This Cookie Policy explains how Kutly, LLC ("Kutly," "we," "us," or "our") uses cookies and similar technologies on our website at https://kutly.io/ and on our application at https://app.kutly.io/ (together, the "Site").
This Policy forms part of, and should be read together with, our Privacy Policy, which explains more fully what personal information we collect, why, and what rights you have. Capitalized terms not defined here have the meaning given to them in our Terms of Service.
1. What these technologies are
A cookie is a small text file that a website asks your browser to store on your device. Local storage and session storage are similar, except that they stay in your browser: unlike a cookie, neither is attached to every request your browser makes to us. Local storage remains until it is cleared; session storage disappears as soon as you close the tab. We use the word "cookies" below to cover all three, and the tables tell you which kind each entry is.
Cookies set by us on our own domain are called first-party. Cookies set by another company
whose service we use are called third-party, even when they appear under our domain name —
our sign-in service, for example, runs on clerk.kutly.io and sets cookies there.
Where a cookie's domain begins with a dot, such as .kutly.io, it is visible to every part
of the Site, including both kutly.io and app.kutly.io. Where it names a single host, such as
app.kutly.io, it is visible only there.
A note on the durations below. They are what we ask your browser for. Browsers apply their own limits — Chrome caps any cookie at 400 days, and Safari shortens cookies and stored data written by scripts to about a week — so the figure that actually applies is the shorter of the two.
2. Your choice
When you first visit kutly.io, a banner asks whether you agree to analytics. You can accept or decline. Neither option is preselected, both buttons are equal in size and prominence, and either takes a single click. The banner is deliberately short; this page is the full description of what each choice means, including the session recording covered in Section 6.
| Your choice | What is stored on your device | What we measure |
|---|---|---|
| You ignore the banner | Nothing beyond the strictly necessary cookies in Section 3 — and, if you arrived through a partner link, the referral cookies in Section 5 | Anonymous measurement only (Section 4). For analytics, we cannot recognize you tomorrow. |
| You decline | The same as above, plus a single record of your refusal, so that we can honor it and stop asking | Anonymous measurement only, exactly as above. Declining does not remove you from our visitor counts; it keeps you anonymous. |
| You accept | The same as above, plus an identifier that recognizes your browser on later visits and the record of your consent | Anonymous measurement, plus a link between your visits over time, plus a replay of your visit (Section 6) |
Global Privacy Control. If your browser or an extension sends a recognized opt-out preference signal such as GPC, we honor it as a refusal: the banner is not shown, and you are measured anonymously exactly as in the "You decline" row above. Unlike pressing Decline, this stores no record of your choice at all — your browser sends the signal again on every visit, so there is nothing for us to remember. The entries in Sections 3 and 5 can still appear, because the banner does not govern them.
If you later choose to open Manage cookies yourself and accept, we treat that as a deliberate override of your own signal and honor it.
Changing your mind. You can change or withdraw your choice at any time using the Manage cookies link in the footer of every page. Withdrawal takes effect immediately and is no harder than giving consent in the first place. Withdrawing consent does not affect anything we lawfully did before you withdrew it, and does not delete replays already recorded — to have those deleted, email us at legal@kutly.io.
3. Strictly necessary
These are required for the Site to work, to keep it secure, and to sign you in. They are not optional and are not covered by the banner, because without them the Site cannot deliver the service you asked for.
Almost all of these appear only once you have opened app.kutly.io. For a visitor who never
does, the only entry below that can appear is cf_clearance, and only if our security check
has challenged you. Entries in Sections 4 and 5 are set independently of this table.
