Cookies, local storage, and tracking choices

Cookie Notice

This notice describes storage and tracking on Blogged's own surfaces and explains the separate controls available to customers on published blogs.

Effective September 17, 202610 min read
Blogged combines autonomous content generation, web research, hosted publishing, and customer-directed integrations. This policy explains how those functions affect your rights and responsibilities.

1. What this notice covers

BoostYard LLC owns and operates Blogged. This notice covers cookies, browser storage, pixels, scripts, and similar technologies on Blogged's marketing website, documentation, and account experience. It also explains how Blogged's optional consent controls work on customer-published blogs. A customer's own privacy and cookie notice governs the trackers and custom code that customer chooses.

2. Blogged website and account technologies

TechnologyPurposeDuration or control
Firebase Authentication browser storageKeep users signed in, refresh authentication, and protect account accessPersists according to authentication state and is cleared when the user signs out or clears site data
Interface and tenant preferencesRemember local product choices, active workspace context, and interface stateVaries by preference; clear it through browser site-data controls
Google Analytics 4Measure page views, acquisition, navigation, button and form interactions, scroll depth, web performance, signups, logins, and verified subscription outcomesOff until you select Allow measurement. Google analytics and non-personalized advertising measurement cookies and Blogged's shared choice are limited to 180 days
Firebase Performance MonitoringMeasure account-page loading, browser-to-service network timing, and selected workspace-readiness operations without customer identifiers in custom attributesOff until you select Allow measurement and used only on app.blogged.dev. Google retains IP-associated events for 30 days and installation-associated and de-identified performance data for 60 days before removal begins
Microsoft ClarityUnderstand page rendering and aggregated interactions such as clicks, scrolls, navigation, and session behavior so Blogged can improve usabilityOff until you select Allow measurement. Blogged's pseudonymous measurement browser id lasts up to 180 days and its measurement session id expires after 30 minutes without activity across the marketing, documentation, and account subdomains
Meta Pixel and Conversions APIMeasure consented page views, high-intent content, buttons, checkout, verified registration, onboarding, Free activation, Trial and first paid subscription events for Blogged's own advertisingOff until you select Allow measurement and suppressed when Global Privacy Control is present. The shared choice is limited to 180 days
Reddit Pixel and Conversions APIMeasure consented page views, high-intent content, buttons, navigation, forms, checkout, verified registration, onboarding, Free activation, Trial and first paid subscription events for Blogged's own advertisingOff until you select Allow measurement and suppressed when Global Privacy Control is present. Reddit click attribution is retained for up to 90 days and the shared choice for up to 180 days
Security and rate-limit recordsProtect public endpoints and accounts from abuseUsually server-side rather than a browser cookie; retained only as needed for security and operational purposes
blogged_roadmap_visitorRemember an anonymous public-roadmap vote and bind rate limits without an account or advertising identifierStrictly necessary, httpOnly, same-site, and retained for up to 2 years unless you clear Blogged site data

Blogged loads fonts from Google Fonts and may serve public media from an external content-delivery host. Those providers receive ordinary request data such as IP address, user agent, requested URL, and timestamp. The Google Analytics tag uses measurement ID G-457QMK65WY, Blogged's Meta integration uses dataset 923230536998919, and Blogged's Reddit integration uses Pixel a2_j4kjql2bcsp5 only after the versioned measurement choice.

3. Google, Meta, Reddit, Firebase Performance, and Microsoft Clarity

Google Analytics 4 measures page views across blogged.dev, app.blogged.dev, and docs.blogged.dev. On the marketing and account surfaces it also measures button, navigation, outbound-link, download, form, signup, login, checkout, verified subscription, scroll-depth, and Web Vitals events. Blogged sends a surface and low-cardinality route group for reporting, retains public campaign parameters on marketing pages, and removes application query values and dynamic identifiers from URLs before measurement. A successful signup or other named lifecycle outcome can wait in bounded first-party session storage through a redirect or initialization race and is sent only if measurement is allowed. It does not send form values, passwords, email addresses, entered websites, workspace identifiers, customer content, or raw dashboard button labels.

Clarity may set first-party cookies such as _clck and _clsk and Microsoft-domain cookies used for operational analytics and browser recognition. After measurement is allowed, Blogged also sets random blogged_measurement_browser and blogged_measurement_session identifiers so consented navigation across its three subdomains has consistent browser and session context. For a signed-in account, Blogged derives a separate purpose-bound one-way digest from its authentication identifier before passing that digest to Google Analytics and Clarity; it does not pass the underlying account identifier, email, or name. Clarity can collect rendered page and interaction data, but form input text remains masked. Blogged sets surface and sanitized route-group labels so marketing, documentation, and account activity can be separated in analysis.

