---
title: "Cookie Policy | GanttFather"
description: "GanttFather Cookie Policy. Learn what cookies and local storage we use, for what purpose, and how to manage your preferences."
canonical: "https://ganttfather.com/cookies/"
locale: "en"
category: "product"
---

# Cookie Policy | GanttFather

# Cookie Policy

 Last updated: July 7, 2026

 This Cookie Policy explains how GanttFather uses cookies, similar tracking technologies, and browser storage (localStorage, sessionStorage, IndexedDB) on the Website and in the Service. Read this Policy together with our [Privacy Policy](https://ganttfather.com/privacy/).

## 1. What are cookies?

 Cookies are small text files that a website places on your device to remember preferences, keep you signed in, and measure usage. Similar technologies include localStorage and sessionStorage, which are stored in the browser, and pixels or beacons embedded in pages. In this Policy we refer to all of them as cookies.

## 2. Categories we use

 Expand each category to see the exact storage entries, providers, and durations.

 Strictly necessary Always on

 Required to deliver the Service you requested. Without them, sign-in, security checks, and core features would not work. No consent is required under GDPR because they are exempt.

 Storage Provider Purpose Duration

 firebaseLocalStorageDb (IndexedDB) Identity provider Keeps you signed in and stores your refresh token. Until sign-out

 CF_Authorization Edge / zero-trust access provider Protects private admin interfaces with zero-trust auth. Session / up to 24h

 __cf_bm, cf_clearance Cloudflare Bot management, challenge verification, and DDoS protection. 30 min - 1 year

 ganttfather:consent (cookie, .ganttfather.com) GanttFather Stores your cookie-preference choice so we do not ask again. Shared across the marketing site and app so your choice is honored in both places. 12 months

 ganttfather:ui:* (localStorage) GanttFather Stores UI preferences such as language, view mode, and column widths. Until cleared

 Functional Always on

 Storage Provider Purpose Duration

 i18nextLng (localStorage) GanttFather Remembers your selected language. Until cleared

 MCP OAuth state (sessionStorage) GanttFather Provides CSRF protection during the AI-agent authorization flow. Until the flow completes

 Diagnostics Consent required

 These help us reproduce crashes and improve reliability. We only set them if you accept the cookie banner, and you can change your choice at any time.

 Storage Provider Purpose Duration

 sentryReplaySession (sessionStorage) Error diagnostics provider Records a sampled session replay (10% of sessions, 100% on error) to diagnose bugs. Text inputs are masked by default. Until tab closes

 Performance tracing IDs Error diagnostics provider Measures performance so we can identify slow endpoints. Per request

 Analytics Consent required

 We use Google Analytics 4, a Google service, to understand which pages and features are used so we can improve the product. These cookies are set only if you accept the cookie banner, and you can withdraw at any time. Analytics is configured for measurement only: Google Signals and advertising personalisation are turned off, so your data is not used to target ads, and we never send your name or email to Google.

 Cookie Provider Purpose Duration

 _ga Google Analytics Distinguishes visitors with a pseudonymous ID to measure usage. Up to 13 months

 _ga_<stream> Google Analytics Persists session state for a specific GA4 data stream. Up to 13 months

 _gid Google Analytics Distinguishes visitors. This is a legacy, short-lived cookie. 24 hours

 Analytics data is processed by Google in the United States under the EU-US Data Privacy Framework, and we retain event and user data for 14 months. Declining, or sending a Global Privacy Control signal, means no Google Analytics cookie is ever set. See our [Privacy Policy](https://ganttfather.com/privacy/) for the full processor list.

## 3. Managing your choices

- Use the Cookie preferences link in the footer to review or change your choice at any time.
- Most browsers let you block or delete cookies in their settings. Blocking strictly necessary cookies will break sign-in and core features.
- On the Website, declining optional cookies keeps diagnostics and analytics off for your session.
- You can also opt out of session replay at any time from your account settings once signed in.

## 4. Do Not Track

 We respect the Global Privacy Control (GPC) signal and treat it as a withdrawal of consent for optional cookies. Older browser Do Not Track headers are no longer maintained by a standards body; we currently do not act on them specifically, but GPC provides equivalent coverage.

## 5. Changes to this Policy

 We update this Policy when our cookie usage changes. Material changes are shown via the cookie banner on your next visit.

## 6. Contact

 Questions: support@ganttfather.com.

 *This document is provided for informational purposes. It reflects GanttFather's current cookie usage and is not legal advice. Consult qualified counsel for regulatory compliance.*
