Cookie Policy

Last updated: 14 May 2026

1. What this page covers

This page lists the cookies and browser-storage keys that GSC Wizard sets, what each one does, whether it is strictly necessary, and how long it persists. It is a companion to the Privacy Policy.

2. Strictly necessary

These are required for the service to work. They are always set and cannot be disabled via the consent banner. Declining non-essential cookies does not affect them.

  • sb-<project>-auth-token - HTTP-only Supabase session cookie that keeps you signed in. Expires when the session expires or you sign out.
  • oauth_link_state - short-lived HTTP-only cookie used as a CSRF token while linking a Google account. Removed immediately after the OAuth callback.
  • oauth_bigquery_link_state and oauth_bigquery_link_account_id - short-lived HTTP-only cookies (10 minutes) used as a CSRF token and target-account hint when you opt in to the BigQuery sync. Only set if you start the "Connect BigQuery" flow; removed immediately after the OAuth callback.
  • gscwizard_cookie_consent - first-party cookie set on .gscwizard.com (and mirrored to localStorage) that remembers your choice on the consent banner so we don't prompt you again. Because it is shared across our subdomains, one choice covers this site, the app at tool.gscwizard.com and the MCP docs at mcp.gscwizard.com. Value is accepted or declined; persists up to 1 year.

3. Analytics (optional)

Set only if you click Accept on the cookie banner. You can withdraw consent at any time by deleting the gscwizard_cookie_consent cookie (and localStorage key) or by using your browser's site-data tools.

  • PostHog cookies (prefixed ph_) - anonymous distinct-id, session id, and feature-flag state used by PostHog to deduplicate events and reproduce bugs. Persists up to 1 year.

Until you choose, PostHog runs in cookieless mode on both the marketing site and the app: it counts pageviews without storing anything on your device, with no cookie, no localStorage and no sessionStorage, and no identifier that can follow you between visits or between our sites. While in that state we do not link those pageviews to your account and do not record your session. Accepting switches on the ph_ cookies described above, and session recording. Declining stops analytics entirely, and PostHog is not loaded again on later pages.

4. Functional (set by sub-processors)

  • Stripe may set fraud-prevention cookies on the checkout page (__stripe_mid, __stripe_sid). These are required for payment pages to function.
  • Vercel may set a short-lived load-balancer cookie to route your request consistently within a session.

5. What we do not use

  • No advertising or retargeting cookies.
  • No third-party social-media pixels.
  • No cross-site tracking beyond the sub-processors above.

6. Managing your choices

You can use the consent banner the first time you visit, or delete the gscwizard_cookie_consent cookie (and localStorage key) in your browser to be prompted again. Your choice is shared across gscwizard.com subdomains, so accepting or declining once covers the marketing site, the app and the MCP docs page. All modern browsers also let you block or delete cookies on a per-site basis from their settings.

7. Contact

Questions about cookies:

privacy@gscwizard.com

Search Console tips in your inbox

Practical GSC and GA4 workflows, product updates and SEO experiments. No spam, unsubscribe anytime.