Cookie Policy
Last updated: October 3, 2026
This policy explains the cookies and similar technologies InputTrail uses, why, and how you control them. InputTrail is built to be light on cookies: it sets only a few strictly necessary first-party cookies of its own and no advertising or cross-site tracking cookies at all. If you turn on the optional functional category, your account page loads Paddle's script, which leads to a cookie of Paddle's own on Paddle's domain, and Paddle and Stripe both store more inside the checkout; sections 4 and 5 cover that in full. Opening a video loads YouTube's video player, and YouTube and Google can store cookies of their own on their own domains when it does; section 5 covers that too.
1. What cookies and similar technologies are
A cookie is a small text file a website stores on your device. Similar technologies, such as your browser's local storage, session storage, and IndexedDB, also store or read information on your device. The rules that require us to inform you and, for anything that is not strictly necessary, to ask for your consent apply to all of these, not only to cookies. This policy uses "cookies" to cover cookies and these similar technologies together, and calls out the specific technology where it matters.
2. How we ask for your consent
The cookies InputTrail sets itself are all strictly necessary, so they do not require your consent. We show a consent banner on your first visit. It has a necessary category, which is always on because the service cannot work without it, and two optional categories, functional and performance, each off until you turn it on. Nothing in either optional category is pre-selected: "Choose cookies" on the banner lets you turn on one without the other, and declining both is as easy as accepting both. The functional category covers loading Paddle's script on your account page before you press Subscribe there; that script leads to a cookie of Paddle's own on its own domain (sections 4 and 5). Pressing Subscribe opens the checkout, and inside the checkout, Paddle's script and what Paddle and Stripe store there are strictly necessary for the payment you asked for, so the banner does not cover those; section 5 says when they arrive, what they are for, how long the one we can document lasts, where to find the rest, and why the two places are treated differently. Nor does the banner cover what YouTube and Google can store when the watch page loads YouTube's video player; section 5 explains why. You can reopen the banner at any time using "Cookie settings" in the footer.
3. Strictly necessary cookies
These cookies are needed to deliver features you ask for, such as staying signed in and remembering your preferences. They are set without consent because the service cannot work without them. All of them are first-party cookies (set by InputTrail, not a third party).
| Cookie | Purpose | Duration |
|---|---|---|
| ci-tracker-theme | Remembers your light or dark theme choice | 12 months |
| __Host-ci-tracker-session | Keeps you signed in after you log in (set only if you create an account) | 14 days, renewed automatically while you keep using the app |
| ci-tracker-consent | Remembers your cookie choices so we do not ask again | 6 months |
In production these cookies are sent only over HTTPS and limited with SameSite=Lax, and the session cookie is also HttpOnly so it cannot be read by scripts. This list can change as the product changes; we keep it current and bump the "Last updated" date when it does.
4. Functional and performance cookies
Both of these categories are optional. Each stays off until you turn it on, and you can turn on one without the other, or change your mind later (section 6).
Functional. Functional cookies make a feature you use work better without being needed for the service to work. The functional category covers one thing today: on your account page, while you have no subscription, it lets your browser load Paddle's script so that Paddle can show you our price in your local currency, including the tax that applies where you are. Loading that script sends your IP address and browser information to Paddle and leads to a cookie on Paddle's own domain, described in section 5. If you leave the functional category off, you still see the list price we show you ourselves.
Performance. Performance cookies would help us understand how the app is used so we can improve it. We set no performance cookies today. The optional performance category does cover one similar technology: the Sentry diagnostic session replay described in section 5, which uses session storage rather than a cookie and stays off until you turn the category on. If we add performance cookies later, they will sit in this same category, off until you turn them on, and we will update this policy and ask for your consent before using them.
5. Similar technologies, and the cookies others set
Besides cookies, InputTrail uses a few storage and diagnostic technologies:
- On-device statistics (IndexedDB). If you use InputTrail without an account, your hours and progress are stored in your browser using an IndexedDB database named "ci-tracker". This stays on your device, is needed for the anonymous tracking you asked for, and is not sent to us unless you sign in and sync. Clearing your browser storage removes it, and your browser can also delete it on its own, as the next bullet describes.
