SetForth
Features Use cases Integrations Pricing Docs Blog
Sign in Start free →

SetForth Cookie Policy

Last updated: August 30, 2026

This Cookie Policy explains how SetForth LLC ("SetForth," "we," "us") uses cookies and similar technologies on our website and platform at setforth.app (the "Service"). It supplements our Privacy Policy.

1. What are cookies?

Cookies are small text files placed on your device when you visit a website. Similar technologies (such as local storage, pixels, and software development kits) perform comparable functions. We refer to all of these as "cookies." We use both session cookies (deleted when you close your browser) and persistent cookies (which remain until they expire or are deleted), and both first-party cookies (set by us) and third-party cookies (set by our providers).

2. Categories of cookies we use

  • Strictly necessary. Required to operate the Service and provide features you request, such as authentication, maintaining your signed-in session, security, load balancing, and remembering your cookie choices. These cannot be switched off through our consent tools, and the Service will not work properly without them.
  • Analytics / performance. Help us understand how the Service is used so we can measure and improve it (for example, which pages and features are used, and which channels bring people to us). These are non-essential and are used only with your consent where required. On our marketing site, this category also covers a short record of how you first arrived during your current visit, described under "How we record where sign-ups come from" below. Accepting this category also enables the Google Ads and Meta advertising measurement on our marketing site, described under "How we measure our advertising" below.
  • Functional. Enable optional features you choose to use, such as our customer-support live chat. These are non-essential and are used only with your consent where required.

We use advertising-measurement cookies from Google and Meta on our marketing site for one purpose: measuring whether a click on one of our ads led someone to start a sign-up. Neither is loaded until you accept, and we do not sell information collected through cookies. The two providers differ in what they are permitted to do with what they receive, so we describe each of them, and the limits we place on each, under "How we measure our advertising" below.

3. Cookies we use

The table below describes the main cookies we use. Specific names and durations may change as the Service evolves.

Cookie / technologyProviderPurposeCategoryDuration
wos-sessionSetForth (via WorkOS)Maintains your authenticated, signed-in sessionStrictly necessarySession
cookie-consentSetForthStores your cookie consent choicesStrictly necessary12 months
sf_attrSetForthCarries the campaign parameters and referring site of a sign-up you have started, so the new account can be attributed to where it came fromStrictly necessary30 minutes
view_* (for example, view_projects)SetForthRemembers your grid or list view preference for a pageStrictly necessarySession
theme (browser local storage)SetForthRemembers your light or dark theme preferenceStrictly necessaryUntil cleared
amplitude_id, AMP_* (cookies and browser local storage)AmplitudeProduct-usage analytics (device and session identifiers)AnalyticsUp to 13 months
sf_attr (browser session storage on our marketing site)SetForthRemembers how you first arrived during this visit, so a sign-up later in the same visit is attributed to itAnalyticsCurrent browsing session
_gcl_awGoogleGoogle Ads conversion measurement: records that you reached us from one of our ads, so a later action on our marketing site can be counted against that adAnalyticsUp to 90 days
_fbpMetaMeta advertising measurement: identifies your browser to Meta, so that clicking Start free on our marketing site can be counted against one of our Meta adsAnalyticsUp to 90 days
_fbcMetaMeta advertising measurement: records the identifier of the Meta ad click you arrived fromAnalyticsUp to 90 days
Stripe payment cookiesStripePayment processing and fraud prevention on billing pagesStrictly necessarySet by Stripe (session and persistent)
crisp-client/* (cookies and browser local storage)CrispCustomer-support live chat session on our websiteFunctionalUp to 6 months

How we record where sign-ups come from

The sign-up attribution cookie (sf_attr). When you actively begin creating an account, we set a first-party sf_attr cookie on the platform to hold the campaign parameters (for example, utm_source, or an ad click identifier such as gclid or fbclid) and the referring site of the link you followed. Our sign-in provider's hosted pages sit in the middle of that flow and would otherwise discard them. The cookie is HttpOnly, so it cannot be read by scripts in your browser; it expires after 30 minutes, and it is deleted as soon as the sign-up flow finishes, whether or not the account was created. It is used solely to attribute that one new account to the channel it came from, never to track you across websites or across visits. If you reach us with no campaign parameters and no referring site, no such cookie is set.

