Document 04 of 04
Cookie Policy
This page lists every cookie Claypath uses and everything else it keeps in your browser: who sets it, what it is for and how long it lasts.
None of it is used for analytics or advertising, so you are not asked to consent to any of it. Everything listed is needed either to keep you signed in, to take a payment you started, or to remember something you did in the app. The privacy policy covers what Claypath does with your data more broadly.
What this page covers
A cookie is a small piece of text a website asks your browser to keep and send back on later visits. Browsers also have other ways for a page to keep things on your device, such as local storage and IndexedDB. The law treats them all alike, so this page lists all of them.
A first-time visitor who only reads the site gets none of this, apart from the setting covered in section 04 if they choose light or dark. Sign-in cookies arrive when you sign in, and payment cookies when you open checkout.
Signing in
Clerk runs Claypath's accounts. When you sign in, it sets these cookies so you stay signed in from one page to the next. Some are also written a second time under the same name with a short suffix on the end. That copy does the same job.
| Name | What it does | Lasts |
|---|---|---|
__client | Holds your sign-in. It is set on Clerk's sign-in address for Claypath, and the page's scripts cannot read it. | Until you sign out or your session expires |
__session | A short-lived token proving you are signed in, sent with each request the app makes for you. Clerk replaces it about once a minute. | Each token is good for one minute. The cookie is cleared when you sign out. |
__client_ | Records when your sign-in last changed, so a page can tell whether you are signed in before loading anything from Clerk. Claypath's own pages read it for exactly that reason. It is how the legal pages avoid contacting Clerk at all for someone who is not signed in. | 1 year |
clerk_ | Remembers which sign-in is active when you have Claypath open in more than one tab. | Until you close your browser |
Clerk's sign-up form includes a bot check from Cloudflare. It runs in Cloudflare's own frame, and nothing it keeps is stored on clay-path.com.
Paying
Stripe takes Claypath's payments. Its payment form runs inside the Claypath page, and its script is only loaded once you open checkout. At that point it sets two cookies to help spot fraudulent payments.
| Name | What it does | Lasts |
|---|---|---|
__stripe_ | Lets Stripe recognise a browser it has seen before, as one signal in its fraud checks | 1 year |
__stripe_ | Links the steps of a single checkout for the same checks | 30 minutes |
The card form itself is Stripe's own page in a frame, and anything it keeps is stored on Stripe's domain under Stripe's cookie policy.
What the app keeps in your browser
None of these are cookies, so none of them is ever sent to Claypath's servers. Each one is there because you did something the app should remember.
| Name | What it does | Lasts |
|---|---|---|
claypath_ | Light or dark, once you pick one. Until then the site follows your device's setting and stores nothing. | Until you clear it |
claypath_ | The mold settings from your last job, so the form is how you left it | Until you clear it |
claypath_ | Your ten most recent jobs, listed under Recent, one list per account | Until a newer job replaces it, or you delete your account |
claypath IndexedDB | The mold parts from those ten jobs, so a recent job opens again without asking the server | As above |
claypath_ | Which site announcements you have closed, so they stay closed | Until the announcement ends |
claypath_, claypath_ | The job running in this tab, so a reload picks it up where it was | Until you close the tab |
Clerk also keeps a little of its own state in local storage while you are signed in, for the same purpose as the cookies in section 02.
What Claypath does not set
- No analytics cookiesClaypath counts how its pages are used, on its own servers and without storing anything on your device. Section 01 of the privacy policy explains how.
- No advertising cookiesThere is no advertising on Claypath and no advertising company's code runs on it.
- Nothing that follows you elsewhereNothing listed here is read by any other website or used to recognise you on one.
If Claypath ever needs a cookie that is not strictly necessary, this page will change first, and you will be asked before it is set.
Global Privacy Control and Do Not Track
Global Privacy Control is a signal your browser can send to say you do not want your personal information sold or shared for advertising. Claypath honours it, but there is nothing for it to switch off: Claypath does not sell or share your personal information with anyone, whether you send the signal or not.
Do Not Track is an older signal asking not to be followed across websites. Claypath does not follow you across websites, so it makes no difference to what is recorded.
Clearing or blocking them
You can delete any of these from your browser's settings, under site data for clay-path.com. Here is what that costs:
- Clearing the sign-in cookies signs you out. Blocking them stops you signing in at all.
- Blocking Stripe's cookies may make a payment fail its fraud check.
- Clearing the app's storage resets the form to its defaults and empties Recent on this device. A subscriber's stored jobs can still be downloaded from Recent on any device while they are kept.
Changes to this page
If a cookie or a storage item is added, removed or changes purpose, this page changes and the date at the top moves with it.
Claypath is a sole proprietorship trading as Claypath, established in California, United States. Questions about this page go to support@clay-path.com.
Withdraw from contract Claypath 0.1.10