COOKIE_PROTOCOL

クッキー
ポリシー

> 最終更新日: 8/10/2026

Cookieおよび類似技術の使用方法

🍪

クッキーとは

クッキーは、当サイトを訪問する際にデバイスに保存される小さなテキストファイルです。

このポリシーは、GDPRとスペインのLSSIに準拠し、XeitoがどのようにCookieを使用するかを説明します。

📦

使用するCookieの種類

必須Cookie

サイトの適切な機能に必要です。無効にすることはできません。

セッション管理と認証

__Secure-better-auth.session_token — Authenticates your session after sign-in. Duration: 7 days (rolling). Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai. In local development the cookie is named better-auth.session_token (no __Secure- prefix) because it is served over HTTP.

__Secure-better-auth.session_data — Caches non-sensitive session metadata so we can avoid hitting the auth database on every request. Duration: matches the session token. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai.

__Secure-better-auth.dont_remember — Set only when you sign in without "remember me", so the session ends when you close the browser. Duration: session. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax.

better-auth.state_* / better-auth.pkce_* — Short-lived CSRF state and PKCE verifier cookies used during OAuth sign-in flows (Google, GitHub, LinkedIn) and email-verification redirects. Duration: 10 minutes. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax. Deleted as soon as the OAuth round-trip completes.

Stripe (payment security — Stripe Payments Europe Ltd, Ireland)

__stripe_mid — Machine identifier for fraud detection. Duration: 1 year. Provider: Stripe. Set only on payment pages.

__stripe_sid — Session identifier for fraud detection. Duration: 30 minutes. Provider: Stripe. Set only on payment pages.

m — Device fingerprint for fraud prevention. Duration: 2 years. Provider: Stripe. Set only on payment pages.

Cloudflare (network security — Cloudflare, Inc., USA)

__cf_bm — Bot management and abuse prevention. Duration: 30 minutes. Provider: Cloudflare.

_cfuvid — Rate limiting to protect against abuse. Duration: Session. Provider: Cloudflare.

分析Cookie

訪問者がサイトとどのようにやり取りするかを理解するのに役立ちます。明示的な同意がある場合のみ読み込まれます。

_ga — Distinguishes unique users. Duration: 2 years. Provider: Google.

_ga_ZVXP12T53T — Maintains session state. Duration: 2 years. Provider: Google.

xeito-cookie-analytics — Stores your analytics consent choice. Duration: localStorage (no expiry). Provider: Xeito (first-party).

IPの匿名化が有効になっています。

機能Cookie

設定を記憶し、エクスペリエンスをパーソナライズします。

xeito-locale — Stores your language preference when you switch languages. Duration: 1 year. Provider: Xeito (first-party).

xeito-cookie-consent — Stores your cookie consent decision. Duration: localStorage (no expiry). Provider: Xeito (first-party).

保存した検索と求人設定

広告Cookie

Xeitoを無料に保つため、広告は公開ブログおよびマーケティングページに常に表示されます。デフォルトでは非パーソナライズ(トラッキングCookieなし、同意不要)です。Cookieバナーからの明示的な同意後、Google AdSenseおよびそのパートナーは広告Cookieを設定して興味に基づいた広告を表示する場合があります。Premium加入者には広告は一切表示されません。

Google AdSense (Google Ireland Limited / Google LLC)

NID — Used by Google to remember your preferences and show personalized ads. Duration: 6 months. Domain: .google.com.

IDE — Used by Google DoubleClick to measure ad effectiveness and show relevant ads. Duration: 13 months. Domain: .doubleclick.net.

ANID — Ad personalization identifier. Duration: 13 months. Domain: .google.com.

__gads, __gpi — Frequency capping and ad selection. Duration: 13 months. Domain: xeito.ai.

_gcl_* — Google Ads conversion tracking. Duration: 90 days. Domain: xeito.ai.

広告Cookieは、認証済みアプリ(app.xeito.ai)やPricing、Terms of Service、このCookie Policyなどの法的ページでは決して有効になりません。広告配信は、AdSenseのコンテンツポリシーに従い、薄いコンテンツやプログラム生成ページでも抑制されます。

⚙️

Cookieの管理

ブラウザの設定からCookieを管理できます。

Chrome: 手順を表示

Firefox: 手順を表示

Safari: 手順を表示

Edge: 手順を表示

特定のCookieを無効にすると、サイトの機能に影響する場合があります。

🔗

サードパーティCookie

一部のサードパーティサービスがデバイスにCookieを設定する場合があります:

Googleアナリティクス(ウェブ分析用)

Google AdSense(広告用、公開ブログおよびマーケティングページのみ)

LinkedIn(プロフェッショナルネットワーク機能用)

決済処理業者(取引セキュリティ用)

📧

お問い合わせ

クッキーポリシーについてご質問がある場合は、お問い合わせください: