Cookies and device storage · Updated 22 July 2026

Only what the requested flow needs.

Marlo uses authentication, security and short signup-state storage. The marketing site does not persist its visit identifier or place advertising cookies.

Why no consent banner appears

The technologies listed below authenticate users, secure the service or carry the source and plan selection through signup and checkout. The first-party marketing site measures page and signup-CTA events with a random identifier held only in memory for the active page session. It is not placed in a cookie, local storage or session storage. We do not load advertising or cross-site behavioural analytics.

If that changes, Marlo will update this page and introduce a control that keeps non-essential storage off until the required choice has been made.

Current inventory

NameProvider and locationPurposeDuration
__clientClerk · clerk.withmarlo.appLong-lived client token used to maintain and secure authentication state.Browser-dependent and limited by the configured Clerk session.
__sessionClerk · app.withmarlo.appShort-lived signed session token used to authenticate requests.Approximately 60 seconds and refreshed while the session remains active.
__client_uatClerk · Clerk authentication domainsTracks the last client update so Clerk can refresh authentication state.Managed by Clerk and the browser for the authentication session.
_cfuvidCloudflare for Clerk · Clerk authentication domainsSecurity and rate-limiting for authentication traffic.Managed by Cloudflare according to the active security session.
marlo_checkout_selectionMarlo · browser local storageRemembers the plan and billing interval the user selected while account setup completes.Until Checkout starts or the user clears browser storage.
marlo_acquisition_attributionMarlo app · browser local storage after signup is selectedCarries limited campaign, CTA and random first-party visit values through account and workspace creation.Removed after attachment to a workspace; otherwise treated as expired after 30 days.

Cookie names can gain a host prefix or change where a provider makes a security update. We will keep this inventory aligned with the production service.

Your controls

You can remove cookies and local storage through browser settings and can sign out to end the active Marlo session. Blocking required authentication cookies prevents sign-in. Clearing the checkout selection only means you may need to choose the plan again.

Contact

Questions about this inventory can be sent to hello@builtbyjames.co.uk. Related personal-data use is described in the Privacy Notice.