Cookie Policy

Last updated: 5 September 2026 · Consent version 1

Zerpd uses cookies and similar browser storage to provide the service and, only with your permission, for optional product analytics and preferences. The same choices apply globally, to visitors and signed-in users. Authentication, security, requested work recovery and checkout remain available when you reject optional technologies.

Analytics is off until you choose it. With consent, selected conversion events are sent to Zerpd’s /api/conversion endpoint and added to daily totals by event and broad source. The aggregate table has no visitor, account, project, IP address or referrer fields. Tab storage remembers only the broad source and boolean milestone markers. These are removed when analytics consent ends. Aggregate totals are retained for product comparison, without a browsing history or a link to your identity. No external analytics SDK, advertising pixel, session replay or affiliate tracker is installed. Marketing is not enabled by Accept all. External players have separate permission. Theme and analysis choices work on the current page without permission to remember them.

Use at any time to reject optional technologies or change individual choices. We remember the consent version, time, categories and whether you chose from the banner or preferences for 180 days. We do not attach an account ID, IP address or location to that preference record. Material changes to purposes or vendors require a consent-version review and renewed consent where required.

Withdrawal stops future optional events and removes the optional Zerpd storage listed below. Authentication cookies and requested-work drafts are preserved. Browser restrictions can prevent saving a choice; in that case optional tracking stays off and we show an explanation. Expired or invalid choices require a new decision. Global Privacy Control and Do Not Track signals keep analytics and marketing off; this is Zerpd's global product policy.

Zerpd cookies and browser storage

Names below use HTTPS production prefixes. Local HTTP development omits __Secure- and __Host-. Browser session storage may survive a browser's session-restore feature. Optional storage is also removed when Zerpd detects expiry or withdrawal.

zerpd:conversion:source (sessionStorage)

Provider / party
Zerpd · First party
Category
Analytics
Purpose
Remembers only an allowlisted source: TikTok, Instagram, YouTube, outreach or direct/other. No full UTM strings or referrer URLs.
Duration
Tab session, or earlier withdrawal/consent expiry
When set
A consented funnel event occurs on a page with utm_source.

zerpd:conversion:first_ai_project_created / first_candidate_ready / checkout_completed (sessionStorage)

Provider / party
Zerpd · First party
Category
Analytics
Purpose
Boolean markers avoid repeating an observed funnel milestone in one tab. No account or project ID.
Duration
Tab session, or earlier withdrawal/consent expiry
When set
The corresponding milestone occurs with analytics consent.

revenue-gmail-oauth-state

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Protects an administrator-requested Gmail connection against forged callbacks.
Duration
Up to 10 minutes
When set
An administrator starts connecting Gmail; scoped to /api/admin/revenue/gmail.

zerpd_cookie_consent

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Remembers consent version, time, choices and choice source.
Duration
180 days
When set
When you save a banner or preference choice.

__Secure-authjs.session-token (including numbered chunks)

Provider / party
Auth.js / Zerpd · First party
Category
Strictly necessary
Purpose
Keeps your authenticated session.
Duration
30 days; renewed during session use
When set
Successful sign-in and session refresh.

__Host-authjs.csrf-token

Provider / party
Auth.js / Zerpd · First party
Category
Strictly necessary
Purpose
Protects authentication requests against forgery.
Duration
Browser session
When set
Auth.js middleware initializes authentication security state, including on the first anonymous page response.

__Secure-authjs.callback-url

Provider / party
Auth.js / Zerpd · First party
Category
Strictly necessary
Purpose
Returns you to the requested page after authentication.
Duration
Browser session
When set
Auth.js middleware initializes redirect state, including on the first anonymous page response, and during authentication redirect handling.

