Cookies used by htmldrop
We use the smallest set of cookies the Service can sensibly run on. Everything below is either strictly necessary for the Service to work (sessions, anti-CSRF, abuse cookies) or first-party analytics with no cross-site tracking. We don't run third-party advertising cookies and we don't sell or share data with ad networks. Under UK GDPR and PECR, the cookies below don't require a consent banner because they're either necessary or are strictly first-party measurement on aggregate.
Privacy details are in the full Privacy Policy; this page is the technical inventory.
1. Marketing site (htmldrop.app)
| Name | Purpose | Lifetime | Category |
|---|---|---|---|
ph_*PostHog |
Aggregate page-view + session-replay analytics. Stored in PostHog Cloud EU; not shared with third parties. | 1 year | First-party analytics |
_ga, _ga_*Google Analytics 4 |
Aggregate visitor + session analytics. Set only after you click Accept on our cookie banner; Consent Mode v2 defaults to denied otherwise. No advertising data flows to Google. | 2 years | Third-party analytics (opt-in) |
htmldrop_consent_v1 |
Stores your accept/reject choice from the cookie banner so we don't ask again. localStorage, not a cookie technically — but listed here for transparency. | Until cleared | Strictly necessary |
2. Anonymous drops
| Name | Purpose | Lifetime | Category |
|---|---|---|---|
htmldrop_anon |
Signed cookie binding subsequent anonymous uploads from your browser to a per-visitor tenant. Lets the marketing dropzone show you your past drops without an account. | 7 days | Strictly necessary |
cf_chl_*Cloudflare Turnstile |
Bot-check token. Set by Cloudflare's Turnstile widget when the dropzone is rendered; verified server-side before an anonymous upload is accepted. | 30 minutes | Strictly necessary |
3. Signed-in dashboard (htmldrop.app/dashboard)
| Name | Purpose | Lifetime | Category |
|---|---|---|---|
hs_session |
Signed JWT identifying your account. Issued at sign-in;
required for every authenticated request. HttpOnly,
Secure, SameSite=Lax. |
30 days (rolling) | Strictly necessary |
ph_*PostHog |
Same as the marketing-site row above — first-party feature analytics. Bound to your account ID so we can look at usage by plan, not individual sessions. | 1 year | First-party analytics |
4. Password-protected drops
| Name | Purpose | Lifetime | Category |
|---|---|---|---|
hs_s_<id> |
Signed cookie remembering you've entered the correct password for a specific drop. One per drop you've unlocked; bound to the drop's host so it can't be replayed to others. | 24 hours | Strictly necessary |
5. Turning analytics off
Send a Global Privacy Control signal (most modern browsers + the
Brave/Firefox built-in toggle) and PostHog honours it — no ph_*
cookies are set. You can also block eu.i.posthog.com in
your browser's content-blocker; the rest of the site keeps working.
Strictly-necessary cookies can't be disabled without breaking core flows (you wouldn't be able to sign in, or your anonymous drops would disappear on every page reload). If you'd rather not have them, don't use the relevant feature — anonymous drops without the cookie still work for a single upload, just not the "see my past drops" list.
6. Changes
If we add a new cookie, this page changes before the cookie ships. The effective date at the top is the source of truth.
7. Contact
Middle East Software Solutions Limited
Privacy: [email protected]