| Name | Set by | Type | Domain | Purpose | Duration |
|---|---|---|---|---|---|
__session, __session_B54zy-N9 | Clerk | Cookie | app.kutly.io | Keeps you signed in to the application | 1 year |
__client_uat, __client_uat_B54zy-N9 | Clerk | Cookie | .kutly.io | Tells our servers whether you are signed in, so pages render correctly on first load | 10 years requested; browsers grant less |
__client | Clerk | Cookie | .clerk.kutly.io | Clerk's own record of your client session | 10 years requested; browsers grant less |
clerk_active_context | Clerk | Cookie | app.kutly.io | Remembers which account context you are working in | Session |
__clerk_environment | Clerk | Local storage | app.kutly.io | Caches sign-in configuration so the sign-in screen loads quickly | Until cleared |
cf_clearance | Cloudflare | Cookie | .kutly.io | Records that you passed a security challenge, so you are not challenged repeatedly | Up to 1 year |
__cf_bm | Cloudflare, via Clerk | Cookie | .clerk.kutly.io | Distinguishes human visitors from automated traffic on the sign-in service | 30 minutes |
_cfuvid | Cloudflare, via Clerk | Cookie | .clerk.kutly.io | Supports rate limiting on the sign-in service | Session |
kutly:credits, kutly:usage, kutly:presets, kutly:recents, kutly:voiceFavorites — each suffixed with your account identifier | Kutly (first party) | Local storage | app.kutly.io | Holds your credit balance, render counts, saved presets, recent projects, and voice preferences so the application can display them without refetching | Until cleared |
We do not use Stripe's browser scripts on our own pages; payment is completed on Stripe's hosted checkout, and any cookies set there are governed by Stripe's privacy policy.
4. Analytics — covered by the banner
We use PostHog to understand how people find and use the Site: which pages are read, where visitors come from, what they click, how far they scroll, and how quickly pages load. Analytics events reach PostHog through our own server rather than directly from your browser. This does not change who receives the data; PostHog receives your IP address.
Unless and until you accept, this measurement is anonymous and PostHog stores no identifier on your device — no cookie, nothing in session storage, and nothing in local storage except the record of your choice, if you made one. PostHog counts you using an irreversible one-way calculation based on your IP address, your browser type, the site you are visiting, and a secret value that changes every day. That secret is discarded at the end of each day, so if you come back tomorrow you are counted as a new visitor and cannot be connected to today's visit.
If you accept, PostHog stores an identifier on your device so that your visits can be recognized as belonging to the same browser over time. This is what lets us see, for example, that someone read three pages over two weeks before contacting us.
| Name | Set by | Type | Domain | Purpose | Duration |
|---|---|---|---|---|---|
ph_phc_…_posthog | PostHog, via kutly.io | Cookie | .kutly.io | Recognizes your browser across visits and groups your activity into sessions | Up to 1 year |
__ph_opt_in_out_phc_… | PostHog, via kutly.io | Local storage | kutly.io | Records the choice you made on the banner so it is applied on later visits | Until cleared |
ph_phc_…_posthog | PostHog, via kutly.io | Session storage | kutly.io | Holds where you arrived from, for the length of this browsing session | Until you close the tab |
ph_phc_…_window_id | PostHog, via kutly.io | Session storage | kutly.io | Tells one open tab apart from another | Until you close the tab |
Only the second of these is stored if you decline; the rest appear once you accept. That one is stored whichever button you press, including Decline — without it we could not remember your refusal and would ask you again on every page. It is the only thing PostHog stores for someone who declines; Sections 3 and 5 are set independently of your choice.
The first entry and the third share a name but are not the same thing: one is a cookie that lasts up to a year, the other is session storage that is gone when you close the tab.
PostHog is named in our Privacy Policy as one of the companies whose services we use. See PostHog's privacy policy.
5. Referral attribution — not covered by the banner
If you arrive at kutly.io through a link shared by one of our affiliate partners, our affiliate provider FirstPromoter stores identifiers recording which partner referred you, so that the partner is credited if you later subscribe.
A partner link is recognized by a parameter in the address. Ten are accepted: fpr, fp_ref,
via, ref, a, _from, _by, deal, _go, and _get. Some of these are common on the
web generally, so a link that happens to use one without coming from a partner is treated the
same way. If none is present, nothing below is stored.
These are set whichever button you press on the banner, and they are set even if you press nothing. They tell us which partner referred you, and we do not use them for advertising or to track you across other websites. Because of this, the banner's refusal button says "Decline" rather than "Reject all."
| Name | Set by | Type | Domain | Purpose | Duration |
|---|---|---|---|---|---|
_fprom_tid | FirstPromoter | Cookie | .kutly.io | Identifies the referral so the partner's commission can be attributed | Up to 60 days |
_fprom_ref | FirstPromoter | Cookie | .kutly.io | Records which partner referred you | Up to 60 days |
kutly:fprReferral — suffixed with your account identifier | Kutly (first party) | Local storage | app.kutly.io | Carries the referral through to your subscription so the partner's commission can be attributed | Until cleared |
Because these are set on .kutly.io, they remain valid when you move from kutly.io to
app.kutly.io, which is what allows a referral to be credited when you subscribe. The analytics
identifier in Section 4 is stored on the same domain, but we do not measure your activity
inside app.kutly.io at all — our analytics provider is not installed there.
