Cookie Policy
How Image-to-Prompt.org uses cookies and browser storage
2026/08/21
1. Scope
This Cookie Policy explains how Image-to-Prompt.org (the Service, we, us, or our) uses cookies and similar browser-storage technologies. It should be read together with our Privacy Policy.
Cookies are small text files stored on your device. Similar technologies, including session storage, can store or retrieve information from your browser for comparable purposes.
2. Technologies We Use
The Service currently uses the following technologies. Cookie names may carry
a __Secure- prefix in production or change when an infrastructure provider
updates its implementation.
Strictly Necessary Cookies
- Authentication session cookie (commonly
better-auth.session_token): keeps you signed in, protects authenticated areas, and helps prevent account misuse. A session may remain valid for up to 7 days unless you sign out or it is revoked. itp_daily_credits(legacy): older versions used this signed cookie to record anonymous usage. New submissions no longer set it. While it remains present, its recorded usage can be carried over to the one-time trial.itp_pending_history: stores a random claim token so an anonymous result can be attached to your account if you sign in. It also identifies the browser's one-time three-image trial. It is HTTP-only and renewed for up to 400 days when used. Signing in does not reset the trial. The token itself does not contain your image or Prompt. Anonymous results expire after approximately 24 hours. After the anonymous result expires, a subsequent cleanup operation deletes its stored image before removing the expired result record.- Security and verification cookies: may be used during email verification, password reset, account linking, checkout initiation, fraud prevention, and other security-sensitive workflows. Their duration is limited to the relevant workflow or session.
These cookies are necessary to provide features you request. Blocking them may prevent free-credit enforcement, sign-in, account security, History claiming, or checkout from working correctly.
Preference Cookies
NEXT_LOCALE: may remember the selected site language. The Service is currently provided in English only.sidebar_state: remembers whether a signed-in navigation sidebar is open or collapsed for up to 7 days.
Browser Session Storage
image-to-prompt:google-one-tap-started: a temporary session-storage marker used to avoid repeatedly starting the Google One Tap flow during the same browser session. It is removed when the session ends or the flow is completed.ga4_google_auth_intent: a short-lived local-storage marker that lets us record a completed Google sign-in only after authentication succeeds. It is removed after use, after a failed sign-in, or ignored when more than 5 minutes old.
3. Third-Party Technologies
Google Identity
If Google One Tap or Continue with Google is displayed or used, Google may set or read cookies and similar technologies under its own policies. Google may receive technical information such as your IP address, browser information, and interaction with the sign-in interface. See the Google Privacy Policy.
Creem Checkout
Purchases and subscription management take place on Creem-hosted pages. Creem may use its own cookies for checkout, fraud prevention, payment processing, and customer-portal functions. Those cookies are controlled by Creem and governed by the Creem Privacy Notice.
4. Analytics, Advertising, and Tracking
We use Google Analytics 4 (GA4) to understand whether visitors can complete
the image-analysis and paid-purchase flows. GA4 may set first-party cookies such
as _ga and _ga_<measurement-id>. These cookies distinguish a browser
through a pseudonymous Client ID, associate activity with a Session ID,
and ordinarily persist for up to 2 years unless you remove or block them. Google
may receive page location, device and browser information, interaction events,
and IP-derived approximate location under its own practices.
For signed-in users, we configure GA4 with an internal, non-public User-ID. For checkout attribution, the Client ID and Session ID are carried through the checkout metadata. After Creem confirms a real payment, our server reports the product, currency, transaction identifier, and transaction-level revenue to GA4. We record initial purchases and subscription renewals as separate events.
We do not send uploaded images, image URLs, filenames, generated Prompts, names, email addresses, payment-card details, authentication tokens, or API secrets to GA4. We do not use GA4 data to sell personal information, build advertising profiles, or enable personalized advertising. We currently do not enable first-party advertising cookies or Vercel Analytics.
5. Your Choices
You can delete or block cookies through your browser settings, use a tracking protection or content-blocking feature, or use private browsing. Blocking GA4 does not prevent core image analysis, authentication, or checkout, although it may make our aggregate funnel reporting incomplete. You can also sign out to end an authenticated session. Blocking strictly necessary cookies may make parts of the Service unavailable.
Where applicable law requires consent for a non-essential technology, you may refuse or withdraw that consent without losing access to core features. Browser controls do not necessarily remove information already stored in our server systems; see the Privacy Policy for data-rights requests.
6. Changes to This Policy
We may update this Cookie Policy when the Service, providers, or legal requirements change. The date at the top identifies the latest revision. Material changes will be highlighted on the Service or communicated by another reasonable method.
7. Contact
Questions or requests about cookies can be sent to [email protected].