callback completes. |
X-Flash-MessageFirst-party temporary cookie | Strictly necessary | Carries a short success or error message across redirects, such as OAuth, account, checkout, or dashboard actions. Large messages may be split into related cookie chunks. | Normally about 10 seconds, then cleared. |
saas_localeFirst-party cookie, when present | Strictly necessary / preference | Allows the server to detect a preferred language when a locale is available from a cookie. Page URLs remain the primary source for page language. | Depends on browser or prior language-setting behavior. |
cookie_consentFirst-party cookie | Functionality / consent record | Stores your cookie choices, including policy version, config version, enabled categories, status, and timestamps. | 365 days, unless you clear it or we change the policy/config version. |
sidebar_stateFirst-party cookie | Functionality | Remembers whether the dashboard sidebar is expanded or collapsed. | 7 days. |
saas-themeBrowser localStorage, not a cookie | Functionality | Remembers your light or dark theme preference between visits. | Until changed or cleared in the browser. |
saavo.analytics.cache.v1:*Browser sessionStorage, not a cookie | Analytics — only when Saavo Sliding analytics is enabled | Stores an opaque, server-signed Visit cache for one Website ID and collection endpoint so a full-page reload can continue the same sliding Visit. It is not used by the Umami strategy and is not a public user identifier. | For the current browser tab session; removed when the site or tracker is disabled, the identity changes, or browser session storage is cleared. |
saavo.disabledBrowser localStorage, not a cookie | Analytics preference | Remembers that first-party Saavo Analytics collection has been disabled in this browser through the available Analytics control. | Until Analytics is enabled again or localStorage is cleared in the browser. |
4Saavo CLI and Template Delivery
The website may use cookies to maintain an OAuth authorization request initiated by Saavo CLI. After approval, the CLI exchanges the authorization result using the OAuth protocol and may store its own local credentials or project configuration outside the browser.
The website cookie banner controls cookies and browser storage used by this website. It does not control local files or secure credential storage created by Saavo CLI. CLI credentials can be managed through the applicable account and authorization flows.
5Third-Party Services
Some service flows involve third parties that may set or read their own cookies, identifiers, or browser storage. These third parties control their own technologies and policies.
- Stripe: checkout, payment processing, receipts, fraud prevention, tax collection, and payment-management sessions.
- Google and GitHub: OAuth sign-in redirects and identity verification.
- Cloudflare and Turnstile: hosting, security checks, bot protection, rate limiting, and abuse prevention.
- Analytics and advertising providers: measurement or advertising only when configured and allowed by your consent choices, except where a provider's technology is strictly necessary for security or delivery.
6Managing Your Choices
Necessary cookies are always active because the website needs them for security, login, checkout, account management, support, and fraud prevention.
- Use the cookie banner or preferences dialog to accept all, reject non-essential cookies, or customize analytics, marketing, and functionality choices.
- Clear or block cookies in your browser settings. Blocking necessary cookies may prevent login, checkout, billing portal access, support ticket access, OAuth authorization, and account security flows from working.
- Clearing
saavo_anonymous_idremoves the current browser token. Because this identity is used for security and abuse prevention, the website creates another signed token on the next request while the feature is enabled. - Clear local storage in your browser if you want to remove the saved theme or first-party Analytics opt-out preference.
- Clearing
saavo_affiliate_referralbefore account creation removes the referral attribution from the current browser. Following another valid link for an active Affiliate can then establish a new session attribution. - Review or revoke supported OAuth access and sign out of the website when you no longer want an active account session.
- Manage third-party cookies directly with Stripe, Google, GitHub, Cloudflare, and any configured analytics or advertising providers.
7Do Not Track and Browser Signals
Some browsers send "Do Not Track" or similar signals. Because there is no single industry standard for how these signals should be interpreted, our primary control is the cookie preference system described above. We will also honor legally required browser or platform-level signals where they apply to our service.
8Changes to This Policy
We may update this Cookie Policy when our website, Saavo CLI authorization, payment flows, analytics setup, advertising setup, security controls, or third-party providers change. If we make a material change, we may update the "Last Updated" date, reset the consent version, or show the cookie banner again.
9Contact Us
If you have questions about cookies, browser storage, CLI authorization, or privacy choices, contact us at:
Third-party cookie practices are governed by those third parties' own privacy and cookie policies.