Skip to content
Legal & Compliance

Cookie Policy

We use strictly essential authentication and security cookies, plus the Meta advertising pixel to measure our own ads. We do not sell your data or use cross-site behavioural ad networks beyond that.

Last updated 30 August 2026

What we use

A cookie is a small text file stored on your browser. Most of the cookies we set are strictly necessary — they keep you authenticated to your dashboard, manage session security, and prevent Cross-Site Request Forgery (CSRF). Because these are strictly necessary, they do not require a consent banner under EU/UK GDPR regulations.

We also run one advertising measurement tool, the Meta pixel, described in Advertising below.

Essential cookies

Cookie NamePurposeDuration
kws_everywhere_sessionMaintains your authenticated user session2 hours of inactivity
XSRF-TOKENProtects web forms against CSRF attacksSession
remember_web_*Optional persistent login token, set only if you tick "Remember me"5 years, or until you log out
cf_* / __cf_*Set by Cloudflare Turnstile on the sign-up and login screens to tell humans from botsUp to 30 minutes

These cookies are set on the application at app.kwseverywhere.com. This marketing site sets no essential cookies of its own; it does load a web font from Google Fonts, which contacts fonts.googleapis.com and fonts.gstatic.com but does not set cookies or identify you.

Advertising

We advertise on Facebook and Instagram, and we use the Meta pixel to measure whether those ads actually lead to sign-ups. It runs on this marketing site and on the application, and it sets the following cookies:

Cookie NamePurposeDuration
_fbpSet by Meta to distinguish one browser from another, so a visit and a later sign-up can be recognised as the same person90 days
_fbcRecords the ad click that brought you here, from the fbclid parameter on the link. Only set if you arrived from a Meta ad90 days

These are set on kwseverywhere.com and are readable on app.kwseverywhere.com, because measuring an ad means connecting the click on one to the sign-up on the other. We store the same two identifiers against your account when you register, and send them back to Meta when a purchase completes, so that a payment made by bank transfer days later can still be attributed to the ad that caused it.

What this is used for is measuring and targeting our own ads. We do not sell this data, and we do not use it to build a profile of your activity on other websites. Meta processes it under its own data policy, and you can limit how it is used from your Facebook ad settings.

Blocking these cookies costs you nothing — every part of the product works normally without them.

Controlling cookies

You can clear or block cookies at any time in your browser settings (e.g. Chrome Settings > Privacy and Security > Third-party cookies). Most ad and tracker blockers stop the Meta pixel outright, and we do not attempt to work around them. Note that disabling essential session cookies will prevent logging into your user dashboard.

Contact

For questions about our cookie practices, reach out to [email protected].