COOKIE_PROTOCOL

Cookie
政策

> 最后更新: 8/10/2026

我们如何使用Cookie和类似技术

🍪

什么是Cookie

Cookie是您访问我们网站时存储在设备上的小型文本文件。

本政策解释Xeito如何使用Cookie,符合GDPR和西班牙LSSI的规定。

📦

我们使用的Cookie类型

必要Cookie

网站正常运行所必需的Cookie,无法禁用。

会话管理和身份验证

__Secure-better-auth.session_token — Authenticates your session after sign-in. Duration: 7 days (rolling). Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai. In local development the cookie is named better-auth.session_token (no __Secure- prefix) because it is served over HTTP.

__Secure-better-auth.session_data — Caches non-sensitive session metadata so we can avoid hitting the auth database on every request. Duration: matches the session token. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax, Domain=.xeito.ai.

__Secure-better-auth.dont_remember — Set only when you sign in without "remember me", so the session ends when you close the browser. Duration: session. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax.

better-auth.state_* / better-auth.pkce_* — Short-lived CSRF state and PKCE verifier cookies used during OAuth sign-in flows (Google, GitHub, LinkedIn) and email-verification redirects. Duration: 10 minutes. Provider: Xeito (first-party, set by BetterAuth). HttpOnly, Secure, SameSite=Lax. Deleted as soon as the OAuth round-trip completes.

Stripe (payment security — Stripe Payments Europe Ltd, Ireland)

__stripe_mid — Machine identifier for fraud detection. Duration: 1 year. Provider: Stripe. Set only on payment pages.

__stripe_sid — Session identifier for fraud detection. Duration: 30 minutes. Provider: Stripe. Set only on payment pages.

m — Device fingerprint for fraud prevention. Duration: 2 years. Provider: Stripe. Set only on payment pages.

Cloudflare (network security — Cloudflare, Inc., USA)

__cf_bm — Bot management and abuse prevention. Duration: 30 minutes. Provider: Cloudflare.

_cfuvid — Rate limiting to protect against abuse. Duration: Session. Provider: Cloudflare.

分析Cookie

帮助我们了解访客如何与网站互动。仅在您明确同意后加载。

_ga — Distinguishes unique users. Duration: 2 years. Provider: Google.

_ga_ZVXP12T53T — Maintains session state. Duration: 2 years. Provider: Google.

xeito-cookie-analytics — Stores your analytics consent choice. Duration: localStorage (no expiry). Provider: Xeito (first-party).

已启用IP匿名化。

功能Cookie

记住您的偏好设置并个性化您的体验。

xeito-locale — Stores your language preference when you switch languages. Duration: 1 year. Provider: Xeito (first-party).

xeito-cookie-consent — Stores your cookie consent decision. Duration: localStorage (no expiry). Provider: Xeito (first-party).

已保存的搜索和工作偏好

广告Cookie

为了让Xeito保持免费,广告始终在公共博客和营销页面上展示。默认情况下它们是非个性化的(无跟踪Cookie,无需同意)。在您通过Cookie横幅明确同意后,Google AdSense及其合作伙伴可能会设置广告Cookie,向您展示基于兴趣的广告。Premium订阅用户永远不会看到任何广告。

Google AdSense (Google Ireland Limited / Google LLC)

NID — Used by Google to remember your preferences and show personalized ads. Duration: 6 months. Domain: .google.com.

IDE — Used by Google DoubleClick to measure ad effectiveness and show relevant ads. Duration: 13 months. Domain: .doubleclick.net.

ANID — Ad personalization identifier. Duration: 13 months. Domain: .google.com.

__gads, __gpi — Frequency capping and ad selection. Duration: 13 months. Domain: xeito.ai.

_gcl_* — Google Ads conversion tracking. Duration: 90 days. Domain: xeito.ai.

广告Cookie绝不会在已认证的应用程序(app.xeito.ai)或Pricing、Terms of Service、本Cookie Policy等法律页面上激活。根据AdSense内容政策,广告投放在薄内容或程序化页面上也会被抑制。

⚙️

Cookie管理

您可以通过浏览器设置控制Cookie。

Chrome: 查看说明

Firefox: 查看说明

Safari: 查看说明

Edge: 查看说明

禁用某些Cookie可能会影响网站功能。

🔗

第三方Cookie

某些第三方服务可能会在您的设备上放置Cookie:

Google Analytics用于网络分析

Google AdSense用于广告(仅限公开博客和营销页面)

LinkedIn用于专业社交功能

支付处理商用于交易安全

📧

联系我们

如果您对我们的Cookie政策有疑问,请联系我们: