Cookies and storage we use
Here are the cookies and browser storage Extract.FAST can set, grouped by purpose. Exact names are shown where they help you recognise them.
| Name | Type | Purpose | Duration | Details |
|---|---|---|---|---|
| extract.fast.session | Essential | Keeps you signed in across Extract.FAST (single sign-on) | Up to 365 days, sliding | HttpOnly, Secure, scoped to the .extract.fast domain |
| __Host-fast.csrf | Essential | Protects forms and requests against cross-site request forgery | Session | HttpOnly, Secure, path / |
| Sign-in redirect cookies | Essential | Complete a secure sign-in redirect | Short-lived | Created only during sign-in |
| cookie_consent | Preference | Remembers whether you accepted or declined analytics | Up to 365 days | Set when you make a consent choice |
| Internal traffic suppression | Preference | Excludes internal testing and operational traffic from analytics | Varies | Not set for normal visitors |
| Options panel preference | Preference | Remembers whether your uploader options panel is open | Varies | A small preference cookie |
| Analytics | Analytics | Privacy-first page and event analytics via /p/script and /p/event | No tracking cookie | Uses IP and User-Agent to count visits through our own domain; loads only where consent allows |
| Error diagnostics | Diagnostics | Error reporting and masked session replay on error | Not a marketing cookie | Sensitive fields are scrubbed; on-screen text is masked and media blocked |
Essential cookies
These keep the core service working: signing you in, protecting forms against cross-site request forgery, completing secure sign-in redirects, and protecting your jobs and downloads. They are required, so they are set without asking.
Sign-in and checkout
When you choose to sign in with Google, or pay with Stripe, those providers may set their own cookies on their own surfaces to complete the flow securely. They apply only when you use sign-in or checkout.
Preferences and consent
We remember small choices, such as your analytics consent and your uploader options panel state. Where consent is required, optional analytics does not load unless consent has been accepted. Clearing browser storage can reset local uploader preferences.
Analytics
Analytics is privacy-first and served first-party through /p/script and /p/event on our own domain. It is loaded only where our consent settings allow it: in regions that require consent, analytics is not loaded unless consent has been accepted. Internal testing and operational traffic are excluded. It uses your IP and User-Agent to count visits; it does not build advertising profiles.
Error diagnostics
We use error diagnostics to find and fix problems. This is not a marketing cookie. Diagnostics run with no personal data by default, sensitive fields are scrubbed, and any session replay on error masks all on-screen text and blocks media.
Managing choices
You can clear or block cookies in your browser settings at any time. Blocking essential cookies will break sign-in, security, and checkout. Where consent applies, declining it stops optional analytics from loading.
Frequently Asked Questions
Do you use advertising cookies?
No. Extract.FAST does not use advertising cookies, tracking pixels, or cross-site profiles. The cookies we set are for sign-in, security, your preferences, and — where consent allows — privacy-first analytics.
Why do I not always see a cookie banner?
We only need consent for optional analytics. In regions that require consent, analytics is not loaded unless consent has been accepted; elsewhere essential cookies work without a banner. Essential cookies for sign-in and security do not require consent.
What does /p/script mean?
It is a first-party path on our own domain that serves our privacy-first analytics, with /p/event receiving the analytics pings. Routing analytics through our own domain keeps it first-party; it loads only where our consent settings allow it.