Cookie Policy
This Cookie Policy explains what cookies and similar technologies Pilot Protocol ("we", "us") uses on pilotprotocol.network, why we use them, and how you can control them. It supplements our Privacy Policy.
What Are Cookies?
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work, improve efficiency, and provide information to the site owners. "Similar technologies" includes localStorage, session storage, and browser-level storage APIs that serve a similar purpose.
Cookie Inventory
Here is every cookie and browser-storage entry used on pilotprotocol.network, what it does, how long it lasts, and who sets it:
| Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
__cf_bm | Cloudflare | Bot management. Cloudflare may set this to distinguish human visitors from automated bots when bot protection is active on the zone. Does not track users across sites. | 30 minutes | Strictly necessary |
pilot_consent | Pilot Protocol (localStorage) | Stores your cookie consent preference (accepted or rejected). No personal data, no tracking. | Persistent (until cleared) | Strictly necessary |
pilot-theme | Pilot Protocol (localStorage) | Remembers your light/dark theme choice. No personal data, no tracking. | Persistent (until cleared) | Functional |
pilot.publish.draft.v1 | Pilot Protocol (localStorage) | Saves your in-progress app-submission draft on the Publish page so you don't lose it on reload. Set only if you use that form. | Persistent (until cleared) | Functional |
pilot.publish.ui.v1 | Pilot Protocol (localStorage) | Remembers UI state on the Publish page (e.g. which step you're on). Set only if you use that form. | Persistent (until cleared) | Functional |
_ga | Google Analytics | Distinguishes unique users for analytics. Set only after you accept cookies. Contains a randomly generated client identifier. | 2 years | Analytics |
_ga_EEWEKT0GW5 | Google Analytics | Session-level analytics for our GA4 property. Set only after cookie consent. Tracks page views and session state. | 2 years | Analytics |
ph_<project-key>_posthog | PostHog (localStorage) | Product analytics: page views, clicks, heatmaps, and session replay. Written only after you accept cookies. Holds a randomly generated device identifier and session state. We run PostHog with person profiles disabled, so events are not tied to an identified user account. | Persistent (until cleared) | Analytics |
_twclid | X Corp. (first-party, set by the X pixel) | Stores the X click identifier (twclid) so a later action on our site can be attributed to the X ad you clicked. Set only after you accept cookies, and only if you arrived from an X ad carrying that parameter. | Up to 30 days | Advertising |
personalization_id, muc_ads, guest_id | X Corp. (third-party, on .x.com / .twitter.com / .t.co) | Set by X itself when the pixel loads, to recognise your browser for ad measurement and ad personalisation — including across other sites that run X's tag. Set only after you accept cookies. Browsers that block third-party cookies may prevent some or all of these. | Up to 2 years | Advertising |
The X cookies above are set by X Corp., not by us, and the exact names and lifetimes are X's to change. We list what X currently documents; treat it as indicative rather than exhaustive.
Cookieless Analytics
In addition to the cookies above, we use Cloudflare Web Analytics, which is entirely cookieless. It sets no cookies or localStorage and does no client-side fingerprinting or persistent tracking; it reports only aggregated page-view and performance metrics. (As with any web request, the analytics beacon transmits your IP and user-agent to Cloudflare; see Cloudflare's privacy documentation for how they handle it.)
Consent Model
When you first visit pilotprotocol.network, a consent banner appears offering two options:
- Accept — Enables Google Analytics 4 cookies (
_ga,_ga_EEWEKT0GW5), PostHog product analytics (heatmaps and session replay, inputs masked — see below), and the X (Twitter) advertising pixel (see below). Your preference is stored in thepilot_consentlocalStorage entry. - Reject — No analytics or advertising cookies are set; PostHog and the X pixel are never loaded. If Cloudflare bot management is active, its strictly-necessary
__cf_bmcookie may still be set. Your preference is stored inpilot_consent.
The banner does not use a "nag wall" — you can browse the site without interacting with it. If you do not make a choice, no analytics or advertising cookies are set (implied rejection).
How to Change Your Preference
You can change your consent at any time:
- Cookie preferences link — In the site footer (on the main marketing pages), click "Cookie Preferences" to reopen the consent banner. You can also clear the
pilot_consententry (below) to make the banner reappear. - Clear localStorage — Removing
pilot_consentfrom your browser's localStorage will reset your preference, and the banner will reappear on your next visit. - Browser settings — Most browsers allow you to block or delete cookies globally. See your browser's help documentation for instructions.
Product Analytics (PostHog)
We use PostHog for product analytics — page views, click and scroll behaviour, heatmaps, and session replay — so we can see which parts of the site are and aren't working. PostHog is loaded only after you accept cookies; if you reject or never answer the banner, it is never initialised and writes nothing to your browser.
How we've configured it:
- No person profiles. Events are not attached to an identified user; we do not build a profile of you across visits.
- Inputs masked in session replay. Every form input is masked before it leaves your browser, so typed values (including anything you enter on the Publish page) are never recorded. Elements marked
data-privatehave their text masked as well. - localStorage, not cookies. PostHog stores its device identifier in localStorage (see the inventory above), not in a cookie.
- Withdrawable. Reopening the banner via "Cookie Preferences" and choosing Reject stops further collection; clearing your browser's localStorage for this site removes the identifier.
Advertising & Conversion Tracking (X / Twitter)
We advertise Pilot Protocol on X (formerly Twitter). To measure whether those ads work, we run X's universal website tag (pixel ID re3tv), a script loaded from static.ads-twitter.com/uwt.js and operated by X Corp., a third party. This is the first advertising technology on the site — the other tools listed above are analytics only, and this one is different in kind, so it is worth stating plainly.
What it does and what X receives:
- Consent-gated. The tag is loaded only after you accept cookies. If you reject, or never answer the banner, it is never loaded, it contacts X not at all, and none of the X cookies above are set.
- What it sends. Once loaded, it reports page views to X together with the data any web request carries — your IP address, user-agent, the page URL, the referring URL, and a timestamp — plus the cookie identifiers in the inventory above.
- What it's for. Attributing sign-ups and other actions on our site back to an X ad campaign, and letting us build audiences on X (for example, retargeting people who visited this site). X may also use the data for its own ad measurement and personalisation under its own terms.
- What we do not send. We do not pass X your name, email address, phone number, or any hashed identifier you have given us. We run only the base tag; we have not enabled X's server-side conversion API.
- Third-party control. Unlike our analytics, this data sits with X Corp. under X's own retention and processing rules — see the X Privacy Policy. X's own ad-personalisation controls are at x.com/settings/ads_preferences.
- Withdrawable. Reopening the banner via "Cookie Preferences" and choosing Reject stops the tag from loading on subsequent page views. Cookies X has already set are removed by clearing cookies in your browser, or blocked outright by browser settings and tracking protection.
Changes to This Policy
We will post changes to this page and update the "Last updated" date. If we add new cookies or substantially change how we use existing ones, we will re-prompt for consent where required by law.
Contact
Questions about cookies or our use of analytics?
Email: founders@pilotprotocol.network
This policy was drafted for transparency. If you are a legal professional reviewing this document, please direct feedback to founders@pilotprotocol.network.