Skip to main content
Decision Lab
Guides ⌄
Start hereAll guidesReal journeysCase studies
IngredientsUI examplesPricing
Sign in

Product

01Decision Lab02Guides03Case studies04Ingredients05UI examples06Pricing
Sign in →

Cookies,
clearly.

Last updated 29 August 2026. You can use the site whether you accept or reject analytics cookies.

Your choice

Essential cookies support security, account sessions, checkout continuity and your cookie preference. They cannot be switched off through this control because the service relies on them. Analytics cookies are optional and are not set until you accept them.

Essential cookies

CookiePurposeTypical duration
uxo_cookie_preferencesStores whether you accepted or rejected analytics cookies.6 months
uxo_analytics_exclusionRecords that an authorised owner or test browser profile must not contribute to analytics. It contains only a fixed exclusion value and is not a device identifier.Up to 13 months; removable in Account
sb-…-auth-tokenStores the Supabase account session needed after Google or email access. It also supports the one-use Supabase PKCE handoff used by email and the retained Google rollback route. The session can include the basic linked identity metadata described in our Privacy notice; Google provider access credentials are not retained. The name varies with the project and may be split across cookies.A returned verifier is removed when our callback exchanges or rejects its code. If a Supabase handoff is cancelled or abandoned before a code returns, its verifier can remain for up to 400 days. The account session lasts up to its configured lifetime.
__Host-uxo_google_direct_…Binds one Google attempt to this browser using a one-use security state, nonce, PKCE verifier, safe return destination and creation time. It is host-only, HttpOnly and Secure. SameSite=None is required because Google returns the result as a cross-site form post, keeping the code out of the URL.Up to 10 minutes; the matching cookie is removed after success, refusal or a returned failure. An abandoned attempt expires.
uxo_auth_confirmationBinds the deliberate email confirmation form to the one-time action and this browser.Up to 10 minutes; removed after the confirmation succeeds or fails
uxo_new_account_preferencesBinds the short optional preference step to the newly verified email account, safe destination and this browser. It does not record whether you chose email notes.Up to 10 minutes; removed when the preference step is submitted
Google cookies on Google pagesIf you choose Google account access, Google may use its own account and security cookies during that external handoff.Set by Google according to its service
Stripe cookies on Stripe pagesFraud prevention, secure Checkout and Billing Portal operation.Set by Stripe according to its service

Google account access is separate from Google Analytics and remains available whether you accept or reject optional analytics cookies.

On-device Decision Lab drafts

When a signed-in member starts a new Decision Lab brief, the unfinished answers can be kept in this browser’s local storage so the same account can recover them. This is essential on-device storage rather than an analytics cookie, so it does not depend on your analytics choice. The key uses a server-generated opaque account scope: it contains no email address, name or sign-in method. Linked Google and email access to the same Supabase account use the same scope; a different account cannot address that draft.

Every draft read, write and removal uses the browser’s exclusive lock for that opaque account scope and checks the exact random revision. If that coordination is unavailable, Decision Lab does not read, write or remove a browser draft, but you can still create a brief. A valid submission also puts a one-use random marker and the submitted draft’s revision in that tab’s session storage under the same opaque account scope. The success response carries the marker value in its fragment, which is not sent with later server requests. Cleanup first consumes the matching marker, then removes only a draft with the exact submitted revision. An ordinary visit, copied URL, duplicated tab, replay or later edit therefore cannot remove unrelated work. The random values contain no raw account or brief details. They are removed after matching cleanup, when that account returns to the new-brief form, or when the tab closes.

A draft expires seven days after its latest edit. The application removes it when that account next opens Decision Lab after expiry, when a matching successful same-tab creation response is verified or when the member chooses Discard. Clearing this site’s browser data also removes it. If browser storage or the required lock is unavailable, an already stored draft remains until its normal expiry or site-data clearing. Because a closed browser cannot run expiry code, an expired item can remain physically in local storage until the same account returns or site data is cleared, but the application will not restore it.

A draft saved by the older shared-key version is quarantined. The current application does not read, parse, copy, migrate or delete that value. It may remain until site data is cleared or a separately reviewed no-read cleanup is approved. Decision Lab answers, the opaque account scope and the one-use marker are not sent to analytics or included in application logs.

Analytics cookies

If you accept, The UXologist may set two first-party analytics cookies. uxo_analytics_id distinguishes this browser in aggregate journeys; it expires no later than 13 months after your first consent and is not renewed on repeat visits. uxo_analytics_session groups consented activity into a visit; it expires 30 minutes after the latest accepted event and is renewed only after our server has checked that event. We do not load a Google tag in your browser.