__Secure-authjs.pkce.code_verifier; __Secure-authjs.state

Provider / party
Auth.js / Zerpd · First party
Category
Strictly necessary
Purpose
Secures OAuth sign-in with Google or Discord where the corresponding check applies.
Duration
Up to 15 minutes; cleared after use
When set
Starting OAuth sign-in.

zerpd_youtube_oauth_state; zerpd_youtube_oauth_user; zerpd_youtube_reconnect_account; zerpd_youtube_code_verifier

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Binds a requested youtube account connection to its initiating user and protects the callback.
Duration
Up to 10 minutes; cleared on callback
When set
You start a social-account connection; reconnect marker only for reconnections.

zerpd_instagram_oauth_state; zerpd_instagram_oauth_user; zerpd_instagram_reconnect_account

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Binds a requested instagram account connection to its initiating user and protects the callback.
Duration
Up to 10 minutes; cleared on callback
When set
You start a social-account connection; reconnect marker only for reconnections.

zerpd_tiktok_oauth_state; zerpd_tiktok_oauth_user; zerpd_tiktok_reconnect_account

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Binds a requested tiktok account connection to its initiating user and protects the callback.
Duration
Up to 10 minutes; cleared on callback
When set
You start a social-account connection; reconnect marker only for reconnections.

zerpd_facebook_oauth_state; zerpd_facebook_oauth_user; zerpd_facebook_reconnect_account

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Binds a requested facebook account connection to its initiating user and protects the callback.
Duration
Up to 10 minutes; cleared on callback
When set
You start a social-account connection; reconnect marker only for reconnections.

zerpd:campaign-draft-recovery:<campaignId> (localStorage)

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Recovers unsaved campaign editing work after a save or connection failure.
Duration
Until recovery is saved/cleared, or you clear site storage; no automatic browser expiry
When set
Campaign editing recovery workflow.

zerpd-direct-request:<creator>:<service>:step / :draft (localStorage)

Provider / party
Zerpd · First party
Category
Strictly necessary
Purpose
Saves progress and entered work in the direct-request form.
Duration
Until you clear site storage; no automatic browser expiry
When set
Using the request form or saving a draft.

zerpd:campaign-join-completed:<campaignId>:<joinedAt> (sessionStorage)

Provider / party
Zerpd · First party
Category
Analytics
Purpose
Avoids repeating an optional campaign-join analytics event in the same tab.
Duration
Tab session, or earlier withdrawal/consent expiry
When set
Viewing a joined campaign with analytics permission.

dataLayer (page memory, not a cookie)

Provider / party
Zerpd · First party
Category
Analytics
Purpose
Holds up to 100 consented product interaction events; no external analytics SDK is installed.
Duration
Page lifetime, or earlier withdrawal/consent expiry
When set
Product interactions after analytics permission; earlier events are discarded.

zerpd-theme (localStorage)

Provider / party
Zerpd · First party
Category
Preferences
Purpose
Remembers light, dark or system theme.
Duration
Until cleared or preference consent ends (up to 180 days per choice)
When set
Theme updates with preference permission.

zerpd-landing-audience (sessionStorage)

Provider / party
Zerpd · First party
Category
Preferences
Purpose
Remembers the brands/clippers landing-page choice.
Duration
Tab session, or earlier withdrawal/consent expiry
When set
Changing the landing audience with preference permission.

zerpd.creator-search.recents.v1 (localStorage)

Provider / party
Zerpd · First party
Category
Preferences
Purpose
Remembers up to five recent creator searches.
Duration
Until cleared or preference consent ends (up to 180 days per choice)
When set
Searching with preference permission.

zerpd-source-analysis-mode; zerpd-auto-analysis-depth (localStorage)

Provider / party
Zerpd · First party
Category
Preferences
Purpose
Remembers requested source analysis mode and depth.
Duration
Until cleared or preference consent ends (up to 180 days per choice)
When set
Choosing analysis settings with preference permission.