- Your account, kept on this device (IndexedDB). If you have an account, the same "ci-tracker" database keeps a copy of it: the time you have watched, which videos you have marked, the days of input you logged yourself, the single baseline figure you reported for input from before you started tracking, and your daily goal, along with anything recorded here that has not reached us yet. That is what lets the app show your real hours without asking our servers on every screen, and keep counting when it cannot reach the network. It is your own data, it stays on your device, and it is not sent anywhere else. Signing out removes the copy of your account. Anything recorded here while you were signed in that has not reached us yet is kept when you sign out, so that it is not lost: it goes to your account the next time you sign in on this device, and we do not make it available to anyone else signing in on this browser. If you never sign in again, it stays until you clear your browser storage, which removes all of it. Your browser can also delete it on its own: private browsing data is usually deleted when the private session ends, a browser can delete it when the device runs low on storage, and Safari, with its default settings, deletes it after seven days of Safari use without any interaction with InputTrail.
- Staying signed in (IndexedDB or local storage). If you have an account, the Firebase authentication library stores a sign-in credential in your browser, using IndexedDB where it is available and your browser's local storage otherwise. It is what keeps you signed in: the app uses it to renew your session cookie automatically while you keep using InputTrail, and to restore your session if that cookie runs out while you are away, so you are not asked to sign in again. It is strictly necessary for the account you asked for, it stays on your device, and it does not expire on its own, though your browser can also delete it on its own, as the previous bullet describes. Signing out removes it, and so does clearing your browser storage.
- Error monitoring and diagnostics (Sentry). We use Sentry to detect and diagnose faults so we can keep the service working and secure. If you turn on the optional performance category, Sentry may also record a diagnostic replay of a session when an error occurs, with text and media masked, using your browser's session storage (not a cookie) to link that replay. Without that consent no replay runs and nothing is stored for it. This data is processed by Sentry in the European Union and is used only for reliability and security, not for advertising or profiling. The session storage is cleared when you close the browser tab.
- Cookieless analytics (Vercel). We measure aggregate, anonymized usage and performance through Vercel, such as page views, videos started and finished, and page-load speed. This is cookieless: it sets no cookies and stores no identifier on your device.
- App caching (service worker). InputTrail is a Progressive Web App, so a service worker caches static files (such as scripts and styles) to load faster and work offline. It also stores one page, an offline fallback shown when your device cannot reach the network, so the app still opens. That page is fetched without your cookies, so it holds no personal data, and no other page is ever stored.
Payments run through Paddle, our Merchant of Record, and Paddle uses payment processors of its own, including Stripe for card payments. Paddle's script loads on the pages where a subscription is started or completed: your account page while you have no subscription, and the checkout page. On your account page we show you our list price with no request from your browser to Paddle, and the script loads there only if you have turned on the functional category (as soon as you do, including from the banner while you are on that page), or when you press Subscribe, which opens the checkout you asked for. With the functional category on, the script replaces the list price with the price in your local currency, including the tax that applies where you are, but only when Paddle answers with a price we can display; otherwise the list price, or the last price we published if our own price lookup failed, simply stays. On the checkout page it loads as soon as you arrive, because that page is the checkout itself.
When that script loads, a cookie is set on Paddle's own domain. It comes from Cloudflare, it tells a real visitor apart from an automated one, and Cloudflare documents it as expiring after 30 minutes without further activity from you. When the checkout opens, Paddle and Stripe both store more under their own domains: cookies, and browser storage as well. The checkout can open on either page, because pressing Subscribe on your account page opens it in a layer over that page rather than sending you anywhere. That storage is what holds your payment session together while you pay and what helps prevent fraud. None of it is ours. The cookies listed in section 3 are the only ones InputTrail sets, we set nothing at all for payments, and we cannot read what Paddle and Stripe store. How long the rest lasts is theirs to set, and their notices are the current source. See Paddle's privacy notice, Stripe's cookies policy, and Cloudflare's cookie documentation.
Section 3's strictly necessary list covers only the cookies InputTrail sets, so it does not answer for these, and the answer depends on where the script loads. Inside the checkout they are strictly necessary: there is no paying without a payment session, and a payment page that cannot tell a customer from an automated attack is not one we could offer. On your account page, on arrival, that reasoning does not carry. The list price you see first comes from our own server, and what the script adds is the total in your own currency with the tax that applies where you live, which is a better number to read but not a necessary one. So there we ask first, through the functional category. The cookie from Cloudflare is the kind of cookie that is often classed as strictly necessary for security, and we do not rely on that for your account page, because it only arrives there as a result of a script we load for an optional purpose. Separately from your choices on our banner, a browser that blocks third-party cookies stops most of that storage (that is your browser's setting for third-party cookies; section 6 has the general instructions), though the script is still fetched and your IP address still reaches Paddle whenever it loads. Blocking them may also stop the checkout itself from working, since the payment session depends on that storage. The rest of InputTrail works whether or not you visit your account page.
