Legal
Cookie Notice
Effective 8 September 2026.
Citelift uses first-party cookies only, all of them strictly necessary to keep you signed in. There are no third-party cookies at all.
What we set
| Cookie | Type | Purpose | Lifetime |
|---|---|---|---|
| Session cookie | Strictly necessary, first-party | Keeps you signed in to the embedded Shopify app and carries the CSRF protection on forms. Set only once you authenticate | Session, or up to 30 days if you stay signed in |
| Sign-in cookies set by Clerk | Strictly necessary, first-party | Clerk runs sign-in, sign-up and session management for the Citelift web account. Signing in sets a session cookie and the supporting cookies Clerk needs to keep that session valid and to protect it. They are set on our own domain, only once you use an account page, and they carry no advertising or cross-site identifier | Session, up to Clerk's session lifetime; cleared when you sign out |
Strictly necessary cookies do not require consent under the ePrivacy Directive or the PECR, because without them the thing you asked for does not work. We therefore do not show a cookie banner: there is nothing to consent to.
What we do not do
- No third-party cookies. No advertising, retargeting or social pixels — not on this site, and not inside the embedded app.
- No cross-site tracking. We do not build profiles of you across other sites, and we sell nothing to anyone who does.
- No advertising or third-party analytics tags. Google Analytics, Meta Pixel and their equivalents are absent by design. The one analytics script we run is our own, served from citelift.app, and sets no cookie — see below.
How we measure the product instead
Product analytics are recorded server-side: when the app publishes an article, when a visibility check completes, when an install finishes. Those rows are keyed by a store or domain identifier and are described in our Privacy Policy. They are not tied to a browser identifier and set nothing on your device. Public page-load counts, which the page sends to citelift.app once it has loaded, separately record only a known page path, a broad referral category and any campaign tags on the link that brought you.
So that we can tell how many people read a page rather than only how many times it was loaded, each page-load count carries a visitor number worked out on our server. We build it by hashing your IP address and browser user-agent string together with a secret that changes every day. Nothing is stored on your device and no cookie is set. The number cannot be turned back into your IP address, and because yesterday's secret is gone, your number today cannot be connected to your number yesterday. It tells us that one person read three pages this morning. It cannot tell us that you came back, build a profile, or follow you anywhere. Anonymous local-tool completion requests contain only the tool name and outcome; they use no browser identifier or analytics cookie. A known Citelift page path can accompany an explicit signup journey without tracking prior visits.
The one script on our public pages
Our public pages load a small first-party analytics script so we can see how long pages are read and how quickly they load for real visitors. It is served from citelift.app and talks only to citelift.app, which passes what it reports on to PostHog. It sets no cookie and uses no local or session storage, so there is nothing on your device to consent to. It reports the page address without its query string, the linking site's domain, your browser and device type, when you leave the page, and loading-speed measurements. If the advertising prompt is shown, it also reports that it was shown and which answer you gave. It does not record your screen, clicks, keystrokes or tool inputs; it does not run in the signed-in workspace, the embedded app or private report links; and it does not load if your browser sends Do Not Track or Global Privacy Control. The Privacy Policy describes how PostHog tells visits apart without an identifier on your device.
Fonts and other requests
The marketing site's typefaces are served from our own origin. Reading a public page sends no request to Google Fonts or to any other font host, and sets nothing on your device.
Two third-party requests do happen, and neither is analytics:
- Clerk's Frontend API, on the sign-in, sign-up and account pages only. It loads the sign-in form and holds the session cookie described above. Public marketing pages do not load it.
- cdn.shopify.com, inside the embedded Shopify admin app and its authorisation screens, for the Polaris interface stylesheet Shopify's own admin uses. Public marketing pages do not load it.
As with any request for a file, each reveals your IP address to the host serving it. Everything else the page needs is served from our own domain.
Your browser controls
You can block or delete cookies in your browser settings. Blocking the session cookie will sign you out of the embedded app; the public pages, including the AI-visibility check, work without it.
Questions
Write to siddesh@citelift.app.