Observed external player storage

The following items were observed on authenticated Zerpd source pages in isolated Chromium sessions on 5 September 2026, after explicit player permission. None appeared before loading a player. No YouTube cookies were set or sent in those player tests, but YouTube used the other storage listed here. Provider versions, location and browser settings can change names and behavior. These are optional external-media technologies, not essential Zerpd authentication storage.

yt-icons-last-purged (localStorage)

Provider / party
Google / www.youtube-nocookie.com · Third party
Category
Optional external media — separate player permission
Purpose
Tracks maintenance of the player's icon cache.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load YouTube; caption and bandwidth entries appeared during playback.

ytidb::LAST_RESULT_ENTRY_KEY (localStorage)

Provider / party
Google / www.youtube-nocookie.com · Third party
Category
Optional external media — separate player permission
Purpose
Records player storage capability/metadata state.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load YouTube; caption and bandwidth entries appeared during playback.

yt-player-caption-persistence (localStorage)

Provider / party
Google / www.youtube-nocookie.com · Third party
Category
Optional external media — separate player permission
Purpose
Remembers the player's caption setting.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load YouTube; caption and bandwidth entries appeared during playback.

yt-player-bandwidth (localStorage)

Provider / party
Google / www.youtube-nocookie.com · Third party
Category
Optional external media — separate player permission
Purpose
Stores a bandwidth estimate used for playback quality.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load YouTube; caption and bandwidth entries appeared during playback.

YtIdbMeta (IndexedDB database)

Provider / party
Google / www.youtube-nocookie.com · Third party
Category
Optional external media — separate player permission
Purpose
Holds metadata for the player's browser database use.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load YouTube; caption and bandwidth entries appeared during playback.

yt-icons (Cache Storage)

Provider / party
Google / www.youtube-nocookie.com · Third party
Category
Optional external media — separate player permission
Purpose
Caches YouTube player icons.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load YouTube; caption and bandwidth entries appeared during playback.

server_session_id

Provider / party
Twitch / .twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Identifies the Twitch player session.
Duration
Browser session
When set
After Allow and load Twitch, before pressing Play.

unique_id

Provider / party
Twitch / .twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Recognizes a browser/device within Twitch services.
Duration
13 months observed
When set
After Allow and load Twitch, before pressing Play.

unique_id_durable

Provider / party
Twitch / .twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Maintains a durable Twitch browser/device identifier.
Duration
13 months observed
When set
After Allow and load Twitch, before pressing Play.

referrer_url

Provider / party
Twitch / .twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Records the page referring the viewer to the player.
Duration
30 minutes observed
When set
After Allow and load Twitch, before pressing Play.

experiment_overrides

Provider / party
Twitch / .twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Stores Twitch feature/experiment override state.
Duration
13 months observed
When set
After Allow and load Twitch, before pressing Play.

api_token

Provider / party
Twitch / .twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Supports Twitch API security; it is not a Zerpd login token.
Duration
13 months observed
When set
After Allow and load Twitch, before pressing Play.

KP_UIDz-ssn

Provider / party
Twitch protection endpoint / k.twitchcdn.net · Third party
Category
Optional external media — separate player permission
Purpose
Supports the player's integrity/security checks.
Duration
24 hours (Max-Age=86400)
When set
After Allow and load Twitch. Also offered by gql.twitch.tv; only the k.twitchcdn.net cookie was retained in the audited browser.

KP_UIDz (Set-Cookie attempt; not retained)

Provider / party
Twitch protection endpoints / k.twitchcdn.net and gql.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Additional state offered by the player's integrity/security endpoints.
Duration
24 hours offered by the response; not present in the audited cookie jar
When set
Response headers after Allow and load Twitch; listed as an observed attempt, not a stored cookie.

local_storage_device_id (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Identifies the device/browser to the player.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

local_storage_app_session_id (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Identifies the player application session.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

local_copy_unique_id (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Keeps a local copy of Twitch's browser identifier.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

sentry_device_id (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Identifies the device for the provider's diagnostic tooling.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

amazon_ivs_device_config_v1_player-web-v1_state (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Maintains Amazon IVS player device-configuration state.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

amazon_ivs_device_config_v1_player-web-v1_data (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Caches Amazon IVS player device-configuration data.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

_amazon_ivs_dc_player-web-v1_b8e4f7c1 (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Stores version-specific Amazon IVS player configuration state.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

