Cookie Policy

Cookie Policy

This Cookie Policy explains how Saavo uses cookies and similar browser storage on our website, account pages, checkout, support tools, OAuth authorization flows, and template delivery services.

Last Updated: August 12, 2026

Complete Cookie Policy

This page describes the cookies and similar technologies currently relevant to Saavo.

1What Cookies and Similar Technologies Are

Cookies are small files stored by your browser. They can keep a user signed in, remember preferences, secure redirects, or help us understand how the website is used.

We also use similar browser storage, such as localStorage and sessionStorage, for interface preferences and enabled analytics behavior. This policy covers those technologies together because they affect your browser in a similar way.

2How Our Website Uses Cookies

Strictly necessary cookies

These are required for the service to work. They support login, session security, email verification, password reset, two-factor checks, account settings, dashboard access, checkout, billing portal access, support tickets, OAuth authorization, language detection, anonymous-use limits, rate limiting, fraud prevention, abuse prevention, and redirect messages. You cannot disable these through our cookie banner.

Functionality cookies and browser storage

These remember choices such as cookie consent, theme, and dashboard sidebar state. A referral-attribution cookie also remembers the first Affiliate link deliberately followed by a signed-out visitor for the current browser session. These technologies make repeated use of the site less repetitive, but they do not determine your entitlement to a paid Saavo product.

Analytics cookies

When analytics providers are configured and you consent, we may load analytics scripts to understand page views, referrers, device/browser information, feature usage, and conversion events. The configured consent system supports providers such as Google Analytics, Microsoft Clarity, Cloudflare Web Analytics, Umami, Plausible, PostHog, Seline, Ahrefs Web Analytics, DataFast, and OpenPanel, but only providers with active scripts are shown in the preference dialog.

Marketing cookies

If advertising is enabled and you consent, Google AdSense or similar advertising partners may use cookies or identifiers to display ads, measure ad performance, reduce ad fraud, and understand campaign effectiveness.

3Current Cookies and Browser Storage

The following table reflects the cookie and browser storage names used by the current website code or supported by current service integrations. Third-party providers may set additional cookies under their own domains.

Name / StorageCategoryPurposeDuration
saavo_anonymous_id

First-party signed HTTP-only cookie

Strictly necessary — security and abuse preventionRecognizes this browser independently of account login so the service can enforce anonymous-use limits, rate limits, fraud controls, and abuse prevention. The signed value contains a randomly generated pseudonymous ID and is not used for cross-site advertising.365d; re-signed with the same logical ID when less than 30d remains.
saas_session

First-party HTTP cookie

Strictly necessaryKeeps you signed in and lets the website recognize your account for dashboard, checkout, billing portal, support tickets, OAuth authorization, and account settings.30 days, with renewal when an active session is close to expiration.
saavo_affiliate_referral

First-party HTTP-only session cookie

Functionality / referral attributionStores the first valid referral code followed by a signed-out visitor after confirming that the referring Affiliate is active. An inactive, missing, or malformed referral does not set the cookie. A later valid referral link does not replace the existing code. The referring Affiliate must still be active when the new account is created. This cookie is written independently of cookie-banner choices and is not used for cross-site advertising.Current browser session or until successful account creation. A complete browser shutdown normally clears it, although browser session restoration may restore session cookies.
auth_step_up_session

First-party HTTP-only cookie

Strictly necessaryRemembers a recent identity check so sensitive account actions do not repeatedly ask for verification during the short verification window.About 10 minutes.
email_verification_session

First-party HTTP cookie

Strictly necessaryMaintains the temporary email verification flow after signup, email changes, or verification-code requests.About 10 minutes.
password_reset_session

First-party HTTP cookie

Strictly necessaryMaintains the temporary password reset flow, including email verification and any required two-factor step.About 10 minutes.
oauth_auth_session

First-party HTTP cookie

Strictly necessaryMaintains a temporary OAuth authorization request when Saavo CLI or another approved client asks you to authorize access.About 10 minutes.
oauth2_github_state

First-party HTTP cookie

Strictly necessaryProtects GitHub sign-in redirects by matching the OAuth state value returned by GitHub.About 10 minutes or until the callback completes.
oauth2_google_state

First-party HTTP cookie

Strictly necessaryProtects Google sign-in redirects by matching the OAuth state value returned by Google.About 10 minutes or until the callback completes.
oauth2_google_code_verifier

