Skip to content

Cookie Policy

Last updated: September 17, 2026

1. Introduction

This Cookie Policy explains how dosya.dev ("we," "us," or "our") uses cookies and similar storage technologies when you visit our website and use our services. It lists every cookie we set, what it does, and how long it lasts.

This policy should be read alongside our Privacy Policy, which explains how we collect and process your personal data.

2. The Short Version

We believe cookie policies should be boring. Ours is:

  • We only set cookies that are needed to sign you in, keep your account secure, and remember your preferences.
  • Every cookie we set is first-party. We do not place third-party cookies on our pages.
  • We do not use analytics cookies. There is no Google Analytics or any other cookie-based analytics service on this site. The only measurement is Cloudflare Web Analytics, a cookieless beacon described in Section 6.
  • We load no advertising scripts. No Facebook Pixel, no Google Ads tags, no Reddit Pixel, no cross-site tracking of any kind.
  • The one ad-related cookie we set is first-party: if you arrive from one of our Reddit ads, the link carries a click identifier and we keep it for 30 days, so that when you sign up we can tell Reddit, server-to-server, that the ad worked. It holds nothing but that identifier, and rejecting cookies in the banner removes it.
  • We do not track your location for marketing purposes. Our cookies contain no location data at all.
  • We do not put tracking pixels or read receipts in our emails.
  • We do not sell your data. The only thing an advertising platform ever receives from us is the sign-up confirmation described above, and only for people who arrived from that platform's ad.

The rest of this page is the detail behind those statements.

3. What Are Cookies?

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently, for example to keep you signed in as you move between pages.

Cookies can be "first-party" (set by the website you are visiting) or "third-party" (set by a different domain than the one you are visiting). They can also be "session cookies" (deleted when you close your browser) or "persistent cookies" (remain on your device for a set period or until you delete them). All cookies set by dosya.dev are first-party.

4. Cookies We Set

4.1 Strictly Necessary Cookies

These cookies are essential for signing in, keeping your session secure, and remembering your consent choices. Without them, the service cannot work. They contain only random tokens or your consent settings - never your location, browsing history, or an advertising profile.

Cookie Purpose Duration
__Host-dosya_session Keeps you signed in after login. Sessions created before this cookie was renamed use the older name dosya_session, which we still accept until they expire. 30 days
dosya_2fa_challenge Links the two steps of a two-factor login together 5 minutes
dosya_pending_email Tells the verification page which account to verify during signup 30 minutes
dosya_oauth_state One-time security token that protects "Sign in with Google/Apple" against forged requests 10 minutes
dosya_sa_* Grants access to a password-protected share link after you enter its password 30 minutes
dosya_sr_* Grants access to a restricted share link after you enter the one-time code emailed to you. Kept separate from the password grant above, so clearing one gate never clears the other. 30 minutes
dosya_ura_* Grants access to a password-protected file request link after you enter its password 30 minutes
dosya_urv_* Set on a public file request page. A random secret that tells us you are the same browser that sent a file earlier, so you can come back and withdraw it. It identifies a browser, not a person: it carries no name, email or address, we store only a one-way hash of it, and it unlocks nothing on its own. 30 days
d1b Points your next request at a database replica that already has your last change, so something you just saved does not appear to be missing 10 minutes
cookie_consent Stores your cookie consent preferences 1 year

All authentication cookies above are marked HttpOnly, which means scripts running in the page cannot read them.

4.2 Functional Cookies

These cookies remember interface preferences, plus the one ad-click identifier described below. They are optional - you can turn them off in the cookie banner and everything will still work, you will just lose the remembered preference.

Cookie Purpose Duration
sidebar_state Remembers whether the app sidebar is open or collapsed 7 days
dosya_rdt_cid Set only if you arrive from one of our Reddit ads (the link carries a click identifier). Lets us tell Reddit, server-to-server, that the ad led to a sign-up. Contains only that identifier - no browsing history. Rejecting cookies removes it. 30 days

5. Local Storage

In addition to cookies, we store some preferences in your browser's local storage. Unlike cookies, local storage data is never sent to our servers - it stays on your device and is only read by the page you are viewing. It remains until you clear it or your browser does.

Key Purpose
dosya_theme / theme Your light/dark mode preference
dosya_fs_sidebar_collapsed / dosya_vault_sidebar_collapsed Sidebar open/collapsed state in the file browser and vault
dosya_table_columns Which columns you show in file lists
dosya_uploads State of in-progress uploads so they can resume after a page reload
upload_concurrency Your upload performance setting
dosya_last_login_method Shows a "last used" hint next to your previous sign-in method
dosya_li Session storage, not local storage: remembers for five minutes whether the menu should show "Log in" or "Dashboard", so the header does not flicker. Cleared when you close the tab.

6. What We Do Not Use

To be completely explicit about what is absent from dosya.dev:

  • No analytics cookies. We do not run Google Analytics or any other cookie-based analytics service, first-party or third-party. Our marketing pages do use Cloudflare Web Analytics, which is cookieless: it sets nothing in your browser and cannot identify you. It is measurement without a cookie, not an absence of measurement.
  • No advertising scripts or third-party cookies. We do not load the Facebook Pixel, Google Ads tags, the Reddit Pixel, or any ad network script, and we do not participate in cross-site or cross-context behavioral advertising. Measuring our own Reddit ads happens server-to-server, using only the first-party click identifier listed in section 4.2.
  • No location tracking for marketing. Our cookies contain no location data, and we do not build location profiles of our users for marketing or any other purpose.
  • No tracking pixels. Our emails contain no tracking pixels; we do not know whether you opened an email we sent you. Our marketing pages use Cloudflare Web Analytics, a cookieless, privacy-preserving measurement beacon that does not identify you. It sets no cookie and stores nothing in your browser.
  • No fingerprinting. We do not attempt to identify you through device or browser fingerprinting techniques.