CV7o9fRC/gx24wn2 (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Opaque Twitch player state; its detailed internal purpose is not publicly specified.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

CV7o9fRC/gx24wn2-rc (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Opaque Twitch player state; its detailed internal purpose is not publicly specified.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
After Allow and load Twitch.

vodResumeTimes (localStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Remembers the playback position of a Twitch VOD.
Duration
No browser-enforced expiry; the provider may reset or expire its own state. Clearing provider site data removes it.
When set
During playback after Allow and load Twitch.

session_storage_last_visited_twitch_url (sessionStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Remembers the last Twitch location used by the player.
Duration
Tab session; provider/browser lifecycle and session restore may affect retention
When set
After Allow and load Twitch.

session_storage_unique_id (sessionStorage)

Provider / party
Twitch / player.twitch.tv · Third party
Category
Optional external media — separate player permission
Purpose
Identifies the player session in this tab.
Duration
Tab session; provider/browser lifecycle and session restore may affect retention
When set
After Allow and load Twitch.

External services and media

Player permission is separate from Zerpd analytics, marketing and preference choices. Accept all does not load either player. Even after Reject non-essential, you can choose to load one player with its disclosed provider processing. This grants permission only while that player is open; it does not change your saved Zerpd categories. Both providers may use device identifiers, security checks, usage measurement and advertising. Saving changed cookie preferences or Stop and unload removes the player and stops future requests, but cannot erase provider cookies or storage already created. You can clear provider site data through your browser.

In the audit, YouTube contacted youtube-nocookie.com for player code, playback APIs and measurement; googlevideo.com for video; ytimg.com and ggpht.com for images; gstatic.com for fonts/icons; and google.com and jnn-pa.googleapis.com for provider scripts/integrity requests. Twitch contacted player.twitch.tv and assets.twitch.tv for its player, configuration and experiments; gql.twitch.tv and k.twitchcdn.net for API/integrity checks; spade.twitch.tv, live-video.net and reporting.cdndex.io for player telemetry; ttvnw.net and CloudFront for video delivery; jtvnw.net for images; gstatic.com for casting support; and s.amazon-adsystem.com for advertising-related requests. The Amazon endpoint sent/set no cookies in these tests. A request without cookies can still transmit connection or device data.

YouTube campaign-reference and Creator Search players use youtube-nocookie.com; Twitch uses its official player. Both remain unloaded until you choose “Allow and load YouTube / Twitch” for that player. Opening a reference or source page alone does not load either provider. Permission is held only in page memory while the player is open. “Stop and unload”, closing the reference, or changing cookie preferences unloads it. You can instead follow the link to the original platform.

Privacy-enhanced mode limits personalisation; it does not promise that Google receives no information or uses no browser storage. After loading, Google receives connection and playback data and may use its own storage, with names and lifetimes controlled by Google and dependent on the player and your browser. Zerpd cannot read or delete cross-origin Google storage. See YouTube's player explanation and Google's privacy policy. Twitch does not offer a no-cookie mode in this integration; its player may use provider-managed storage after permission. Names and lifetimes depend on the provider and browser. See the Twitch cookie notice. No social pixel is installed.

Stripe checkout opens on Stripe after you request a payment flow; Stripe.js is not globally loaded by Zerpd. Stripe documents __stripe_mid (fraud prevention, one year) and __stripe_sid (fraud prevention, 30 minutes) on its checkout surfaces. These are provider-managed cookies on the external checkout, not optional Zerpd analytics. Other checkout storage depends on payment methods and Stripe settings. See Stripe's cookie details.

Google and Discord sign-in and social-account connections contact their providers when requested. Social images and requested media can disclose connection information to their host. Zerpd-hosted media delivery, server security logs, campaign verification, account reporting and AI jobs serve requested functionality; the optional analytics switch does not disable those services. Content fingerprints used for deduplication are not browser fingerprints.

For personal-data processing and your rights, read our Privacy Policy. Contact hello@zerpd.com about this inventory.

Cookie PolicyPrivacy Policy

Cookie Policy | Zerpd