AutoPosting ProPricing →
// COOKIE POLICY

Cookie Policy

Last updated July 26, 2026

This page lists every cookie autopostingpro.com sets and why. The short version: we use essential, first-party cookies only — the ones needed to sign you in and keep your account secure. We do not use advertising cookies, analytics cookies, or cross-site tracking of any kind.

Cookies we set

All of the cookies below are first-party (set by autopostingpro.com), marked HttpOnly and Secure where the browser supports it, and are only used to operate the service. Most appear only after you sign in. On non-HTTPS local development the __Secure-/__Host- prefixes are dropped.

CookiePurposeDurationEssential
__Secure-next-auth.session-tokenKeeps you signed in to the client portal and admin dashboard.8 hoursYes
__Host-next-auth.csrf-tokenProtects sign-in and account forms against cross-site request forgery.Browser sessionYes
__Secure-next-auth.callback-urlReturns you to the page you came from after signing in.Browser sessionYes
apf_tdRemembers a device you explicitly trusted after two-factor sign-in, so we do not have to email you a code on every login from that device.30 daysYes
meta_pickEncrypted, short-lived cookie used only during the Facebook connection flow, while you choose which Facebook Page to connect.10 minutesYes

Browser storage (not cookies)

We also use your browser’s localStorage for two small UI preferences. This data never leaves your browser and is not sent to our servers:

  • autopostingpro:setup:progress — remembers which steps of the portal setup checklist you have completed.
  • ap_cookie_notice_v1 — remembers that you dismissed the cookie notice so we do not show it again.

What we do not use

  • No advertising or retargeting cookies.
  • No third-party analytics cookies (no Google Analytics, no pixels, no session recording).
  • No cross-site tracking or fingerprinting.
  • We do not sell or share your data for advertising.

Third-party services

  • Stripe — payments happen on Stripe’s own hosted checkout page (checkout.stripe.com). Stripe sets its own cookies there under its own privacy policy; card details never touch our servers.
  • Iconify CDN — the site loads its icon graphics from the Iconify CDN. Those requests carry standard web-request data (IP address, browser info) like any resource load, and set no AutoPosting Pro cookies.
  • Infrastructure logs — our hosting provider (Vercel) keeps standard server logs (IP address, user agent, timestamps) for security and operations, and the domain’s DNS and email routing run through Cloudflare. These are ordinary infrastructure records, not tracking cookies.

Managing cookies

You can block or delete cookies in your browser settings at any time. Because every cookie we set is essential, blocking them will prevent sign-in to the portal — the public marketing pages work fine without any cookies. Since we do no tracking, there is nothing to opt out of beyond that.

Changes & contact

If we ever add a new cookie, we will list it here and update the date above. Questions: [email protected]. See also our Privacy Policy.

This document is provided as a general template and does not constitute legal advice. Have counsel review it before relying on it.