1. What cookies are
Cookies are small text values stored by a browser and returned with later requests. First-party cookies are created for the site you visit; third-party services may create their own cookies on their domains.
2. Cookies PublishYourSaaS uses
| Cookie | Purpose | Type | Typical duration |
|---|---|---|---|
| sessionid | Links your browser to the server-side Django login session and temporary OAuth state. | Strictly necessary, first party, HttpOnly | Up to 14 days, or until logout/deletion |
| csrftoken | Lets the frontend attach a security token that protects state-changing requests from cross-site request forgery. | Strictly necessary, first party | Approximately one year |
These durations reflect the application's current Django settings and may be shortened by logout, browser controls, or operational changes.
3. Google and GitHub sign-in
Starting sign-in creates security state in the server-side session and redirects you to Google or GitHub. The selected provider may use cookies on its own domains to authenticate you, remember your provider session, prevent fraud, and present consent. The provider controls those cookies under its own policies.
After the callback, PublishYourSaaS stores a local account and uses thesessionid cookie to recognize your authenticated browser. The cookie contains an opaque identifier, not your profile information. We do not receive your Google or GitHub password and do not persist provider access or refresh tokens.
4. Checkout and external services
If you choose a paid plan, you are redirected to Whop. Whop may use cookies on its domains to operate checkout, prevent fraud, and remember preferences. Those cookies are controlled by Whop rather than publishyoursaas.com.
5. No analytics or advertising cookies
The current application does not install analytics, advertising, remarketing, or social-media tracking cookies. It also does not store authentication data in localStorage or sessionStorage.
6. Managing cookies
Browser settings can display, block, or delete cookies. Blockingsessionid or csrftoken will prevent Google or GitHub sign-in, authenticated dashboard access, or protected actions from working correctly. You can also clear the authenticated session by signing out.
Questions can be sent to publishyoursaas@gmail.com.