Cookie Policy

Effective Date:

SKRIB, INC.

Cookie Policy

Effective Date: 26 May 2026

1. About this Policy

This Cookie Policy explains how Skrib, Inc. (“Skrib,” “we,” “us,” or “our”) uses cookies and similar technologies on skrib.com, any subdomain of skrib.com, and the related online services (collectively, the “Platform”). It supplements the Privacy Policy at https://skrib.com/legal/privacy.

Where required by applicable law, Skrib will request your consent before using non-essential cookies and similar technologies. You can manage your consent at any time using the “Cookie Settings” link in the website footer.

2. Skrib’s identity

Skrib, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Operational address: 37m I. Chavchavadze Avenue, Axis Business Centre, 0179 Tbilisi, Georgia. Privacy contact: contact@skrib.com.

3. What we mean by “cookies and similar technologies”

Cookies are small text files that are placed on, stored on, or accessed from your browser, device, or application environment when you visit or use a website or online service. In this Policy, the term “cookies and similar technologies” includes session and persistent cookies; local storage and session storage; pixels, tags, and web beacons; scripts and browser-based SDKs; session replay and interaction-monitoring technologies; and server-side tracking arrangements that achieve equivalent purposes.

“Local storage” and “session storage” refer to browser-based key-value storage APIs that allow a website or web application to persist data on your device similarly to a cookie. “Server-side tracking” refers to data-collection arrangements in which Skrib’s server (or a service provider on Skrib’s behalf) communicates directly with an analytics, advertising, or measurement partner using server-to-server APIs. Server-side tracking is treated under this Policy as if equivalent technologies were placed on your device for the same purpose, including for consent purposes where required.

4. Why we use cookies and similar technologies

We use cookies and similar technologies to operate, deliver, and maintain the Platform; enable core technical functions including authentication, session continuity, security, and load balancing; remember your preferences; support billing and fraud prevention; measure traffic and feature usage; analyse performance and reliability; provide customer support; and (where consented) measure marketing effectiveness and support retargeting on marketing pages.

The drafting page, editor, and AI-assisted features themselves do not deploy advertising or marketing cookies, and Skrib does not transmit document content, prompts, AI inputs, or AI outputs to advertising or analytics partners through cookies or pixels.

5. Categories

Strictly necessary.

Required to operate the Platform or to provide services you request. Generally do not require consent under applicable law. Examples: authentication cookies, load-balancing cookies, payment-fraud-prevention cookies.

Functional.

Remember your preferences and provide enhanced functionality. May require consent depending on jurisdiction and on whether they are strictly necessary in context.

Analytics and performance.

Help us understand how the Platform is used and how it performs. Require consent in jurisdictions where consent is required by law.

Session replay and interaction analytics.

Reconstruct user interactions for usability research. Require consent in jurisdictions where consent is required.

Advertising and marketing.

Measure marketing effectiveness, attribute conversions, build audiences. Require consent.

6. Cookie inventory

The cookie inventory below is representative. The live, authoritative inventory is maintained by Skrib’s Consent Management Platform (Cookiebot, by Usercentrics) and rescanned at least monthly across the public website and the logged-in product areas. Where a tool listed here is not yet deployed, it will not be active until deployment is confirmed and (where applicable) consent has been obtained.

__cf_bm — Provider: Cloudflare; Category: Strictly necessary / Security; Area: Site-wide; Duration: 30 minutes; Consent?: No.

cf_clearance — Provider: Cloudflare; Category: Strictly necessary / Security; Area: Site-wide; Duration: Up to 1 year; Consent?: No.

__session — Provider: Clerk; Category: Strictly necessary / Authentication; Area: Logged-in; Duration: 7 days; Consent?: No.

__client — Provider: Clerk; Category: Strictly necessary / Authentication; Area: Logged-in; Duration: Up to 1 year; Consent?: No.

__stripe_mid — Provider: Stripe; Category: Strictly necessary / Payments; Area: Billing / Checkout; Duration: 1 year; Consent?: No.

