Cookie Policy
What We Use Cookies For
We use cookies and similar technologies (localStorage, OAuth session tokens) for three purposes only:
- Authentication — keeping you signed in (
filesq_sid,filesq_refreshcookies, HttpOnly + Secure + SameSite=Lax). - Anonymous analytics — aggregated counts of compressions, link views, page visits. No personal identifiers stored.
- Trust signals — one-time "you've seen this message" flags (e.g. the AUP banner).
Third-Party Cookies
We do not allow third-party advertising cookies. The only external services that may set cookies during an OAuth or checkout flow are:
| Service | When | Cookie | Purpose |
|---|---|---|---|
| GitHub | "Sign in with GitHub" | gh_session, user_session |
OAuth callback, expires on tab close |
| "Sign in with Google" | SID, HSID, SSID |
OAuth callback, up to 2 years if you stay signed in to Google | |
| PayPal | checkout on /pricing |
paypal_session, paypal_correlation_id |
Payment authorization, expires after capture |
Analytics Cookies
We self-host analytics (no Google Analytics, no Facebook Pixel). The single _count cookie stores a random visitor ID valid for 14 months, then rotates. You can opt out at any time by clearing cookies for *.link and photo2kb.com.
How to Refuse
- Browser settings: block third-party cookies, or set "Delete cookies on exit".
- Per-site: use your browser's site-data inspector to remove
filesq.linkcookies. - Do Not Track (DNT): we honor
DNT: 1— analytics stays in-memory only, no_countcookie is set.
Updates
This policy may change. Material changes (new third parties, new purposes) get a 30-day banner on the home page. Last updated: 2026-09-20.
Questions? Email [email protected] (data), [email protected] (refunds), [email protected] (reports).