Your browser fetches FirstPromoter's script only when there is a referral to attribute: on kutly.io, when the address carries one of the parameters above; in the application, that, or when you create an account while a referral cookie from an earlier visit is still present. Without a referral your browser never contacts FirstPromoter at all — no request, no IP address, and nothing stored on your device.
Two different parties are involved here, and they see different things.
FirstPromoter is the company whose service we use to run the affiliate program. If you create an account after arriving through a partner link, we send it your account identifier — not your email address — so the referral can be matched to the account. If you did not arrive through a partner link, nothing about your registration is sent to FirstPromoter at all. If that account later subscribes, Stripe passes on the referral identifier and your account identifier so the commission can be calculated; we do not send your email address there either, so any address FirstPromoter holds is one you entered on Stripe's payment page yourself. This referral report also carries the address of the page you were on and the page you came from.
The partner is the person who shared the link. We send them nothing ourselves, and we never send FirstPromoter your name. What a partner can see is decided by FirstPromoter: as of the date of this Policy, the referral we report carries no email address at all, and where an address does reach FirstPromoter through Stripe, a partner is shown it with most of the characters replaced by asterisks, together with the commission earned.
How long FirstPromoter keeps the record. This is FirstPromoter's own statement, not a commitment we can make for it: as of the date of this Policy, FirstPromoter states that its data retention is two years for expired trial and cancelled users, and five years for the rest. That is longer than the lifetime of the cookies above, which govern only how long your browser carries the referral, not how long the resulting record is kept.
See FirstPromoter's privacy policy and its GDPR statement.
6. Session recording
Only if you accept, PostHog creates a replay of your visit to kutly.io — the pages you view, where you click, how you move and scroll, and how the page responded — so that we can see where the Site is confusing or broken. Recording begins on the page after the one where you pressed Accept.
Text you type into forms is never recorded. The contents of every input field, text area, and dropdown are replaced with placeholder characters in your browser before any recording data is transmitted. Your name, email address, and the message you write in our contact form or the "Contact sales" form never appear in the replay — they are not merely hidden during playback; they are never sent — and neither is text you type and then delete. We can see that a field was filled in and where people stop filling in the form; we cannot see what was written. What you choose to submit reaches us through the form itself, as described in our Privacy Policy.
We do not record replays of your activity inside app.kutly.io. Our analytics provider is not installed there at all.
Replays are stored by PostHog and are automatically deleted 30 days after they are created.
Recording sets no additional cookie beyond the analytics identifier in Section 4, but it does
add two entries to your browser's session storage — ph_phc_…_primary_window_exists and
ph_phc_…_session_registered_properties. They let several tabs open at once be recorded as
one visit rather than one recording each, and both disappear when you close the tab. To have
replays of your visits deleted sooner, email us at legal@kutly.io.
7. Controlling cookies in your browser
Separately from our banner, you can block or delete cookies through your browser settings. Blocking strictly necessary cookies will stop parts of the Site from working — in particular, you may not be able to stay signed in.
Several entries in the tables above are held in local or session storage rather than as cookies, and browsers do not list those alongside cookies. Session storage clears itself when you close the tab; to remove the rest, use your browser's option to clear site data or browsing data for kutly.io and app.kutly.io.
Because there is no common industry standard for "Do Not Track" signals, we do not respond to them. We do act on recognized opt-out preference signals such as Global Privacy Control, as described in Section 2.
8. Changes to this Policy
We may update this Policy as the Site changes. When we do, we will revise the "Last updated" date above. If we begin using a technology that requires your consent for a new purpose, we will ask you again rather than relying on a choice you made earlier.
9. Contact
Questions about this Policy, or a request to delete replays of your visits:
Kutly, LLC
Attn: Legal Department
131 Continental Dr, Suite 305
Newark, Delaware 19713, USA
Email: legal@kutly.io