Cookie Policy
Last updated: 2026-09-29
1. What Are Cookies
Cookies are small text files stored in your browser. We use cookies and similar technologies to provide site functionality and understand usage patterns.
2. Types of Cookies We Use
Essential Cookies: Better Auth session cookies (for authentication) and CSRF tokens. These are required for the Service to function. On landing pages served by Convika, `_cvk_consent_essential=1` is always set.
Analytics Cookies: On landing pages served by Convika, `_cvk_consent_analytics` keeps the visitor's choice for 1 year: 1 for Allow analytics cookies, 0 for Decline analytics cookies. With 1, Convika sets `_cvk_vid` (a random visitor ID, 90 days) and `_cvk_sid` (a random session ID, 30 minutes) as soon as the visitor chooses. It may also set `_cvk_variant`, which records the version of a page a visitor sees in an A/B test until the browser closes; A/B tests aren't in use today. With 0, it deletes these cookies if they were set before.
Without analytics consent, Convika sets no visitor or session cookie and stores nothing in the browser beyond the choice itself. Page views, button clicks, and form submissions are still counted, under a visitor ID computed from the site, IP address, and User-Agent with a key for each UTC day, which is deleted 2 days after its day begins. Section 1 of the Privacy Policy explains this ID.
Where analytics events are stored: Each page view, button click, and form submission is its own row, with the page path, referrer, UTM parameters, device type, country, User-Agent, and visitor ID. These rows go to Cloudflare Workers Analytics Engine, which keeps them for 3 months, and to a raw event archive in Cloudflare R2, which keeps them for 400 days. The archive also holds the scroll, time-on-page, and load-speed events. Button click and form submission events also go to Tinybird, without the User-Agent, and are deleted there after 400 days. None of these rows include the IP address.
convika.com and the dashboard: The banner on convika.com and on the dashboard (app.convika.com) saves your choice in your browser's local storage (`convika_cookie_consent`). If you accept, your browser also keeps a random visitor ID in local storage (`cvk_self_analytics_vid`) until you decline or clear the site's data, and sends it with each page view. On the dashboard's sign-up and log-in pages, accepting also keeps the link that brought you there (its UTM parameters and referrer) in local storage (`convika_attr_pending`) until you sign in, for up to 90 days. If you decline, or haven't chosen yet, Convika keeps no ID or link in your browser, and deletes any saved earlier without sending them. Your page views still count, under an ID computed from the host name, IP address, and User-Agent with a key for each UTC day, which is deleted 2 days after its day begins. Page views go to Convika's database (Cloudflare D1) as daily counts by page, referring site, UTM parameters, device type, and country, and these counts are kept. To count unique visitors, the database also keeps rows that pair a one-way hash of each visitor ID with the pages and sources it was counted under that day. Convika deletes these rows 2 days after their day. It stores neither the IP address nor the User-Agent.
Functional Cookies: Locale preference (ja/en). The free rebuild tool on convika.com keeps the id and start time of your latest rebuild in local storage (`convika.rebuildTool.lastRun`), so reopening the page shows its result. It is removed when that rebuild ends without a preview, when you start another one, or 7 days after it started. When a rebuild stops because of a problem on Convika's side, the tool also keeps that page's address and the rebuild's id in session storage (`convika.rebuildTool.failedRuns`), so after a second stop in a row it suggests another page instead of the same one. The address is removed when a rebuild of that page ends any other way, and session storage is cleared when you close the tab.
Attribution cookie: `convika_attr` (first-party, shared with the dashboard). Only after you accept cookies in the banner on convika.com, it stores the UTM parameters and referrer of your first visit for up to 90 days, so a signup can be traced to the campaign or link that brought it. Declining deletes it.
3. Third-Party Cookies
Stripe: During the payment flow, Stripe may set cookies for fraud detection purposes.
Cloudflare may set strictly necessary cookies for security and traffic management on Convika-hosted infrastructure.
4. Managing Cookies
You can delete or block cookies through your browser settings. Please note that disabling essential cookies may prevent the Service from functioning properly.
5. Consent and Withdrawal
On landing pages served by Convika, a banner asks each visitor whether to allow analytics cookies. Choosing Decline analytics cookies turns off the analytics cookies, not the counting: views, clicks, and submissions are still counted under the daily visitor ID described in section 2. To change your choice, delete the `_cvk_consent_*` cookies in your browser, and the banner appears again on your next visit.
On convika.com and the dashboard, the banner asks whether you accept cookies. Declining deletes the stored visitor ID and the `convika_attr` cookie, and on the dashboard `convika_attr_pending` too, but page views are still counted under the daily ID described in section 2. To change your choice, use Cookie settings at the bottom of any page on convika.com, or the Cookies section in the dashboard's Settings.
