Cookie Notice
Download as PDFTaproot uses cookies and similar browser storage where needed to operate and secure the service. A cookie is a small value a website asks a browser to retain and send with later requests.
Cookies we set
Strictly necessary — Taproot app (app.taproot.io and *.taproot.io)
Cookie Purpose Lifetime __taproot_session Keeps you signed in to your Taproot account 15 minutes, renewed while you use the service __taproot_refresh Lets your session renew without signing in again 1–30 days (you choose in settings; default 7 days)
These are set for the taproot.io domain so signing in also works on Taproot staging and profile addresses. They are HttpOnly, Secure, SameSite=Lax cookies.
Strictly necessary — published creator sites
When you sign in on a published creator site (to comment, follow, or access member content), that site sets its own site-scoped session cookies:
Cookie Purpose Lifetime __taproot_site_session Keeps you signed in on that specific site 15 minutes, renewed while you browse __taproot_site_refresh Lets that site session renew 7 days
These are scoped to the individual site's domain only. Visitors who never sign in on a published site receive no Taproot cookies from it.
Payment cookies (Stripe)
Checkout and payment-method pages on app.taproot.io load Stripe's payment component, and Stripe sets its own cookies (such as __stripe_mid, about one year, and __stripe_sid, about 30 minutes) for fraud prevention and payment security under Stripe's cookie policy. Stripe's component loads only on checkout and billing surfaces, never on published creator sites.
Referral attribution
Cookie Purpose Lifetime __taproot_affiliate Records that you followed an affiliate's referral link so the affiliate can be credited if you subscribe 30 days
This cookie is set only when you arrive through an affiliate link, only on app.taproot.io, and is used only for referral crediting and fraud prevention — not for advertising.
Analytics — none
Taproot's site analytics are cookie-free by design. Published-site visits are counted at our edge network without any analytics script, cookie, or device-storage access; visitors are counted using a privacy-preserving identifier that changes every day and cannot be linked across days. Server and edge logs may still process request information for security and reliability.
Optional advertising or personalization — none
Taproot does not use advertising or cross-site tracking cookies. If optional cookies or comparable storage are ever introduced, Taproot will update this notice and implement the required preference/consent controls before use.
Other browser storage
Taproot uses browser localStorage/sessionStorage for non-tracking conveniences: your light/dark theme choice, editor preferences, sign-in flow state, and a flag that remembers whether you have a session so pages load faster. Preference values stay in your browser. Temporary sign-in and signup values — the security values that protect a sign-in redirect, and a short-lived token that connects a completed signup to its payment step — are sent to Taproot only to complete those flows and are cleared afterward. None of this storage is used for advertising, and none of it is shared with third parties.
Creator sites and third parties
Creator-authored content may link to third-party services with their own storage practices, and creator sites may have independent legal duties. Taproot's own published-site templates load no third-party scripts.
Controls
Browsers can block or delete cookies, although strictly necessary features may then fail (you cannot stay signed in without session cookies). Where law requires a preference control for optional technologies, Taproot will present that control before activating them. A link to this notice at signup is notice, not consent.
Questions: support@taproot.io.