Cookie policy
This explains the cookies and tags on trygatefold.com and gatefold.ai (including www.gatefold.ai, app.gatefold.ai and preview.gatefold.ai), what each one does, and how to say yes or no. A cookie is a small file a site saves in your browser. A pixel or tag is code from another company that can set cookies and tell that company about your visit.
Effective date: October 10, 2026.
Your choice
On trygatefold.com, a banner asks for your choice when you arrive. Until you choose, only the cookie that stores your choice can be set. Accept turns on the analytics and marketing tags listed below. Reject keeps them off. Closing the banner (×) counts as Reject.
If your browser sends a Global Privacy Control signal, the marketing tags stay off even if you click Accept. Plausible, our cookieless page counter, still runs if you accept. gatefold.ai and www.gatefold.ai load no third-party scripts, whatever you choose.
Cookies the site needs
These cookies keep the sites and sign-in working, and they don't need a yes. The Gatefold app has no remember-me cookie.
| Cookie | Where | What it does | How long |
|---|---|---|---|
| gf_consent | trygatefold.com, gatefold.ai, www.gatefold.ai | Stores your cookie choice, when you made it, and whether your browser sent GPC. First-party. | 1 year. We ask again after 12 months or when this policy changes. |
| __Secure-authjs.session-token | app.gatefold.ai, preview.gatefold.ai | Keeps you signed in. HttpOnly, SameSite=Lax. | 30 days. Rolls forward while you use the app, refreshed at most once every 24 hours. |
| authjs.csrf-token, authjs.callback-url | app.gatefold.ai, preview.gatefold.ai | Protects sign-in and sends you back to the right page | Short-lived. Ends when you close the browser. |
| authjs.state, authjs.pkce.code_verifier, authjs.nonce | app.gatefold.ai, preview.gatefold.ai | Used only while you sign in with Google or Microsoft | About 15 minutes |
| gatefold.signin.continue | app.gatefold.ai, preview.gatefold.ai | Links an email sign-in link to your browser | 20 minutes. Deleted after use. |
| gatefold.email.confirm | app.gatefold.ai, preview.gatefold.ai | Links the confirm-your-email step to your browser | Up to 24 hours. Deleted after use. |
| gf_buffer_oauth | app.gatefold.ai, preview.gatefold.ai | Used only while you connect a Buffer account | 10 minutes |
| gf-last-workspace | app.gatefold.ai, preview.gatefold.ai | Remembers your last workspace when you switch | 2 minutes |
If you reject, trygatefold.com and gatefold.ai may also save a small note in your browser's storage (plausible_ignore, not a cookie) so Plausible doesn't count your visit. You can block the cookies above in your browser, but sign-in may stop working.
Analytics
If you accept, Google Analytics 4 loads on trygatefold.com and sets its own cookies (such as _ga and _ga_<ID>) to count visits and show us how people use the site. Google uses what it collects under its own privacy policy. Plausible also loads there and counts pages without cookies. If you reject, neither loads. On gatefold.ai, Plausible is set up but not loaded.
Inside the app, we use our own first-party analytics (PostHog). It sets no cookies and identifies you by an internal account ID, not your email.
Marketing
These load only on trygatefold.com, only after you accept, and stay off with GPC: the Meta Pixel, the TikTok Pixel, the LinkedIn Insight Tag and HubSpot's tracking code. They measure which ads and pages bring people to Gatefold. Meta, TikTok and LinkedIn also use them to build ad audiences and show our ads to people who might want Gatefold. Each company sets its own cookies (for example _fbp and _fbc for Meta, _ttp and ttcsid for TikTok, li_fat_id for LinkedIn, and hubspotutk and __hstc for HubSpot) and decides how long they last. You can manage how Meta uses your activity for ads at https://www.facebook.com/adpreferences.
When you click one of our ads, the platform adds a click ID to the link (fbclid, ttclid, li_fat_id or gclid), and we add campaign tags. These aren't cookies. If you join the waitlist, they're sent with your signup to HubSpot as signup attribution, even if you rejected cookies. To opt out of their use for ads or to have them deleted, use the Do not sell or share my personal information link or email privacy@gatefold.ai. See Privacy.
Changing your choice
Cookie settings at the bottom of every page reopens the banner, so you can change your answer anytime. If you switch from Accept to Reject on trygatefold.com, the tags stop right away, we tell Meta, TikTok and HubSpot that consent was withdrawn, and we clear their cookies on our site where your browser lets us. On gatefold.ai, Reject clears common Google, Meta, HubSpot, LinkedIn and Bing cookies. Cookies those companies set on their own domains can only be cleared in your browser settings.
Meta, TikTok, LinkedIn and Google also offer ad settings in your account with them. For Meta, go to https://www.facebook.com/adpreferences. To opt out of selling or sharing, use the Do not sell or share my personal information link at the bottom of every page.
How long the choice lasts
We keep your consent record (your choice, when you made it, the policy version, and whether your browser sent GPC) for 12 months. After 12 months, or when this policy changes, we ask again.
© 2026 Gatefold LLC.