Your browser sends approved on-page events to The UXologist. Our server checks them against a fixed list before relaying them to Google Analytics and setting or renewing the session cookie. Successful account, brief, bookmark and Checkout events are sent directly from the confirmed server action rather than accepted from the browser relay. If the analytics service is not fully configured, no analytics cookie is set and no event is sent.

What we measure

For public pages, we measure fixed groups such as Home, About, Ingredients, UI examples, case studies, Books, Pricing, Decision Lab, legal information and Sign in. Detail-page views keep generic page labels. A separate content event includes only a stable public editorial identifier such as ingredient:choice-architecture, its content type and whether the content is public or member-only. This allows aggregate popularity reporting without sending the browser URL, displayed title or a private record identifier.

We measure the session number and the visible time since the previous approved event so Google Analytics can report consented visits, active users and engagement. Hidden-tab time is not counted. We may measure successful magic-link account creation or sign-in; successful brief starts and first completions with Free or Practitioner access; successful Ingredient saves; a previous brief reopened as draft or completed; and a share link successfully copied. These events do not contain the account, Ingredient name, brief, share link or private work.

We also measure whether one of five membership prompts was shown or selected, with signed-out, Free or Practitioner access. On Pricing, we may measure the fixed Practitioner options being viewed or selected and a Checkout start only after Stripe creates a valid Checkout Session; the event includes the monthly or annual interval, published numeric GBP price and fixed plan item. Stripe—not Google Analytics—remains the source of truth for purchases and revenue. In Workbench and Saved material, we may measure Free or Practitioner access and coarse bands—0, 1, 2–5 or 6+—for the number of briefs or saved items.

We do not send a general page-view event, route, URL or title when Workbench or Saved material opens; only the coarse opening event described above. We do not send account identifiers, profile or billing details, Decision Lab content or identifiers, saved-item names, form text, exact counts, raw URLs, referrers, query strings, fragments, payment details, addresses, tax information, purchase events or subscription-lifecycle events.

Google Analytics data

Google receives only the pseudonymous browser identifier, short-lived session number, measured visible engagement interval and controlled event fields relayed by our server. These fields can show an allowlisted public page group, a public editorial content identifier or the fixed interactions described above. Google does not receive a direct request containing your browser IP, browser or device details, referrer, query string, fragment, displayed content title or private content identifier. We disable Google Signals, advertising personalisation, remarketing, demographics, granular location/device collection and Ads linking.

User- and event-level data is retained for 14 months without resetting the period on new activity. Standard aggregate reports may remain for longer. We do not initially use a raw-data or BigQuery export.

Changing your choice

Use Manage cookies at any time. Rejecting analytics stops further collection and, where an Analytics browser identifier exists, asks Google’s user-deletion service to delete its associated user- and event-level data. When Google confirms the request, we remove the identifier from this browser.

If the request fails, analytics remains off and we keep the identifier only so you can retry: open Manage cookies and reject analytics again. The cookie message also explains how to contact us. We remove the identifier after a successful request; otherwise it still expires no later than 13 months after your first consent. Aggregated statistics that no longer identify the browser may remain.

Owner and test browser exclusion

An authorised administrator can exclude the current browser profile from analytics in Account. Enabling the exclusion rejects optional analytics, expires the analytics session, blocks browser and confirmed server events before new analytics state is created, and uses the same deletion process for any existing pseudonymous identifier.

The exclusion applies only to that browser profile. It does not identify or cover every browser on a physical device, and we do not use fingerprinting to create that link. Removing the exclusion leaves analytics rejected until a separate choice is made through Manage cookies.

Start with the decision

Turn product friction into something you can test.

Try the Decision Lab
The UXologist

Evidence-informed psychology for clearer product decisions.

ExploreGuides for product decisionsBlog and product notesBehavioural psychology ingredientsUI examples from real productsProduct psychology case studiesOnboarding psychology guideUX psychology evidence mapBooks and readingAbout and editorial method
Use The UXologistDecision LabMembership pricingWorkbenchAccount
Policies and controlsPrivacyCookiesTermsCancellation
© 2026 The UXologistUse psychology responsibly.

Cookies on The UXologist

We use essential cookies to make The UXologist work.

We’d also like to use analytics cookies so we can understand how people use the site and make improvements.

View cookies