If we ever introduce an analytics or similar tool in the future, we will update this policy first, and no such cookie will be set without your explicit prior consent through the cookie banner.

7. Legal Basis for Cookie Use

Category Legal Basis (GDPR Art.) Explanation
Strictly Necessary Legitimate Interest (Art. 6(1)(f)) Required for the basic operation of the website and service delivery. These cookies are exempt from consent requirements under the ePrivacy Directive (Art. 5(3)).
Functional Consent (Art. 6(1)(a)) Enabled by default but you may opt out at any time. These cookies remember interface preferences and, if you arrived from one of our ads, that click's identifier.

Because we do not use analytics cookies, and the only ad-related cookie is the first-party click identifier above (which Reject removes), the two categories in our banner cover everything this site sets.

8. Cookie Consent

When you first visit dosya.dev, you will see a cookie banner with two categories:

  • Strictly Necessary: Always active. These cannot be disabled as they are required for the website to function.
  • Functional: Enabled by default. Opting out has two effects: interface preferences are no longer remembered, and the ad-click identifier described in section 4.2 is neither stored nor read, so if you arrived from one of our ads we will not report your sign-up as a conversion.

You may use the "Accept All," "Reject All," or "Save Preferences" buttons to set your choice. Your decision is stored in the cookie_consent cookie and remembered for 1 year. You can change it at any time via the "Cookie Settings" button in the footer of any page.

9. Third-Party Services

We do not place third-party cookies on dosya.dev pages. Two external services are involved in specific flows, on their own domains:

  • Stripe: When you purchase a subscription, checkout happens on Stripe's own pages. Stripe sets cookies on its domain for payment processing and fraud prevention, governed by the Stripe Privacy Policy.
  • Cloudflare: Our infrastructure runs on Cloudflare, and some forms (such as the contact and report forms) use Cloudflare Turnstile to block bots. Cloudflare may use strictly necessary security mechanisms to distinguish humans from automated traffic; these are used for security only, never for advertising. See the Cloudflare Privacy Policy.

10. International Data Transfers

We use no analytics cookies, and no cookie data is shared with any analytics company. One cookie does reach an advertising company, and only in one direction: if you arrived from a Reddit ad, the first-party click identifier in section 4.2 is read once, at sign-up, and sent to Reddit, Inc. server-to-server as part of the conversion event described in section 2. That is the only advertising disclosure we make, it is prevented entirely by rejecting Functional cookies, and no cookie of ours is readable by Reddit or any other third party. The infrastructure and payment providers named in Section 9 (Cloudflare, Inc. and Stripe, Inc.) are based in the United States; transfers to them are governed by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs) approved by the European Commission, in accordance with GDPR Article 46. You can obtain details of the relevant transfer mechanisms by contacting us at privacy@dosya.dev.

11. Managing Your Cookie Preferences

11.1 Through Our Cookie Settings

You can review and change your cookie preferences at any time by clicking the "Cookie Settings" button in the footer of any page on our website. This re-opens the consent banner with your current preferences. Changes take effect immediately.

11.2 Through Your Browser

Most web browsers allow you to control cookies through their settings. You can typically find these settings in the "Options," "Preferences," or "Privacy" section of your browser. Common browser cookie management pages:

  • Chrome: Settings > Privacy and Security > Cookies and other site data
  • Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Safari: Preferences > Privacy > Manage Website Data
  • Edge: Settings > Cookies and site permissions > Cookies and site data

Please note that blocking or deleting strictly necessary cookies will sign you out and may prevent parts of dosya.dev from working.

12. Do Not Track and Global Privacy Control

Some browsers send "Do Not Track" (DNT) or Global Privacy Control (GPC) signals to websites. dosya.dev sets no analytics cookies and loads no third-party tracking or advertising scripts for any visitor, so most of what these signals exist to switch off is already absent by default. The one thing they can switch off is the ad-click identifier in section 4.2: we treat a GPC signal as a rejection of Functional cookies, so the identifier is not stored and no conversion event is sent to Reddit.

13. Data Collected Through Cookies

Our cookies contain only:

  • Random session and security tokens (which identify your login session, not your behavior)
  • Your cookie consent choices
  • Interface preferences such as sidebar state

They do not contain, and are not used to derive, your geographic location, browsing history on other sites, or any advertising profile. For details on the data we process when providing the service itself (such as your account information and files), please refer to our Privacy Policy.

14. Cookie Retention Periods

The retention period for each cookie is listed in the tables in Section 4. Persistent cookies remain on your device until they expire or you delete them manually. Signing out clears your session cookie immediately.

We periodically review our cookie usage and remove any cookies that are no longer necessary. We strive to minimize the number and duration of cookies we use.

15. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in the cookies we use, our practices, or for legal and regulatory reasons. When we make changes, we will update the "Last updated" date at the top of this page. If we ever add a new category of cookies, we will re-prompt you for consent before setting any of them.

We encourage you to review this Cookie Policy periodically to stay informed about how we use cookies.

16. Contact Us

If you have any questions about our use of cookies or this Cookie Policy, please contact us: