Legal
Cookies & tracking
Effective date: September 11, 2026 · Companion to the Privacy Policy.
We keep this simple. PhotoEditRocket sets no advertising cookies and uses no third-party analytics — there is no Google Analytics, no Google Ads or DoubleClick tags, and no cross-site tracking. Because we rely only on strictly necessary, first-party storage, there is no cookie consent banner to manage.
Strictly necessary — first-party
| Name | Type | Set by | Purpose | Retention |
|---|---|---|---|---|
photoeditr.purchaseEmail, photoeditr.purchasePlan, photoeditr.licenseKey, photoeditr.licenseExpiresAt, photoeditr.licenseActivatedAt, photoeditr.licenseWarnedOn, photoeditr.licenseRecords, photoeditr.pendingLicenseRecord, photoeditr.deliveredLicenseRecord | localStorage | PhotoEditRocket | Hold your purchase and license-key state locally so you can re-download keys without contacting us. | Until you clear browser data |
photoeditr-autosave (IndexedDB), plus editor settings such as photoeditr.userTemplates, photoeditr.autoUpdate, per.exportCount | IndexedDB & localStorage | PhotoEditRocket | Autosave & crash-recovery of your open projects, your saved templates, recent files, editor preferences, and a copy of your licence key (one of four places it is kept, so it survives any single one being cleared). Stays on your device; the app does not send it to us. | Until you clear browser data |
per_lic | Cookie | PhotoEditRocket | Keeps your licence key (and, on a timed licence, its end date) so the editor still recognises your purchase if browser storage is cleared or evicted. It is a first-party functional cookie: it is not shared with anyone else, carries no identifier beyond the key you already hold, and is not used for analytics or advertising. Removing your licence in the app deletes it. | Up to 10 years, or until you remove your licence |
per-license-v1 | Cache storage | PhotoEditRocket | A third copy of the same licence key, so the editor still recognises your purchase if localStorage and the cookie are both cleared. Nothing else is kept there, and the app does not transmit it. Removing your licence in the app deletes it. | Until you remove your licence or clear site data |
__stripe_mid, __stripe_sid | Cookie | Stripe (only if you are sent to Stripe to pay) | Fraud prevention during checkout. | Up to 1 year (Stripe-controlled) |
Aggregate visit count
We keep a simple tally on our own server. It records only which page was loaded — no cookies, no storage of any kind on your device, no IP address, no timestamp per visit, and no cross-site identifiers, so it cannot identify you and nothing about your visit is sent to any other company. We do not use Google Analytics, Google Ads, DoubleClick, LinkedIn, or any other third-party analytics tag.
Advertising: how we measure our ads without tracking you
We advertise on X and we need to know whether those ads lead to sign-ups. The usual way to do that is an advertising pixel — a script from the ad network that runs on your device and sets its own cookies. We deliberately do not do that. There is no ad-network script anywhere on this site, and no advertising cookie is ever set.
Instead: when you arrive from one of our ads, X appends a click id to the link. It identifies the click, not you — X issued it, it is meaningless to any other website, and it cannot be used to follow you anywhere. If you go on to buy, our server tells X that that click converted. The report goes from our server to X's; your browser is not involved.
- Nothing is stored on your device. The click id is held in memory for as long as the page is open and passed along only if you continue to checkout. Close the tab and it is gone. That is why this site has no cookie banner: there is nothing to ask permission for.
- No third-party script, anywhere. Not on this site, and not in the editor.
- What we send: the click id, and the fact that one of four things happened — the home page was viewed, the free editor was opened, a review licence was requested, or a purchase completed. No email address, no name, no licence key, no order value.
- Once each, not repeatedly. Each of those is reported at most once per ad click, so reloading a page does not send anything further.
- If you did not come from an ad, we send nothing at all. There is no click id, so there is nothing to report.
- We honour Global Privacy Control and Do Not Track as a refusal, and skip the report entirely.
- The click id is removed from the address bar as soon as the page loads, so it is not left in a URL you might copy, share or bookmark.
- To opt out completely: remove the
twclidparameter from the address bar before continuing, or reach the site by typing the address directly. See also X's privacy policy.
How to remove these
- Set your browser to send a Global Privacy Control signal — we honor it automatically as a Do Not Sell or Share request, though we do not sell or share data in any case.
- Clear the cookies and site data for
photoeditrocket.comin your browser settings to remove every first-party item above.