First-party HTTP cookie

Strictly necessarySupports the PKCE security step used during Google sign-in.About 10 minutes or until the callback completes.
X-Flash-Message

First-party temporary cookie

Strictly necessaryCarries a short success or error message across redirects, such as OAuth, account, checkout, or dashboard actions. Large messages may be split into related cookie chunks.Normally about 10 seconds, then cleared.
saas_locale

First-party cookie, when present

Strictly necessary / preferenceAllows the server to detect a preferred language when a locale is available from a cookie. Page URLs remain the primary source for page language.Depends on browser or prior language-setting behavior.
cookie_consent

First-party cookie

Functionality / consent recordStores your cookie choices, including policy version, config version, enabled categories, status, and timestamps.365 days, unless you clear it or we change the policy/config version.
sidebar_state

First-party cookie

FunctionalityRemembers whether the dashboard sidebar is expanded or collapsed.7 days.
saas-theme

Browser localStorage, not a cookie

FunctionalityRemembers your light or dark theme preference between visits.Until changed or cleared in the browser.
saavo.analytics.cache.v1:*

Browser sessionStorage, not a cookie

Analytics — only when Saavo Sliding analytics is enabledStores an opaque, server-signed Visit cache for one Website ID and collection endpoint so a full-page reload can continue the same sliding Visit. It is not used by the Umami strategy and is not a public user identifier.For the current browser tab session; removed when the site or tracker is disabled, the identity changes, or browser session storage is cleared.
saavo.disabled

Browser localStorage, not a cookie

Analytics preferenceRemembers that first-party Saavo Analytics collection has been disabled in this browser through the available Analytics control.Until Analytics is enabled again or localStorage is cleared in the browser.

4Saavo CLI and Template Delivery

The website may use cookies to maintain an OAuth authorization request initiated by Saavo CLI. After approval, the CLI exchanges the authorization result using the OAuth protocol and may store its own local credentials or project configuration outside the browser.

The website cookie banner controls cookies and browser storage used by this website. It does not control local files or secure credential storage created by Saavo CLI. CLI credentials can be managed through the applicable account and authorization flows.

5Third-Party Services

Some service flows involve third parties that may set or read their own cookies, identifiers, or browser storage. These third parties control their own technologies and policies.

  • Stripe: checkout, payment processing, receipts, fraud prevention, tax collection, and payment-management sessions.
  • Google and GitHub: OAuth sign-in redirects and identity verification.
  • Cloudflare and Turnstile: hosting, security checks, bot protection, rate limiting, and abuse prevention.
  • Analytics and advertising providers: measurement or advertising only when configured and allowed by your consent choices, except where a provider's technology is strictly necessary for security or delivery.

6Managing Your Choices

Necessary cookies are always active because the website needs them for security, login, checkout, account management, support, and fraud prevention.

  • Use the cookie banner or preferences dialog to accept all, reject non-essential cookies, or customize analytics, marketing, and functionality choices.
  • Clear or block cookies in your browser settings. Blocking necessary cookies may prevent login, checkout, billing portal access, support ticket access, OAuth authorization, and account security flows from working.
  • Clearing saavo_anonymous_id removes the current browser token. Because this identity is used for security and abuse prevention, the website creates another signed token on the next request while the feature is enabled.
  • Clear local storage in your browser if you want to remove the saved theme or first-party Analytics opt-out preference.
  • Clearing saavo_affiliate_referral before account creation removes the referral attribution from the current browser. Following another valid link for an active Affiliate can then establish a new session attribution.
  • Review or revoke supported OAuth access and sign out of the website when you no longer want an active account session.
  • Manage third-party cookies directly with Stripe, Google, GitHub, Cloudflare, and any configured analytics or advertising providers.

7Do Not Track and Browser Signals

Some browsers send "Do Not Track" or similar signals. Because there is no single industry standard for how these signals should be interpreted, our primary control is the cookie preference system described above. We will also honor legally required browser or platform-level signals where they apply to our service.

8Changes to This Policy

We may update this Cookie Policy when our website, Saavo CLI authorization, payment flows, analytics setup, advertising setup, security controls, or third-party providers change. If we make a material change, we may update the "Last Updated" date, reset the consent version, or show the cookie banner again.

9Contact Us

If you have questions about cookies, browser storage, CLI authorization, or privacy choices, contact us at:

Third-party cookie practices are governed by those third parties' own privacy and cookie policies.