Legal

Cookie policy

Last updated: 25 July 2026

VistoPilot is built to be light on cookies. We set only a handful of strictly-necessary and functional cookies, and we use no advertising or third-party tracking cookies. Our product analytics is first-party and cookieless (explained below).

Cookies we set

CookiePurposeLifetimeType
authjs.session-tokenKeeps you signed in after you authenticate with Google.~30 daysStrictly necessary
authjs.csrf-tokenProtects sign-in and forms against cross-site request forgery.SessionStrictly necessary
vp_refRemembers who referred you (from a /r/ or invite link) so we can credit them if you sign up.30 daysFunctional
vp_impersonateSet only when a support admin views your account read-only to help with an issue; short-lived and signed.30 minutesStrictly necessary

Signing in with Google may also briefly set standard authentication cookies during the sign-in exchange; these are strictly necessary and clear once you're signed in.

Our analytics is cookieless

To understand how the product is used, we count page views and clicks — but we do this without any cookie and without storing your IP address. When a page loads, our own servers turn your IP address and browser into a daily, non-reversible code (it changes every day and cannot be turned back into your IP), which lets us count unique visitors without identifying anyone. The raw IP is discarded immediately; we keep only a country (from your connection) and whether you were on mobile or desktop.

We never capture what you type, and we do not track you across other websites or sell any of this data. Because this analytics stores nothing on your device, it does not require a cookie-consent banner under EU rules — but you can still object at any time by emailing support@vistopilot.com.

Managing cookies

You can clear or block cookies in your browser settings at any time. Blocking the strictly-necessary cookies above will stop you from staying signed in. For everything else about how we handle your data, see our Privacy policy.