laypath Legal
Contents

Document 04 of 04

Cookie Policy

Rev 2026-10-03 Scope clay-path.com

This page lists every cookie Claypath uses and everything else it keeps in your browser: who sets it, what it is for and how long it lasts.

None of it is used for analytics or advertising, so you are not asked to consent to any of it. Everything listed is needed either to keep you signed in, to take a payment you started, or to remember something you did in the app. The privacy policy covers what Claypath does with your data more broadly.

01

What this page covers

A cookie is a small piece of text a website asks your browser to keep and send back on later visits. Browsers also have other ways for a page to keep things on your device, such as local storage and IndexedDB. The law treats them all alike, so this page lists all of them.

A first-time visitor who only reads the site gets none of this, apart from the setting covered in section 04 if they choose light or dark. Sign-in cookies arrive when you sign in, and payment cookies when you open checkout.

02

Signing in

Clerk runs Claypath's accounts. When you sign in, it sets these cookies so you stay signed in from one page to the next. Some are also written a second time under the same name with a short suffix on the end. That copy does the same job.

NameWhat it doesLasts
__clientHolds your sign-in. It is set on Clerk's sign-in address for Claypath, and the page's scripts cannot read it.Until you sign out or your session expires
__sessionA short-lived token proving you are signed in, sent with each request the app makes for you. Clerk replaces it about once a minute.Each token is good for one minute. The cookie is cleared when you sign out.
__client_uatRecords when your sign-in last changed, so a page can tell whether you are signed in before loading anything from Clerk. Claypath's own pages read it for exactly that reason. It is how the legal pages avoid contacting Clerk at all for someone who is not signed in.1 year
clerk_active_contextRemembers which sign-in is active when you have Claypath open in more than one tab.Until you close your browser

Clerk's sign-up form includes a bot check from Cloudflare. It runs in Cloudflare's own frame, and nothing it keeps is stored on clay-path.com.

03

Paying

Stripe takes Claypath's payments. Its payment form runs inside the Claypath page, and its script is only loaded once you open checkout. At that point it sets two cookies to help spot fraudulent payments.

NameWhat it doesLasts
__stripe_midLets Stripe recognise a browser it has seen before, as one signal in its fraud checks1 year
__stripe_sidLinks the steps of a single checkout for the same checks30 minutes

The card form itself is Stripe's own page in a frame, and anything it keeps is stored on Stripe's domain under Stripe's cookie policy.

04

What the app keeps in your browser

None of these are cookies, so none of them is ever sent to Claypath's servers. Each one is there because you did something the app should remember.

NameWhat it doesLasts
claypath_themeLight or dark, once you pick one. Until then the site follows your device's setting and stores nothing.Until you clear it
claypath_settingsThe mold settings from your last job, so the form is how you left itUntil you clear it
claypath_jobsYour ten most recent jobs, listed under Recent, one list per accountUntil a newer job replaces it, or you delete your account
claypath IndexedDBThe mold parts from those ten jobs, so a recent job opens again without asking the serverAs above
claypath_notices_dismissedWhich site announcements you have closed, so they stay closedUntil the announcement ends
claypath_active_job, claypath_active_zipThe job running in this tab, so a reload picks it up where it wasUntil you close the tab

Clerk also keeps a little of its own state in local storage while you are signed in, for the same purpose as the cookies in section 02.

05

What Claypath does not set

  • No analytics cookiesClaypath counts how its pages are used, on its own servers and without storing anything on your device. Section 01 of the privacy policy explains how.
  • No advertising cookiesThere is no advertising on Claypath and no advertising company's code runs on it.
  • Nothing that follows you elsewhereNothing listed here is read by any other website or used to recognise you on one.

If Claypath ever needs a cookie that is not strictly necessary, this page will change first, and you will be asked before it is set.

06

Global Privacy Control and Do Not Track

Global Privacy Control is a signal your browser can send to say you do not want your personal information sold or shared for advertising. Claypath honours it, but there is nothing for it to switch off: Claypath does not sell or share your personal information with anyone, whether you send the signal or not.

Do Not Track is an older signal asking not to be followed across websites. Claypath does not follow you across websites, so it makes no difference to what is recorded.

07

Clearing or blocking them

You can delete any of these from your browser's settings, under site data for clay-path.com. Here is what that costs:

  • Clearing the sign-in cookies signs you out. Blocking them stops you signing in at all.
  • Blocking Stripe's cookies may make a payment fail its fraud check.
  • Clearing the app's storage resets the form to its defaults and empties Recent on this device. A subscriber's stored jobs can still be downloaded from Recent on any device while they are kept.
08

Changes to this page

If a cookie or a storage item is added, removed or changes purpose, this page changes and the date at the top moves with it.

Claypath is a sole proprietorship trading as Claypath, established in California, United States. Questions about this page go to support@clay-path.com.

Withdraw from contract Claypath 0.1.10