Cookie Policy

Effective date: September 1, 2026

This Cookie Policy explains which cookies UseSketch sets when you use the service and why.

Cookies we use#

UseSketch sets exactly two cookies. Both are strictly necessary to sign in and keep you signed in. The product sets no analytics, advertising, or third-party tracking cookies.

Cookie namePurposeLifetime
better-auth.session_tokenKeeps you signed in between requests.7 days
better-auth.session_dataA short-lived cache of your session so that not every request has to query the database.5 minutes

Both cookies are HttpOnly and use SameSite=Lax. In production, better-auth.session_token is also marked Secure and its name is prefixed with __Secure-.

HttpOnly means JavaScript running in the page cannot read them. SameSite=Lax means they are not sent when another site makes a background request to us. Secure means they are only ever sent over HTTPS.

Neither cookie contains your name, your email address, or anything about what you have generated. The session token is an opaque identifier that points at a session record on our side.

What we do not set#

There is no analytics on this product. No Google Analytics, no product analytics SDK, no advertising pixel, no session recording, no A/B testing cookie, and no social media widget.

UseSketch also does not store anything in your browser's localStorage or sessionStorage. The two cookies above are the whole of what we keep on your device.

Because we set no tracking cookies, there is nothing here for you to opt out of.

One thing to be aware of: when you buy credits, the payment page is loaded from our payment gateway inside a frame on our site. Anything that page stores in your browser is set by the gateway, for its own checkout and fraud checks. It is not ours, we cannot read it, and it is not covered by this policy.

What happens if you block them#

You can browse the public pages of the site with cookies blocked. The marketing pages, the pricing information and these policy pages all work.

You cannot sign in. Signing in is what sets better-auth.session_token, and without it every request looks like a new anonymous visitor. In practice you will appear to sign in successfully and then immediately be treated as signed out. Since your credits, your generations and your projects all belong to an account, none of the product is usable in that state.

Blocking only third-party cookies is fine. Ours are first-party cookies, set by this site.

How to clear cookies#

You can view and delete cookies through your browser settings. The exact steps vary by browser:

  • Chrome: Settings, then Privacy and security, then Cookies and other site data.
  • Firefox: Settings, then Privacy & Security, then Cookies and Site Data.
  • Safari: Settings, then Privacy, then Manage Website Data.
  • Edge: Settings, then Cookies and site permissions, then Manage and delete cookies and site data.

In every browser you can also clear cookies for this site alone by opening the padlock or site-information icon in the address bar while on this site, and using the cookies or site data option there.

Clearing the cookies for this site removes your session and signs you out. It deletes nothing on our side: your credits, generations and projects are all still there when you sign in again.

Signing out from within the app does the same thing more cleanly, and also ends the session on our server rather than only in your browser.

Changes to this policy#

If we add a cookie, we will list it in the table above and change the effective date. If we ever add a cookie that is not strictly necessary, we will ask for your consent before setting it.

Contact#

This service is operated by DIGIWEB SOLUTIONS LTD, registered in England and Wales under company number 16726411, at Suite 6038, 128 Aldersgate Street, Barbican, London, England, EC1A 4AE.

Questions about this policy? Contact support. See also the Privacy Policy, which covers everything else we hold about you.

Other legal documents

Questions about this policy? Contact support.