Skip to content

Cookie Policy


1. Overview and Core Principles

This Cookie Policy explains how Shot2Ad ("we", "us", or "our") uses cookies and similar storage technologies when you visit our website and interact with our studio workspace.

Our Commitment: Shot2Ad maintains a minimal and privacy-respecting footprint. We utilize only technical identifiers required for system security, active session management, and basic UI personalization. We do not deploy third-party behavioral ad tracking or cross-site profiling cookies.

2. What Are Cookies

Cookies are small text snippets placed on your device by websites you visit. They allow web platforms to remember your session or preferences over a period of time, ensuring you don't have to re-authenticate or re-select settings upon page navigation.

In addition to standard HTTP cookies, we may use browser web storage (such as LocalStorage) to preserve UI state preferences locally on your client device.

3. Cookies and Technologies We Use

Shot2Ad uses only the following first-party technical categories:

3.1 Authentication and Security (Strictly Necessary)

  • better-auth.session_token / better-auth.csrf_token:
    • Purpose: Authenticates active user sessions, validates API transactions, and protects against Cross-Site Request Forgery (CSRF).
    • Duration: Session duration, or up to 30 days if persistent login is selected.
    • Impact: Essential for core functionality. Disabling these cookies prevents signing in to the studio workspace or triggering ad generation.

3.2 Preferences and Functionality (Functional)

  • locale:
    • Purpose: Remembers your preferred interface language (e.g., English en or Simplified Chinese zh) across sessions.
    • Duration: 1 year.
  • theme:
    • Purpose: Stores your selected visual display theme (Light, Dark, or System).
    • Duration: 1 year.
  • sidebar:state:
    • Purpose: Preserves the collapsed or expanded state of the studio navigation sidebar, preventing layout shifts between page transitions.
    • Duration: Persisted in local client storage.

3.3 Security and Edge Reliability (Operational)

  • Security identifiers (such as Cloudflare edge tokens like __cf_bm) may be dispatched dynamically by our edge proxy to defend against automated bot abuse and DDoS attacks. These tokens are strictly operational and carry no personal identity data.

4. Managing and Disabling Cookies

Most browsers accept cookies by default, but you can configure your browser settings to inspect, restrict, or purge stored cookies:

  • Google Chrome: Settings → Privacy and security → Third-party cookies
  • Apple Safari: Settings → Privacy → Block all cookies
  • Mozilla Firefox: Settings → Privacy & Security → Enhanced Tracking Protection
  • Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies

Please Note: If you disable strictly necessary authentication cookies, you will be unable to sign in, use the generation workspace, or access purchased credits.

5. Policy Updates and Contact

We may periodically revise this Cookie Policy as our platform infrastructure evolves. Modifications will appear on this page with an updated "Last updated" date.

If you have questions regarding our use of cookies, contact us:

  • Online inquiry: Contact Us
  • Email: support@shot2ad.com