Cookie Policy
Last updated: 2026-08-15
Referral attribution begins only when you deliberately open an eligible referral link. Customers who do not participate are unaffected.
1. What cookies and local storage are
Cookies are small files a website asks your browser to store so it can remember things between page loads — your login session, a language preference, an analytics identifier. Local storage is a similar mechanism that lives in your browser and stays until you clear it. Both are controlled by the origin that sets them (e.g., display.dev cannot read storage that dsp.so set). This policy describes every cookie and local-storage key set by the display.dev surfaces listed below.
2. Surfaces this policy covers
- display.dev — our marketing site, documentation, pricing pages, and legal pages.
- api.display.dev — our application API, including referral attribution.
- dsp.so — the domain we serve publicly-viewed published artifacts from.
Owned or private artifacts viewed by authenticated org members inside the app (app.display.dev) are covered by the main Privacy Policy.
One exception: the consent-gated advertising and measurement tags in section 7 run on app.display.dev as well as display.dev, because a signup completes inside the app. Section 7 is the full inventory for those tags on both domains.
3. Strictly necessary – display.dev and api.display.dev
These are required for the site to work and do not require consent.
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
displaydev_cookie_consent | localStorage | display.dev | Records your Accept / Decline choice | Until cleared |
dsp_consent | cookie | display.dev | Mirrors your Accept / Decline choice so our servers can honor it (browser storage is not visible server-side) | 12 months |
theme | localStorage | display.dev | Remembers light / dark mode preference | Until cleared |
dsp_ref | HTTP-only cookie | api.display.dev | Preserves the first eligible inviting organisation while you create a genuinely new organisation through a referral link. It contains only a signed organisation identifier and expiry, never a member ID, name, or raw referral code | 30 days, or until successful organisation creation |
__cf_bm | cookie | Cloudflare | Bot management / DDoS protection | 30 minutes |
dsp_ref is set only after an eligible referral link is opened. It is required
to keep referral attribution consistent through signup, so it does not depend
on analytics consent. Later referral links do not overwrite a valid first-touch
cookie. Successful organisation creation clears it.
4. Strictly necessary — dsp.so
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
__cf_bm | cookie | Cloudflare | Bot management / DDoS protection | 30 minutes |
5. First-party signup attribution — display.dev
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
dsp_acq | cookie | display.dev | Remembers how you first arrived (referring site's hostname, landing page path, and any utm_* campaign parameters) so that, if you later create an account, we can ask "How did you find display.dev?" alongside that context | 30 days |
dsp_acq is a first-party attribution cookie, not advertising or cross-site tracking. It is set on your first visit only when the visit carries a signal (campaign parameters, an external referrer, or a non-homepage landing page), and never contains identifiers, full URLs, or query strings. It is deleted as soon as you answer or skip the post-signup question, and it expires on its own after 30 days. Its contents are not sold, not used for advertising, and not shared beyond the sub-processors that run our product analytics (see the Privacy Policy §5).
If you decline analytics consent in the cookie banner, we stop setting dsp_acq and delete any existing copy on your next page load. Declining does not affect anything else on the site.
6. Analytics — display.dev (requires consent)
Loaded only if you click Accept in the cookie banner. If you decline, we do not initialise PostHog and no analytics events are sent.
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
ph_<projectKey>_posthog | localStorage | PostHog | Distinct visitor id + session metadata | Until cleared |
We configure PostHog with persistence: 'localStorage', so it does not set any ph_* cookies. If you capture a cookie with a ph_ prefix on display.dev, that is a configuration regression — please email privacy@display.dev so we can fix it.
PostHog on display.dev also performs session replay when you accept the cookie banner. Replay captures mouse movements, clicks, scroll position, and page structure via PostHog's rrweb-based session replay, plus browser console logs. Form input values are masked in the browser before transmission. Recordings are retained for 30 days. The same mechanism runs inside the authenticated product (app.display.dev) on a legitimate-interest basis — see the Privacy Policy §1 and §4 for full details and opt-out.
7. Advertising and conversion measurement — display.dev and app.display.dev (requires consent)
We buy ads on Google and Reddit. These tags tell us which ads led to an account being created, so we can stop paying for the ones that don't work. They are loaded only if you click Accept in the cookie banner. If you decline, they do not run and no advertising identifier is set or sent.
