Cookie Policy
Last updated: August 16, 2026
This page lists the cookies and similar technologies spanli.com uses. It is short, because we use few. Two cookies make the product work. On our public pages — the marketing site, these legal pages and the sign-in screens — we also use Google Analytics and Microsoft Clarity to understand how those pages are used and to measure our advertising, and we ask for your consent first where the law requires it. Your dashboard, your projects and the websites you publish are never tracked.
1. Cookies we set
A cookie is a small file a website stores in your browser and sends back to the server on each request. These two come from us and exist to make the product work.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| spanli_session | Spanli | Keeps you signed in. It holds a random session identifier, not your details. Without it you cannot stay signed in to your dashboard. | 24 hours, or 30 days if you tick “Remember me” when signing in |
| spanli_consent | Spanli | Remembers the cookie choices you made in the consent banner, so we do not ask you again and can respect your answer. | 12 months |
The session cookie is marked HttpOnly, so page scripts cannot read it, Secure, so it is only ever sent over HTTPS, and SameSite=Lax, so other websites cannot cause your browser to send it.
Both cookies are strictly necessary: one delivers the service you asked for by signing in, the other records the privacy choice you made. Under the ePrivacy rules neither requires consent.
2. Analytics and advertising measurement
On our public pages — the marketing site, these legal pages and the sign-in and sign-up screens — we use Google Analytics 4, loaded through Google Tag Manager, to understand how those pages are used and to measure whether our advertising works. We also use Microsoft Clarity on the same pages, which builds heatmaps and anonymised replays of how those pages are used — where people scroll, click and hesitate — with typed text masked. These tools never load in your dashboard, in your projects, or on the websites you publish.
Where the law requires consent — the European Economic Area, the United Kingdom and Switzerland — no analytics or advertising cookie is set until you allow it in the consent banner, and declining is exactly as easy as accepting. Elsewhere you can opt out at any time with the “Manage cookies” link in the footer of every public page.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| _ga, _ga_* | Google Analytics | Tells returning visits apart from new ones using a random identifier. Only set if you have allowed analytics cookies. | Up to 2 years |
| _clck | Microsoft Clarity | Tells returning visits apart from new ones for Clarity’s heatmaps, using a random identifier. Only set if you have allowed analytics cookies. | Up to 1 year |
| _clsk | Microsoft Clarity | Links the pages of one visit into a single session replay. Only set if you have allowed analytics cookies. | 1 day |
If you allow advertising cookies, Google may additionally store identifiers that connect a visit to an ad you clicked, for measuring our campaigns. We never see who you are from any of this, and none of it exists on the sites you build.
3. Things we store in your browser
The app also remembers some interface preferences using your browser’s local storage. These are not cookies: they stay in your browser and are never sent to us. They hold your settings, not your identity.
| Key | What it remembers |
|---|---|
| spanli-theme | Whether you chose the light or dark theme. |
| spanli-sidebar-collapsed | Whether you collapsed the dashboard sidebar. |
| spanli:chat-split | How wide you dragged the divider between chat and preview. |
| spanli:composer-expanded | Whether you expanded the message box. |
| spanli:preview-device | Whether you were previewing at phone, tablet or desktop width. |
| spanli:preview-zoom | The zoom level of the preview. |
| spanli:last-project | Which project you were last working on, so we can reopen it. |
| spanli:resume-after-topup | The message you were sending when you ran out of credits, so it can be resumed after you buy more. |
| spanli:wizard-draft:<project> | Your answers in the setup questionnaire, so that leaving the page and coming back does not lose them. Cleared when you finish setup. |
These persist until you clear your browser storage. Clearing them loses the preference and nothing else.
4. Third parties
A few features load resources from other companies while you use them. Apart from Google’s consent-gated analytics cookies described above, none of them set cookies on spanli.com, but the request itself reveals your IP address to that company.
- Google serves the Tag Manager and Analytics scripts on our public pages, so Google sees your IP address there. What it may store in your browser is governed by your consent choices, described in section 2.
- Microsoft serves the Clarity script on the same public pages, under the same consent choices, so Microsoft sees your IP address there.
- Stripe handles payments on its own hosted checkout page. When you are sent there to pay, you are on Stripe’s website and Stripe’s own cookie and privacy policies apply. We do not embed Stripe on our pages.
- Pexels serves the preview thumbnails in the stock photo picker directly to your browser, so Pexels sees your IP address while the picker is open.
- Google Fonts serves the typefaces used to preview each design option during setup, so Google sees your IP address at that moment.
5. Cookies on the websites you publish
Websites you build with Spanli are yours, and what they store in a visitor’s browser is your responsibility. By default a published Spanli site sets no cookies at all.
One exception is worth knowing about: if you turn on spam protection for a form on your site, that form loads Cloudflare Turnstile to check that the sender is a person. Turnstile may store a short-lived value in the visitor’s browser to complete that check. If you enable it, mention it in your own site’s privacy notice.
If you add your own analytics, embeds or third-party scripts to your site, you are responsible for disclosing them and for collecting consent where the law requires it.
6. Managing cookies
You can change your analytics and advertising choices at any time with the “Manage cookies” link in the footer of every public page, including this one. Withdrawing consent takes effect immediately for everything sent after it.
Signing out clears the session cookie. Every browser also lets you view, block and delete cookies and local storage from its settings. Blocking the session cookie means you will not be able to stay signed in, so the dashboard will not work, but the public pages will.
7. Contact
Questions about this page, or about anything in our Privacy Policy: privacy@spanli.com.