Open the Designer

Cookie Policy

Last updated: 19 July 2026. This page lists every cookie and browser-storage item BPMN Studio sets, and lets you change your choice at any time. For the wider picture, see the Privacy Policy.

Change your choice

Open cookie settings →

That link reopens the preferences panel wherever you are on the site. Your choice is stored on your own device and applies across the app and every article page.

What we set

Strictly necessary

These are required for the site to work. They are set without consent, because without them you cannot sign in or pay, and EU law exempts them for that reason.

Name Provider Type Duration Purpose
bs_consent BPMN Studio localStorage 12 months Remembers your cookie choice so you are not asked on every page
sb-*-auth-token Supabase localStorage Session / until sign-out Keeps you signed in
__stripe_mid Stripe Cookie 1 year Payment fraud prevention
__stripe_sid Stripe Cookie 30 minutes Payment fraud prevention during checkout

The Stripe cookies are set only when you begin a checkout.

Analytics — optional

Set only after you accept the Analytics category.

Name Provider Type Duration Purpose
_ga Google Cookie 2 years Distinguishes one visitor from another
_ga_YD5QV8N989 Google Cookie 2 years Maintains the analytics session state

We also use Vercel Analytics for aggregate page-view counts. It sets no cookies and stores no identifier on your device — but it is still only loaded once you accept the Analytics category.

Marketing — optional

We currently set no marketing cookies. No advertising or remarketing pixel is installed. The category exists so that if one is ever added, it runs on consent you have actually given rather than being switched on quietly.

What happens before you choose

We want to be straightforward about this, because "no cookies until you consent" is often stated and rarely true.

Google Analytics runs in Consent Mode v2, advanced mode. The Google tag loads on page load with every consent signal defaulted to denied. While denied, it:

  • sets no cookies and stores nothing on your device
  • sends a cookieless ping containing a timestamp, your user agent, the referring page and your consent state
  • has IP addresses discarded rather than logged by Google

That ping lets us see rough aggregate traffic without identifying anyone. When you accept, the same tag upgrades to normal cookie-based measurement. When you reject, it stays in the cookieless state permanently, and no _ga cookie is ever created.

If you would rather send nothing at all, the browser controls below block it entirely.

Verifying this yourself

You do not have to take our word for it. In your browser's developer tools:

  • Application → Cookies on a fresh visit, before choosing: there is no _ga cookie.
  • Network, filter for collect: requests carry a gcs parameter. G100 means analytics denied; G111 means granted. Watch it change when you accept.

Blocking cookies in your browser

Every major browser can block or clear cookies independently of this site:

  • Chrome — Settings → Privacy and security → Third-party cookies / Delete browsing data
  • Firefox — Settings → Privacy & Security → Cookies and Site Data
  • Safari — Settings → Privacy → Manage Website Data
  • Edge — Settings → Cookies and site permissions

Blocking strictly necessary storage will sign you out and may break checkout. Blocking analytics storage is harmless — the site works identically.

Browser "Do Not Track" and Global Privacy Control signals are not a reliable standard across browsers, so we rely on your explicit choice in the banner rather than inferring one.

Questions

Email mikalajunas.emilis@gmail.com. If we add or remove a cookie, this table is updated and the Last updated date changes; a new category would re-prompt you.