Cookie Policy

Last updated: August 22, 2026

This Cookie Policy explains how SiteLetter (operated by Donatas Petrauskas, individuali veikla, Lithuania, registration number 1534445) uses cookies and similar storage technologies on siteletter.com and app.siteletter.com (the "Service"). It should be read together with the Privacy Policy.

1. What Cookies Are

Cookies are small text files placed on your device by a website you visit. They are widely used to make websites work, or work more efficiently, and to remember information about your session. Similar technologies like Local Storage and Session Storage are also used by modern web applications to store data on your device.

2. What SiteLetter Uses

Every cookie SiteLetter sets is strictly necessary for the Service to function. SiteLetter does not use advertising or any third-party tracking cookies. There is one piece of browser storage that is not strictly necessary: the signup attribution values described in Section 2.5. For anonymous traffic statistics SiteLetter uses Cloudflare Web Analytics and Umami. Neither sets a cookie. See Section 2.4 below.

2.1 Necessary Cookies

  • Sign-in cookie (JWT): Keeps you logged in across siteletter.com and app.siteletter.com. Persists for up to 30 days, or until you log out. Scoped to .siteletter.com, Secure, SameSite=Lax.

2.2 Local Storage

The dashboard uses browser Local Storage to remember interface preferences (for example, whether highlight boxes are shown on a screenshot) and to carry a confirmation message back from checkout. This data lives in your browser only and is never transmitted to SiteLetter's servers for tracking purposes. Local Storage persists until you clear your browser data.

2.3 Third-Party Signup Challenge

SiteLetter's signup form and free public tools embed Cloudflare Turnstile to prevent automated abuse. Turnstile may set short-lived cookies or read browser signals solely to verify that you are not a bot. See Cloudflare's privacy policy for details.

2.4 Cookieless Analytics

SiteLetter uses two analytics tools to understand which pages are visited and where visitors come from: Cloudflare Web Analytics and Umami. Both run on the marketing site only, never inside the app. Both are cookieless by design: no cookies are set, no IP addresses are stored, and no fingerprinting is used. They collect only aggregated, anonymous traffic data (page URL, referrer, campaign tags, country, browser type, device type). Umami counts repeat visits with a hash it computes on its own servers and rotates, not an identifier placed on your device, and SiteLetter's Umami account stores that data in the EU. Because neither sets a cookie, no consent banner is required under ePrivacy Directive Article 5(3). See Cloudflare's Web Analytics documentation and Umami's documentation for details.

Umami reads one key in your browser's Local Storage, umami.disabled, to check whether you have asked it not to count you. It only ever reads that key, and nothing writes it unless you set it yourself, so by default nothing is stored on your device. Section 4 explains how to set it.

2.5 Signup Attribution

When you arrive from a marketing link, the web address often carries campaign tags. SiteLetter copies four of them (utm_source, utm_medium, utm_campaign and utm_content) into your browser's Session Storage when the page loads, so they are still there if you browse a few pages before signing up. Session Storage is per-tab: the values are gone when you close the tab, and a new tab starts fresh.

If you do sign up, those four values are sent along with your signup and stored on your account, so SiteLetter can tell which campaign a signup came from. They are written once and never updated. Nothing else about your browsing is recorded this way, and if you arrive without campaign tags nothing is stored at all.

This is marketing attribution, not something the Service needs in order to work, so it is not strictly necessary storage. Section 4 explains how to clear or prevent it.

3. Consent

SiteLetter does not show a cookie consent banner. Its cookies are limited to strictly necessary session management and the Cloudflare Turnstile anti-bot challenge, and its analytics is cookieless, so under ePrivacy Directive Article 5(3) none of those need your consent.

The signup attribution values in Section 2.5 are the exception. They are not strictly necessary, and they are stored without asking you first. Section 4 covers how to clear or prevent them. Everything on the Service works the same either way.

If SiteLetter ever introduces optional cookies (for example, cookie-based analytics or advertising) it will present a consent banner and will not set them until you opt in.

4. Managing Cookies

Most browsers let you manage cookies from their settings menu. If you disable strictly necessary cookies, the Service will not function correctly. In particular, you will not be able to stay logged in.

The signup attribution values in Section 2.5 sit in Session Storage rather than in a cookie, so clearing cookies alone does not remove them. Closing the tab does. You can also block site data for siteletter.com in your browser settings, or open the site with the campaign tags trimmed off the address. None of this affects how the Service works.

To opt out of the Umami statistics described in Section 2.4, open your browser's developer console on siteletter.com and run localStorage.setItem('umami.disabled', 1). Umami then stops counting you on that browser until you clear site data. Blocking cloud.umami.is in a content blocker has the same effect. Neither changes how the Service works.

5. Contact

Questions about this Cookie Policy? Email SiteLetter at support@siteletter.com.