The referring site is a hostname only. Wherever we record where you came from — the cookie above, the session record described below, and the analytics event for a new account — we keep only the hostname of the referring site (for example, news.ycombinator.com). We never record the full referring URL, its path, or its query string.

Our marketing site stores nothing until you accept analytics cookies. If you have declined analytics cookies, or have not yet answered the banner, our marketing site writes nothing to your device — no cookies, no local storage, and no session storage — other than recording your cookie choice itself once you make one. If you accept analytics cookies, we keep a first-touch record in your browser's session storage holding the campaign parameters and referring hostname from the page you first landed on. It stays on your device for that browsing session only, is cleared when you close the tab or browser, is readable only by our own site, and is not shared with any third party.

How we measure our advertising

The Google Ads conversion cookie (_gcl_aw). We advertise SetForth, and we need to know whether those ads bring anyone to us. If you accept analytics cookies on our marketing site, Google's tag stores the identifier of the ad click you arrived from in a _gcl_aw cookie, so that an action you take afterwards on the same site — clicking Start free — can be counted against that ad. We run it in measurement mode only: ad personalization is disabled, so we do not build advertising profiles, and neither the cookie nor the tag is used to track you across other websites.

The tag loads in a consent-denied state. Google's tag script may load before you answer our cookie banner, so a request to googletagmanager.com can appear in your browser's network tools at that point. It starts with advertising and analytics storage set to denied, which means it writes no cookies and sends no advertising signals to Google before you accept. If you decline, or simply never answer, it stays denied and no _gcl_aw cookie is set.

The Meta pixel (_fbp, _fbc). We also advertise on Meta's platforms, including Instagram and Threads. If you accept analytics cookies on our marketing site, Meta's pixel loads and sets a _fbp cookie identifying your browser, and a _fbc cookie if you arrived from one of our Meta ads. It reports two things to Meta: that you viewed a page, and that you clicked Start free.

How the pixel differs from the Google tag, and what we do about it. Unlike the Google tag above, Meta may use these events for its own advertising purposes, including associating them with your Meta account. We limit this in two ways. First, unlike the Google tag, the pixel is requested only after you accept analytics cookies: if you decline, or never answer the banner, no request is made to Meta at all, and no _fbp or _fbc cookie is set. Second, we enable Meta's Limited Data Use mode, which restricts Meta's processing of data about visitors covered by U.S. state privacy laws to a limited set of permitted purposes. We do not use the pixel to build remarketing or advertising audiences, and we do not upload customer lists to Meta. Meta's own handling of data it receives is governed by Meta's terms and privacy policy.

We do not run a no-script tracking pixel. Meta's standard installation instructions include an image tag that fires for every visitor whether or not they have consented. We deliberately leave it out, so there is no path by which the pixel can report anything before you accept.

4. Your choices

Consent and preferences. Where required by law (for example, in the EEA and UK), we ask for your consent before setting non-essential cookies, and you can accept or reject categories of cookies through our cookie banner and preferences tool. You can change your choices at any time through the "Cookie Preferences" control available in the Service. In regions that operate on an opt-out basis, you may opt out of non-essential analytics through the same control.

Global Privacy Control. Where required, we treat a recognized opt-out preference signal (such as Global Privacy Control) sent by your browser as a valid opt-out of non-essential cookies and of any "sale" or "sharing" of personal information.

Browser controls. Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies may cause parts of the Service to stop working.

5. Changes to this Cookie Policy

We may update this Cookie Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, obtain renewed consent.

6. Contact

Questions about this Cookie Policy: privacy@setforth.app · SetForth LLC.

More legal documents

  • Terms of Service
  • Privacy Policy
  • Acceptable Use Policy
  • Refund & Billing Policy
  • Subprocessor List
  • Security Overview
  • DPA
SetForth

Set forth your vision. Agents handle the rest, and keep the receipts.

sales@setforth.app
Product
FeaturesUse casesPricingDocumentationBlog
Legal
Terms of ServicePrivacy PolicyCookie PolicyOther policiesCookie preferences
© 2026 SetForth LLC Set forth your vision. Agents handle the rest.