InputTrail also embeds YouTube's video player. It loads on the watch page, where it plays the video you chose, and thumbnail images load directly from YouTube wherever videos are shown, such as the app's home page, the browse pages, and the watch page's queue. Loading either connects your browser to YouTube and Google.
When the player loads, YouTube and Google can store or read cookies and similar technologies on your device, under their own domains. We show the video in YouTube's privacy-enhanced mode, from youtube-nocookie.com, but that does not prevent this: the script that starts the player is fetched from youtube.com, and YouTube can set cookies on youtube.com as soon as that script loads, whether or not the video plays. YouTube and Google use what they store under their own policies. We cannot read it, and how long it lasts is theirs to set. We treat it as strictly necessary for playing the video you chose to open: the video can only play in YouTube's player, and we cannot load that player without YouTube and Google being able to store what they choose. That is the same position the paragraphs above take for the checkout's storage. See the Google Privacy Policy and how Google uses cookies.
6. Managing your choices
You can change or withdraw your consent at any time. Doing so is as easy as giving consent in the first place. Withdrawing consent does not affect the lawfulness of anything we did based on your consent before you withdrew it. Use "Cookie settings" in the footer to reopen the banner.
You can also control cookies and site storage through your browser settings, including blocking or deleting cookies and clearing site data. Blocking strictly necessary cookies may stop parts of InputTrail from working, for example keeping you signed in. Most browsers explain how to do this in their help pages.
To sign out, please use the "Sign out" button rather than deleting cookies. Your sign-in credential is kept in your browser's storage (see section 5), not in the session cookie alone, so deleting the cookie on its own can leave you signed in: the app treats the missing cookie as one that ran out and restores your session. Signing out clears both, and clearing all site data for InputTrail does too.
Some browsers send a "Do Not Track" or Global Privacy Control (GPC) signal. Because we do not use advertising or cross-site tracking cookies of our own and do not sell or share your information ourselves, there is no such tracking of ours for these signals to stop. How YouTube and Google respond to these signals when the video player loads is up to them (section 5). We treat a GPC signal as a valid opt-out preference where it applies.
7. US privacy choices
For users in the United States: we do not use advertising, targeting, or cross-context behavioral advertising cookies of our own, and we do not sell or share personal information as those terms are used under the California Consumer Privacy Act and similar state laws. There is therefore no sale or sharing of ours to opt out of. That covers InputTrail's own processing only; it says nothing about what YouTube and Google do with what they receive or store when the video player or a thumbnail loads, which section 5 of this policy and section 6 of our Privacy Policy cover. We recognize the Global Privacy Control signal as an opt-out preference to the extent it would apply. Your broader privacy rights are described in our Privacy Policy.
8. Personal data and our Privacy Policy
Where the information stored or read through these technologies is personal data, we process it as described in our Privacy Policy, which explains your rights and how to exercise them.
9. Changes to this policy
We may update this policy as the product or the law changes. The "Last updated" date at the top reflects the most recent change. If we add cookies or similar technologies that need your consent, we will ask for it before using them.
10. Complaints and supervisory authorities
If you think our use of cookies or similar technologies does not respect your rights, please contact us first at hello@inputtrail.com so we can help. You also have the right to complain to a supervisory authority. In Sweden, the authority for the cookie-consent rule is the Swedish Post and Telecom Authority (Post- och telestyrelsen, PTS) at pts.se, and the authority for data protection is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se. If you are in another EU or EEA country, you can complain to your national data protection authority; you can find it through the European Data Protection Board directory. If you are in the United Kingdom, you can complain to the Information Commissioner's Office. If you are in California, you can contact the California Privacy Protection Agency.
11. Contact us
Mawal AB, Hallandsgatan 38, 118 57 Stockholm, Sweden. Email: hello@inputtrail.com. See also our Privacy Policy.