Meta Pixel measures privacy-safe browser page and funnel events on Blogged's own surfaces. For URLs containing application identifiers, authentication values, or non-marketing query parameters, Blogged suppresses the browser event and sends only a sanitized server page event. Meta's Conversions API also receives server-authoritative verified registration, onboarding completion, Free activation, Trial and first paid-subscription events. Matching can include Meta's _fbp and _fbc values, IP address and user agent, and SHA-256 hashes of normalized account email and account identity. Raw email, IP address, customer content, workspace and Project identifiers are not stored in Meta attribution records or written to analytics logs. Renewal invoices are not Meta Purchase events.

Reddit Pixel measures privacy-safe browser page, interaction, and funnel events on Blogged's own surfaces. Browser events are suppressed when the real URL contains application identifiers, authentication values, fragments, or parameters unrelated to safe marketing attribution; the paired Conversions API event receives a sanitized URL. Reddit CAPI also receives server-authoritative verified registration, onboarding completion, Free activation, Trial, Subscribe, and initial paid Purchase events. Matching may include a Reddit click ID and UUID, transient request IP and user agent, screen dimensions, and SHA-256 hashes of Reddit-canonicalized account email and account identity. Raw email, account identity and IP are never persisted in Reddit attribution records or written to analytics logs. Pixel and CAPI copies share a conversion ID for deduplication, auto-advanced email/phone matching and enhanced metadata sharing are disabled, and renewal invoices are not Reddit Purchase events.

Firebase Performance Monitoring runs only on app.blogged.dev. It measures account-page loading, completed HTTP and HTTPS request timing, response status and size, and duration traces for authentication restoration, tenant bootstrap, and onboarding-status checks. Network measurement can include request paths but not URL query parameters or payload content. Blogged restricts custom trace attributes to fixed operational categories such as success, error, initial load, or refresh; it does not attach names, emails, entered websites, user, workspace, Project, post, or content identifiers.

Blogged does not request Google Analytics, Meta Pixel, Reddit Pixel, Firebase Performance Monitoring, or Microsoft Clarity until you select Allow measurement. If you allow it, Blogged grants Google analytics storage, advertising storage, and ad-user-data consent for analytics and non-personalized advertising measurement; Google ad personalization, Google Signals, and ad-personalization signals remain disabled, and Microsoft advertising storage remains denied. The same explicit choice permits the Meta and Reddit advertising measurement and optimization described above, except that both remain suppressed when the browser sends Global Privacy Control. Blogged remembers the versioned combined choice for 180 days across blogged.dev, app.blogged.dev, and docs.blogged.dev. A previous value does not authorize the added Reddit scope, so an existing visitor is asked once again. You can withdraw your choice by deleting Blogged, Google Analytics, Meta, Reddit, Firebase, and Clarity storage through your browser or contact Blogged with a privacy request.

4. Customer-published blogs

A Blogged customer may configure Google Analytics 4, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, or custom code on its blog. Blogged does not add those tools to a customer blog unless an owner or admin configures them. The customer is responsible for its notices, lawful basis, consent configuration, and vendor accounts.

Customer-blog stateWhat happens
No configured tags or custom codeBlogged does not inject third-party tracking tags. First-party service and aggregated product analytics may still operate as described by the customer's notice
Tags configured, banner offConfigured tags can load when the page loads, subject to Do Not Track and Global Privacy Control unless the customer has deliberately overridden that default
Banner on, no choice yetGA4 loads with Consent Mode v2 storage denied; Meta initializes with consent revoked; GTM, LinkedIn, TikTok, and custom code are withheld until acceptance
Reader acceptsConsent is granted to configured providers and deferred tags or custom code load
Reader declinesConsent remains denied and deferred tags or custom code do not load

5. Customer-blog consent storage

The optional customer-blog banner stores the reader's choice in local storage under blogged:cookie-consent:v1. The choice expires after 180 days, after which the banner asks again. Local storage is specific to the browser and site. Private browsing, clearing site data, or using another device may cause the banner to return.

When a browser sends Do Not Track or Global Privacy Control, customer-configured tags are disabled by default and the Blogged banner is not shown because it has nothing to request. A customer can deliberately override the tag gate in settings, but remains responsible for doing so lawfully and disclosing that choice.

6. Your choices

  • Use the accept or decline controls when a customer blog displays the Blogged cookie banner.
  • Enable Global Privacy Control or supported browser tracking protection.
  • Block or delete cookies and local storage in browser settings. Authentication and saved preferences may stop working until restored.
  • Use vendor-specific controls for Google, Meta, Reddit, Microsoft, LinkedIn, TikTok, or customer-added custom tools.
  • Contact hi@blogged.dev for a request about Blogged's own surfaces, or contact the customer for a request about its published blog.

7. Changes to this notice

Blogged will update this notice when its storage, analytics, or customer-blog consent behavior materially changes. The effective date at the top identifies the current version.

Questions about this policy?

Include the relevant workspace, customer blog, public URL, or account email so the request can be routed without collecting unnecessary information.

Email hi@blogged.dev

Related policies