Legal

Cookie Policy

Last updated: 13 July 2026

This Cookie Policy explains how Easy Content Studio uses cookies, local storage, necessary security verification, and similar browser technologies across the public website and the authenticated application.

Table of contents
  1. 1.What this policy covers
  2. 2.Necessary cookies and storage
  3. 3.Security verification on authentication forms
  4. 4.Analytics cookies
  5. 5.How consent works
  6. 6.How to change preferences
  7. 7.Retention
  8. 8.Contact Us

Easy Content Studio uses both traditional browser cookies and non-cookie storage such as local storage. We use them for core functionality, language preference, consent management, authenticated session handling, required security verification on sensitive forms, and optional analytics.

This policy should be read together with our Privacy Policy. You can update your choices at any time through the action in the public footer or the Cookie Preferences action in the app settings page.

1. What this policy covers

This policy covers cookies, local storage, and similar browser storage used when you visit our marketing pages, legal pages, authentication pages, and the logged-in product experience.

Some storage and browser-side verification is strictly necessary for the service to work and remain protected. Other storage, such as analytics cookies, is optional and only activated after your consent where required by law.

2. Necessary cookies and storage

We use necessary storage so the website and app can function correctly. This may include:

  • cc_cookie - a first-party necessary cookie that stores your CookieConsent preferences for 182 days. It does not require analytics consent.
  • sidebar:state - a browser cookie used in the authenticated app to remember whether the sidebar is expanded or collapsed.
  • ecs_session_hint - stored in local storage to help the public site show the correct signed-in navigation state after a successful login. The authenticated session itself is kept in a secure HttpOnly cookie when cookie auth is enabled.
  • ecs_visitor (or an environment-specific equivalent) - a first-party HttpOnly security cookie used to assign an anonymous visitor identifier for trial abuse prevention and service protection.
  • easycontent.language - stored in local storage to remember your language preference.

These items are used for core functionality, authenticated session handling, interface state, and language selection. They are not used for advertising.

3. Security verification on authentication forms

On sign-in, sign-up, and password reset request pages, we may load Cloudflare Turnstile as a necessary security measure to help distinguish legitimate users from automated abuse.

Turnstile may process browser, device, and network signals such as IP address, user-agent data, browser or TLS fingerprint signals, and the sitekey or origin context. The widget returns a token that our server verifies before allowing the protected action to continue.

In our current setup, Turnstile uses token-based verification by default and we do not expect a Turnstile-specific site cookie to be set for this feature. A cf_clearance cookie would only be expected if we later enable Cloudflare pre-clearance or related challenge features.

For more information about Cloudflare's Turnstile processing, see Cloudflare's Turnstile Privacy Addendum.

4. Analytics cookies

Google Analytics 4 is blocked by default and loads only after you actively accept analytics. Refusing analytics does not prevent you from using the core service.

Name or patternProviderCategoryPurposeTypeDefault durationConsent
_gaGoogle AnalyticsAnalyticsDistinguishes pseudonymous visitors.First-partyUp to 2 yearsRequired
_ga_<container-id>Google AnalyticsAnalyticsMaintains session state for the configured GA4 data stream.First-partyUp to 2 yearsRequired

These are Google's default durations and may be shortened by the GA4 property configuration or browser limits. We do not use Google Ads tracking in this implementation.

5. How consent works

We use CookieConsent v3 to manage your preferences. Necessary storage and required security verification remain enabled because they support the basic operation and protection of the service. Analytics is optional and is enabled only if you actively consent.

If you reject analytics or later turn it off, we stop future collection, disable Analytics, and attempt to clear accessible _ga cookies for the relevant domain and path variants. A browser may prevent deletion where a cookie was created with attributes unavailable to page scripts.

Withdrawal stops future collection but does not automatically erase information previously processed lawfully. You may accept analytics again later through Cookie Settings.

6. How to change preferences

You can change your choice at any time:

  • on public pages, use the action in the footer;
  • inside the app, open Settings from the sidebar menu and use Cookie Preferences;
  • you can also clear cookies or local storage directly in your browser, although doing so may sign you out or reset preferences.

You can also manage browser storage using your browser controls. See the help pages for Chrome, Firefox, and Safari.

7. Retention

The cc_cookie consent-preference cookie is retained for 182 days unless you delete it earlier. Other necessary storage is retained according to its technical role, browser behavior, and account lifecycle.

The secure HttpOnly auth cookie may remain active until it expires or you sign out, the visitor security cookie may remain for up to one year unless refreshed or cleared sooner, and local storage such as ecs_session_hint or easycontent.language may remain until cleared by the app, you, or the browser. GA4 cookies use the durations shown above unless cleared or shortened sooner.

8. Contact Us

If you have questions about this Cookie Policy or about storage used by Easy Content Studio, contact [email protected].