__stripe_sid — Provider: Stripe; Category: Strictly necessary / Payments; Area: Billing / Checkout; Duration: 30 minutes; Consent?: No.

_ga, _ga_* — Provider: Google Analytics 4; Category: Analytics; Area: Public site; Duration: 2 years; Consent?: Yes.

ph_*_posthog — Provider: PostHog; Category: Analytics; Area: Logged-in; Duration: 1 year; Consent?: Yes.

mp_*_mixpanel — Provider: Mixpanel; Category: Analytics; Area: Logged-in; Duration: 1 year; Consent?: Yes.

amplitude_id_* — Provider: Amplitude; Category: Analytics; Area: Logged-in; Duration: 1 year; Consent?: Yes.

hjSession* — Provider: Hotjar; Category: Session replay; Area: Public / enabled product areas; Duration: 30 mins / 1 year; Consent?: Yes.

_clck, _clsk — Provider: Microsoft Clarity; Category: Session replay; Area: Public / enabled product areas; Duration: 1 day / 1 year; Consent?: Yes.

_dd_s — Provider: Datadog; Category: Performance / Diagnostics (consent-gated); Area: Site-wide; Duration: 4 hours; Consent?: Yes.

intercom-* — Provider: Intercom; Category: Functional / Support; Area: Site-wide / support; Duration: Session / 9 months; Consent?: Yes (unless strictly necessary).

_fbp, fr, _fbc — Provider: Meta Pixel; Category: Advertising; Area: Marketing pages; Duration: 90 days; Consent?: Yes.

bcookie, li_gc, li_sugr, UserMatchHistory, lidc — Provider: LinkedIn Insight Tag; Category: Advertising; Area: Marketing pages; Duration: 24 hours – 1 year; Consent?: Yes.

7. Consent and choice

Where consent is required, Skrib obtains it before placing or accessing non-essential cookies. Skrib’s consent banner is configured so that (i) rejecting all non-essential cookies is achievable in a single click and through a control of equivalent prominence to the “accept all” control; (ii) per-category preferences are available without a forced “all-or-nothing” choice; (iii) no checkboxes are pre-ticked; (iv) access to the Platform is not conditioned on accepting non-essential cookies (no cookie wall); and (v) the consent control is accessible from every page of the Platform via the persistent “Cookie Settings” footer link.

Where you withdraw consent, Skrib will cease the relevant processing without undue delay (and in any event within seven (7) working days for direct-marketing processing under the Georgian DPP Law). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Global Privacy Control (GPC).

Skrib treats a Sec-GPC signal sent by your browser as a valid request to opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising under the California Consumer Privacy Act regulations and analogous U.S. state laws.

Children.

The Platform is not directed to children. Skrib does not knowingly use non-essential cookies or similar technologies to process the personal data of minors without an appropriate legal basis.

8. Browser controls

Most browsers allow you to control cookies through their settings, including by viewing stored cookies, deleting cookies, blocking some or all cookies, and receiving alerts before certain cookies are placed. Browser and device settings may not always control similar technologies such as pixels, scripts, and SDK-based tools.

If you block or disable cookies, some parts of the Platform may not function properly. In particular, login, session continuity, and billing-related features may be affected, and analytics, personalisation, and advertising features will not function.

9. International transfers

Information collected through cookies and similar technologies may be processed by service providers located outside the European Economic Area, the United Kingdom, Switzerland, or Georgia, including in the United States. Where Skrib transfers personal data subject to applicable transfer restrictions, Skrib relies on appropriate safeguards including Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, and (where Skrib has certified) the EU-U.S. Data Privacy Framework. Further detail is at https://skrib.com/legal/subprocessors.

10. Changes to this Policy

Skrib may update this Cookie Policy from time to time to reflect changes in applicable law, in the cookies or technologies used, or in Skrib’s practices. The “Last Updated” date in the metadata header indicates when the Policy was last revised. Previous versions are available via the “See all versions” link on the published page.

11. Contact

Privacy: contact@skrib.com | Data Protection Officer: contact@skrib.com | General legal: contact@skrib.com.