Skip to content

Cookie Policy

Last updated: 02/09/2026

This Cookie Policy explains how Diglot OÜ (“Diglot”, “we”, “us”) uses cookies and similar technologies on diglot.ai, in our web editor, browser extensions, and other surfaces of the Service. It complements our Privacy Policy and the Terms of Service.

1. What cookies and similar technologies are

A cookie is a small text file that a website stores on your device when you visit it. Similar technologies — local storage, session storage, pixels, and SDK identifiers — work in comparable ways. We use the word “cookies” in this policy as a shorthand for all of them.

2. The categories we use

Cookies on our sites fall into four categories. Strictly necessary cookies are always on; everything else is off by default and only set after you opt in via the cookie banner or in Settings → Privacy → Cookies.

CategoryWhat it doesDefaultExamples on Diglot
Strictly necessaryCore functions: signing in, keeping your session, security, load-balancing, fraud prevention at checkoutAlways onSupabase Auth session cookie, Cloudflare security cookies, Merchant-of-Record checkout session
Functional / preferencesRemember language, theme, dismissed dialogsOn (with notice)UI language, theme, dismissed onboarding tips
AnalyticsUnderstand which features are used and where users get stuck — to improve the productOff until consentPostHog (with IP anonymisation), Google Analytics 4
Marketing / advertisingAttribute a visit to the partner or campaign that sent it, so partners can be paid and campaigns measuredOff until consentPartner-programme attribution (diglot_aff, set by us); Meta (Facebook) Pixel

The partner-programme cookie is first-party — set by our own domain, containing only an opaque identifier of the click that brought you here. The Meta Pixel is a third-party advertising tag: it loads only after you accept marketing cookies, and it lets us measure which advertising brought people to Diglot. Declining leaves it unloaded; nothing in the Service stops working.

3. Specific cookies you may see

Name (prefix)ProviderCategoryPurposeLifetime
sb-…-auth-tokenSupabaseStrictly necessaryKeeps you signed inSession / up to 7 days
__cf_bm, cf_clearanceCloudflareStrictly necessaryBot management, DDoS protection30 minutes – 1 year
Checkout session cookiesOur Merchant of Record (Dodo Payments; Paddle on failover)Strictly necessaryMaintains the secure payment session while you paySession
diglot_consentDiglotStrictly necessaryStores your cookie-banner choices12 months
diglot_locale, diglot_themeDiglotFunctionalRemembers UI language and theme12 months
diglot_affDiglotMarketingRecords which partner’s link brought you here, so that partner can be paid if you subscribe. Contains an opaque click identifier — no name, e-mail, or browsing history60 days
refgrow_ref_codeRefgrowMarketingSame purpose as diglot_aff, for the partner programme run on Refgrow. Set only after you accept marketing cookies, and only on a visit that did not arrive through a different partner link30 days
ph_*PostHogAnalyticsProduct analytics; events tied to a hashed device id, IPs anonymisedUp to 12 months
_ga, _ga_*Google Analytics 4AnalyticsMeasures traffic and which pages people arrive onUp to 24 months
_fbp, _fbcMeta (Facebook)MarketingMeasures whether an advertisement led to a visit or a sign-upUp to 3 months
sentry_* (transient)SentryStrictly necessaryCorrelate front-end errors with a session for debuggingSession

The list above is illustrative; the actual cookies set on a given visit depend on the page, your plan, and your consent choices. The current cookies are always disclosed via your browser’s developer tools.

4. Your choices

  • Cookie banner — on your first visit you’ll see a banner with Accept all, Reject all, and Manage preferences at the same level of prominence. Rejecting all non-essential cookies is one click and does not break the Service.
  • In-product — change your choices any time at Settings → Privacy → Cookies.
  • Browser-level — most browsers let you delete or block cookies. Blocking strictly necessary cookies will prevent you from signing in.
  • Global Privacy Control (GPC) — if your browser sends a GPC signal, we treat it as an opt-out of analytics and of any “sale” or “sharing” of personal data under U.S. state privacy laws.
  • Do Not Sell or Share My Personal Information — for California and other U.S. states, use the link in the website footer. (As noted in our Privacy Policy, we do not sell or share your data, but we honour the request and the GPC signal regardless.)

Where the EU ePrivacy Directive and GDPR apply, consent for non-essential cookies is collected on an opt-in basis: no boxes are pre-ticked, the Reject all option is as easy to use as Accept all, and we re-ask for consent at most every 12 months or when a material new category is introduced.

6. Third-party services

Some cookies are set by our service providers (“subprocessors”), not by Diglot directly. The full list is at /subprocessors and includes Cloudflare, Supabase, PostHog, Google Analytics, Meta, Sentry, our Merchant of Record, and — for the partner programme — Affonso and Refgrow. The partner-attribution cookie itself is set by us, not by Affonso. When you interact with content embedded from third parties (for example, a YouTube video on a blog post), those providers may set their own cookies under their own privacy policies.

We may update this Cookie Policy when our cookie use, the underlying tools, or applicable law changes. The “Last updated” date at the top reflects the current version. Material changes — for example introducing a new category of cookies or a new provider — will be communicated via the cookie banner and a notice in the product.

8. Contact

Questions about this Cookie Policy or how to exercise your rights:

Diglot OÜ — Republic of Estonia (registration in progress).