This Cookie Policy explains how Everpop, operated by Very - Fast Ltd., uses cookies and similar technologies (together, "cookies") on everpop.app. It should be read together with our Privacy Policy.
1. What cookies we use
We keep cookies to a minimum. Strictly necessary cookies (to keep you signed in and to remember your cookie choice) are always active and cannot be switched off, because the Service cannot function without them. Non-essential support chat, marketing attribution, and client-side product analytics each load or run only when you enable that specific purpose. You can enable one without enabling the others. Server-side operational events may still be recorded where needed to provide and secure the Service.
| Cookie / tracker | Category | Provider | Purpose | Duration |
|---|---|---|---|---|
| Session / authentication | Strictly necessary | Everpop (first-party) | Keeps you securely signed in. Set only when you log in. | Session / up to 30 days |
| everpop_consent (consent record) | Strictly necessary | Everpop (first-party) | Stores your separate support-chat, analytics, and marketing-attribution choices, decision time, and the policy/vendor-set version in your browser's local storage. An older grant is not reused after that version changes. | Until you change it or the policy/vendor set changes |
| everpop_anon (local storage) | Analytics | Everpop (first-party) | When product analytics is enabled, a random browser identifier links pre-signup funnel events without using your name or email. Deleted when you disable analytics. | Until analytics withdrawal or browser deletion |
| ep_attr | Marketing attribution | Everpop (first-party) | Carries campaign/referrer attribution across a Google signup redirect. Written only when you enable marketing attribution and deleted when you disable it. | 30 minutes |
| Product-analytics events | Analytics | Everpop / PostHog (when configured) | When product analytics is enabled, sends bounded funnel event names and properties through Everpop's own endpoint, using the random everpop_anon identifier. It does not add a separate PostHog browser cookie. Server-side service events are described below. | Event record subject to the configured analytics retention; browser identifier lasts until analytics withdrawal or browser deletion |
| crisp-client/* (support chat) | Functional | Crisp | Powers the in-app support chat widget and restores your prior chat history so a new conversation isn't started on every page load. Loads only when you enable support chat. | 6 months (renewed each return visit) |
| Vercel Web Analytics beacon | Analytics | Vercel | When product analytics is enabled, sends page path, filtered query/referrer, timestamp, coarse location, and browser/device metadata for aggregate traffic reporting. Vercel Web Analytics does not use a browser cookie. | No browser cookie; visitor hash resets daily |
| Cloudflare Turnstile challenge | Strictly necessary security | Cloudflare | When anti-bot protection is configured on an account form, runs a browser challenge and sends its short-lived token, IP address, and browser/device signals to Cloudflare for server-side verification. It is not used for advertising or product analytics. | Challenge token expires after 5 minutes; no Everpop analytics cookie |
2. Your choices & withdrawing consent
When you first visit, support chat, product analytics, and marketing attribution are off. You can enable or disable each purpose separately, or reject or accept all. You can change or withdraw any selection at any time — withdrawing is as easy as giving consent. Use the Cookie preferencescontrol (available in your dashboard under Settings → Your data) to re-open the cookie banner and change your selection. If you don't have an account or aren't signed in, use the "Manage cookies" link in the footer of our website pages to re-open the banner and change your selection. Disabling a purpose stops that optional client and clears its removable browser state: the analytics identifier for product analytics, the short-lived attribution cookie for marketing attribution, or the Crisp browser session state for support chat. Other choices remain unchanged.
You can also block or delete cookies through your browser settings, though strictly necessary cookies are required to use the Service.
3. Third-party providers
Crisp (support chat) acts as our processor and sets the cookies described above only when you enable support chat; its processing is also governed by its own policies. Cloudflare Turnstile is a strictly necessary anti-abuse control when configured and therefore does not depend on optional analytics consent. Our other providers, including our product analytics, are listed on our Subprocessors page.
4. Legal basis
We rely on your consent (under the EU ePrivacy rules and the GDPR) for non-essential cookies, and on our legitimate interest in operating a secure, functioning service for strictly necessary cookies.
5. Contact
Questions about cookies? Contact privacy@everpop.app.