Cookie Policy

Last updated: 2 July 2026

The short version

Unsourced uses analytics to understand how the site is used. Non-essential analytics cookies (Google Analytics and Microsoft Clarity) load ONLY after you accept them via our cookie banner — decline and they never run. The only thing we store without consent is a strictly-necessary authentication token when you sign in.

What we store in your browser

We store one item in your browser:

  • Authentication token (localStorage, not a cookie): when you sign in, a JWT (JSON Web Token) is stored in your browser's localStorage to keep you logged in. This is a session token, not a tracking cookie. It contains your account identifier and an expiry time. It is not transmitted to any third party and is automatically cleared when you sign out or after 24 hours.

This item is strictly necessary for the service to function. It cannot be opted out of while signed in.

Analytics

To understand how visitors use unsourced.app, we use Google Analytics 4 (Google LLC) and Microsoft Clarity (Microsoft Corporation). These set analytics cookies, and Clarity additionally records anonymised session interactions (heatmaps) to show how pages are used. Because these are not strictly necessary, they load ONLY after you accept via our cookie banner. If you decline, neither is loaded and no analytics cookies are set. You can withdraw consent at any time by clearing your browser's site data for unsourced.app. Google's privacy policy: policies.google.com/privacy. Microsoft's: privacy.microsoft.com/privacystatement.

Stripe (payment processing)

When you complete a payment, you are directed to a Stripe-hosted checkout page. Stripe may set cookies on their own domain (stripe.com) during this process for fraud prevention and session management purposes. These cookies are subject to Stripe's own Cookie Policy (stripe.com/cookie-settings), not ours. You do not encounter Stripe cookies when simply browsing unsourced.app.

Unsourced monitoring tools — beacon, WordPress plugin, Cloudflare Worker, and server-side snippet

The JS beacon (beacon.js), WordPress plugin, Cloudflare Worker, and server-side reporter snippets (Vercel, Netlify, Node and other backends) that customers install on their own websites are monitoring tools — none of them set cookies. They make lightweight server requests to log AI bot activity.

IMPORTANT: if you are an Unsourced customer who has installed any of these tools on your own website, you are responsible for disclosing their use in your own Privacy Policy and Cookie Policy. These tools do not set cookies, but they do process visitor IP addresses and user-agent strings as described in our Privacy Policy. You may need to update your own site's documentation accordingly.

Do you need a consent banner?

For the non-essential analytics above (Google Analytics and Microsoft Clarity): yes — and we show one. Under UK GDPR and PECR, analytics cookies require prior consent, so those tools load only after you accept our cookie banner; decline and nothing analytics-related is set. Our sign-in authentication token is strictly necessary and exempt from consent.

If you are a customer installing the Unsourced beacon on your own site, you should review your own site's cookie and consent obligations separately.

Managing your browser storage

You can clear all browser storage (including our authentication token) at any time via your browser settings (usually under Privacy or Clear Browsing Data). Doing so will sign you out of Unsourced. You can also sign out explicitly via the dashboard, which removes the token immediately.

Changes to this policy

We will update this page if our cookie or storage practices change. The current version is always available at unsourced.app/cookies.

Contact

For questions about our use of cookies or browser storage: rene@unsourced.app