What we use
A cookie is a small text file stored on your browser. Most of the cookies we set are strictly necessary — they keep you authenticated to your dashboard, manage session security, and prevent Cross-Site Request Forgery (CSRF). Because these are strictly necessary, they do not require a consent banner under EU/UK GDPR regulations.
We also run one advertising measurement tool, the Meta pixel, described in Advertising below.
Essential cookies
| Cookie Name | Purpose | Duration |
|---|---|---|
kws_everywhere_session | Maintains your authenticated user session | 2 hours of inactivity |
XSRF-TOKEN | Protects web forms against CSRF attacks | Session |
remember_web_* | Optional persistent login token, set only if you tick "Remember me" | 5 years, or until you log out |
cf_* / __cf_* | Set by Cloudflare Turnstile on the sign-up and login screens to tell humans from bots | Up to 30 minutes |
These cookies are set on the application at app.kwseverywhere.com. This marketing site sets no essential cookies of its own; it does load a web font from Google Fonts, which contacts fonts.googleapis.com and fonts.gstatic.com but does not set cookies or identify you.
Advertising
We advertise on Facebook and Instagram, and we use the Meta pixel to measure whether those ads actually lead to sign-ups. It runs on this marketing site and on the application, and it sets the following cookies:
| Cookie Name | Purpose | Duration |
|---|---|---|
_fbp | Set by Meta to distinguish one browser from another, so a visit and a later sign-up can be recognised as the same person | 90 days |
_fbc | Records the ad click that brought you here, from the fbclid parameter on the link. Only set if you arrived from a Meta ad | 90 days |
These are set on kwseverywhere.com and are readable on app.kwseverywhere.com, because measuring an ad means connecting the click on one to the sign-up on the other. We store the same two identifiers against your account when you register, and send them back to Meta when a purchase completes, so that a payment made by bank transfer days later can still be attributed to the ad that caused it.
What this is used for is measuring and targeting our own ads. We do not sell this data, and we do not use it to build a profile of your activity on other websites. Meta processes it under its own data policy, and you can limit how it is used from your Facebook ad settings.
Blocking these cookies costs you nothing — every part of the product works normally without them.
Controlling cookies
You can clear or block cookies at any time in your browser settings (e.g. Chrome Settings > Privacy and Security > Third-party cookies). Most ad and tracker blockers stop the Meta pixel outright, and we do not attempt to work around them. Note that disabling essential session cookies will prevent logging into your user dashboard.
Contact
For questions about our cookie practices, reach out to [email protected].