Every optional tag on display.dev and app.display.dev is loaded through a single Google Tag Manager container. Google Tag Manager sets no cookies of its own — it decides which of the tags below are allowed to run. Before any tag loads, we set Google Consent Mode v2 to denied by default, so nothing fires while the banner is still unanswered.
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
_ga, _ga_<streamId> | cookie | Google Analytics 4 | Distinguishes visitors and sessions for aggregate traffic reporting | 2 years |
_gcl_au | cookie | Google Ads | Links an account signup back to the Google ad click that led to it | 90 days |
_rdt_uuid | cookie | Reddit Ads pixel | Links an account signup back to the Reddit ad that led to it | 90 days |
What these measure. Two things: that a page was viewed, and that an account was created. The signup signal carries no name, email address, or artifact content — only the fact that a signup happened and which login method was used. We do not upload customer lists, email addresses, or hashed email addresses to any ad platform.
Where they run. Google Tag Manager and the tags above are present on display.dev and app.display.dev. They are not present on dsp.so — published artifacts are never used for ad measurement (see section 8).
What you consent to. Accepting the banner allows Google and Reddit to set the cookies above and to use them to attribute a signup to an ad click on their own platforms. Both act as independent controllers for that attribution. Their own policies apply: Google and Reddit.
Why you were asked again. If you had already answered the banner before 29 July 2026, you answered it when this page listed no advertising tags. That answer does not carry over to the tags in this section, so we reset the banner and asked everyone again. Nothing in this section runs until you answer it.
If you decline, or if you later switch from Accept to Decline, these tags stop running. Google's tags continue to report traffic in a cookieless, aggregate-only mode that sets no identifier in your browser; the Reddit pixel does not load at all. Switching to Decline stops any further collection, but does not delete cookies already stored in your browser — clear those through your browser settings (section 12) if you want them gone immediately.
8. Analytics — dsp.so
We run no third-party client-side analytics on dsp.so. We do record two things server-side, without cookies, to operate the service:
- Aggregate view counts. Per-artifact daily view buckets so publishers can see how many people read what they published. No viewer identity is stored.
- Publish-to-claim funnel telemetry. For publicly-claimable artifacts we record the first and second distinct hashed IP (hashed with a server-side secret before anything is persisted) so we can measure whether viewers actually claim the URL. Exactly two events per artifact, then no further tracking.
Both streams are processed server-side on a legitimate-interest basis under GDPR Art. 6(1)(f) — pseudonymised inputs, capped scope, no identifying data stored in your browser. If you want us to purge funnel records associated with your IP, email privacy@display.dev.
9. Publisher-authored content on dsp.so
Artifacts published to dsp.so may include third-party scripts chosen by the publisher — charting libraries from a CDN, embedded widgets, their own analytics. display.dev does not modify, block, or insert consent UI into publisher-authored content. If a specific artifact's scripts concern you, contact the publisher.
When we add any of our own third-party client-side script to a dsp.so response in the future, we will ship a dsp.so-side consent banner alongside that change and update this page.
10. How to change your choice on display.dev
Click Cookie settings in the footer of any display.dev page. The banner will reappear and you can accept or decline again. Your choice applies to app.display.dev too, so you do not have to answer twice.
Switching from Accept to Decline clears the PostHog distinct id from this browser and stops the advertising and measurement tags in section 7 from running again. Cookies those tags already set are not deleted by the switch — clear them through your browser settings (section 12).
11. How to change your choice on dsp.so
dsp.so runs no client-side analytics today, so there is no consent banner to re-open. To clear Cloudflare's bot-protection cookie on dsp.so, clear the site's cookies through your browser's standard privacy settings:
- Chrome: Settings → Privacy and security → Clear browsing data
- Safari: Settings → Privacy → Manage Website Data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data
12. How to disable all site storage
You can disable or limit cookies and site data at the browser level. The vendors' help pages below cover the details:
Disabling cookies entirely will prevent you from logging in to the app. Strictly necessary storage on display.dev and dsp.so (listed in sections 3 and 4) does not contain advertising or profiling data.
13. Contact
Displaydev OÜ Ankru 8-23, Tallinn, 11713, Estonia
We aim to respond to all requests within 30 days.
14. Last updated
2026-08-15. We bump this date whenever the tracker inventory above changes.