COOKIE_PROTOCOL

COOKIE
POLICY

> LAST_UPDATED: 8/10/2026

How we use cookies and similar technologies

🍪

What Are Cookies

Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience by enabling essential features, analyzing site usage, and personalizing content.

This Cookie Policy explains how Xeito uses cookies and similar technologies, in compliance with GDPR and the Spanish Law 34/2002 on Information Society Services (LSSI).

📦

Types of Cookies We Use

Essential Cookies

Required for the website to function properly. These cannot be disabled.

Session management and authentication

__Secure-better-auth.session_token — Authenticates your session after sign-in. Duration: 7 days (rolling). Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai. In local development the cookie is named better-auth.session_token (no __Secure- prefix) because it is served over HTTP.

__Secure-better-auth.session_data — Caches non-sensitive session metadata so we can avoid hitting the auth database on every request. Duration: matches the session token. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai.

__Secure-better-auth.dont_remember — Set only when you sign in without "remember me", so the session ends when you close the browser. Duration: session. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax.

better-auth.state_* / better-auth.pkce_* — Short-lived CSRF state and PKCE verifier cookies used during OAuth sign-in flows (Google, GitHub, LinkedIn) and email-verification redirects. Duration: 10 minutes. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax. Deleted as soon as the OAuth round-trip completes.

Stripe (payment security — Stripe Payments Europe Ltd, Ireland)

__stripe_mid — Machine identifier for fraud detection. Duration: 1 year. Provider: Stripe. Set only on payment pages.

__stripe_sid — Session identifier for fraud detection. Duration: 30 minutes. Provider: Stripe. Set only on payment pages.

m — Device fingerprint for fraud prevention. Duration: 2 years. Provider: Stripe. Set only on payment pages.

Cloudflare (network security — Cloudflare, Inc., USA)

__cf_bm — Bot management and abuse prevention. Duration: 30 minutes. Provider: Cloudflare.

_cfuvid — Rate limiting to protect against abuse. Duration: Session. Provider: Cloudflare.

Analytics Cookies

Help us understand how visitors interact with our website. Only loaded after your explicit consent. Provided by Google Analytics 4 (Google LLC).

_ga — Distinguishes unique users. Duration: 2 years. Provider: Google.

_ga_ZVXP12T53T — Maintains session state. Duration: 2 years. Provider: Google.

xeito-cookie-analytics — Stores your analytics consent choice. Duration: localStorage (no expiry). Provider: Xeito (first-party).

IP anonymisation is enabled. Data is processed in accordance with Google's Privacy Policy.

Functional Cookies

Remember your preferences and personalize your experience. Set only on explicit user action.

xeito-locale — Stores your language preference when you switch languages. Duration: 1 year. Provider: Xeito (first-party).

xeito-cookie-consent — Stores your cookie consent decision. Duration: localStorage (no expiry). Provider: Xeito (first-party).

Saved searches and job preferences

Advertising Cookies

Ads always run on public blog and marketing pages to keep Xeito free. By default they are non-personalized (no tracking cookies, no consent required). After your explicit consent via the cookie banner, Google AdSense and its partners may set advertising cookies to show you interest-based ads. Premium subscribers never see ads at all.

Google AdSense (Google Ireland Limited / Google LLC)

NID — Used by Google to remember your preferences and show personalized ads. Duration: 6 months. Domain: .google.com.

IDE — Used by Google DoubleClick to measure ad effectiveness and show relevant ads. Duration: 13 months. Domain: .doubleclick.net.

ANID — Ad personalization identifier. Duration: 13 months. Domain: .google.com.

__gads, __gpi — Frequency capping and ad selection. Duration: 13 months. Domain: xeito.ai.

_gcl_* — Google Ads conversion tracking. Duration: 90 days. Domain: xeito.ai.

Advertising cookies are never activated on the authenticated app (app.xeito.ai) or on legal pages like Pricing, Terms of Service, or this Cookie Policy. Ad serving is also suppressed on thin or programmatic pages per AdSense content policies.

⚙️

Managing Cookies

You can control and manage cookies through your browser settings. Here's how:

Chrome: View instructions

Firefox: View instructions

Safari: View instructions

Edge: View instructions

Note: Disabling certain cookies may affect the functionality of our website.

🔗

Third-Party Cookies

Some third-party services may place cookies on your device when you use our website:

Google Analytics for website analytics

Google AdSense for advertising (only on public blog and marketing pages)

LinkedIn for professional networking features

Payment processors for transaction security

📧

Contact Us

If you have any questions about our Cookie Policy, please contact us: