Cookies and similar storage

Last updated 10 October 2026

This notice explains what How’s that? stores in your browser on this website (howsthat.design), in the app (app.howsthat.design) and in the browser extension, and how to change your choice. It follows the Privacy and Electronic Communications Regulations (PECR). How we use any personal data involved is covered in our privacy notice.

1. Cookies and browser storage

A cookie is a small file a website saves in your browser. Websites can also save data in your browser’s local storage, which stays until it is cleared, and session storage, which is cleared when you close the tab. The law treats all of these the same way: a site may only store or read them without your consent if they are strictly necessary for a service you asked for.

This website sets one cookie of its own, ht_consent, to remember your choice. If you visit from the UK, the European Economic Area, Switzerland or California, it uses no analytics or advertising cookies unless you agree. Elsewhere they are on unless you turn them off, and advertising is off if your browser sends a Global Privacy Control signal. The app follows the same choice, so you only choose once.

2. This website

Your consent choice

When you first visit from the UK, the EEA, Switzerland or California (or from somewhere we can’t tell), a banner asks whether you allow analytics and advertising. Elsewhere there is no banner, and you can turn either off under Changing your choice. Rejecting is as easy as accepting, and you can choose each one separately. We save your answer in a cookie, ht_consent, for 12 months, so we don’t ask on every page. The app at app.howsthat.design reads the same cookie, so your choice applies there too. This is strictly necessary to respect your choice.

Which ad you came from

If advertising is allowed, we save two entries:

  • ht_first_touch in local storage: the first page you landed on, when, and any ad click IDs (gclid, gbraid, wbraid) or campaign tags (UTM parameters) in the address you arrived at;
  • ht_first_touch_session in session storage: the same click IDs and campaign tags, and the landing page, for the current visit.

If you then sign up, these values are sent with your signup so we can tell which ads bring in customers. If advertising isn’t allowed, neither entry is saved, and if you later turn it off, we delete both.

Your currency on the pricing page

If you pick a currency on the pricing page, we remember it in local storage as ht_currency, so prices show in that currency next time. We only save it when you choose a currency, and it isn’t sent anywhere.

Our typeface

The typeface, Onest, is served from our own website, so loading it doesn’t contact anyone else.

Google Tag Manager

Every page loads Google Tag Manager from our own address (howsthat.design/metrics/, or app.howsthat.design/metrics/ in the app), which Cloudflare passes on to Google. It loads the Google tools below and tells them what you allowed, using Google consent mode. Until analytics or advertising is allowed, Google’s tags don’t set or read cookies for it, though they may send Google limited, cookieless signals that a page was viewed.

Analytics

Where analytics is allowed, we use two tools that show us how the site is used:

  • Google Analytics counts visits and records which pages you view, roughly where you are and what device you use.
  • Microsoft Clarity records clicks, scrolling and mouse movement on our pages so we can see where people get stuck. Text you type is hidden from the recording.

Advertising

Where advertising is allowed, we use Google Ads conversion tracking, which tells us when someone who clicked one of our ads goes on to sign up.

Each tool sets its own cookies, listed in the table below. Their providers also process the data under their own privacy policies: Google and Microsoft.

3. The app

The app at app.howsthat.design loads Google Tag Manager the same way as this website, under the same choice: Google Analytics and Google Ads only run where you’ve allowed them, and choosing or changing it in either place changes both. Microsoft Clarity is never used in the app. It doesn’t load it in the review sidebar shown on your own site, or on the pages where you let another app sign in with your account. You can change your choice from Cookie settings on your Account page.

Besides ht_consent, which it shares with this website, the app’s own cookies are strictly necessary for the service you signed up for:

  • __Host-annotate keeps you signed in;
  • annotate-csrf proves that changes you make come from the app itself, which protects your account from cross-site request forgery;
  • annotate-integration-oauth is set for 10 minutes while an admin connects Linear, to protect that sign-in;
  • __Host-annotate-snap lets you open a journey snapshot you launched from the app. It is set on that journey’s own address, under howsthat.page;
  • __Secure-annotate-gate lets you use web mode, which reviews a site through our servers. It is set on the web mode addresses only when web mode is switched on.

The app also keeps a few things in your browser’s storage to make it work the way you left it: your light or dark theme, whether you dismissed the getting-started card or a notice in the review sidebar, replies you have started but not sent, and, in the review sidebar, your sign-in token.

4. The browser extension

The extension doesn’t use cookies. It keeps your sign-in token in the extension’s own storage in your browser, along with the list of your project addresses, your theme and any unsent drafts or unpublished journey steps. Websites can’t read the extension’s storage. Removing the extension deletes it all.

5. Everything we store, in one table

Cookies and browser storage
NameWherePurposeHow longType
ht_consent howsthat.design and app.howsthat.design, cookie Remembers your consent choice 12 months, then we ask again Strictly necessary
ht_first_touch howsthat.design, local storage First landing page and time, ad click IDs and campaign tags 90 days, or until you withdraw consent Advertising (consent)
ht_first_touch_session howsthat.design, session storage Click IDs, campaign tags and landing page for this visit Until you close the tab Advertising (consent)
_ga, _ga_* howsthat.design, cookie set by Google Analytics Tells visits from the same browser apart 2 years Analytics (consent)
_clck, _clsk howsthat.design, cookies set by Microsoft Clarity Links pages you view in one visit, and visits from the same browser 1 year and 1 day Analytics (consent)
CLID, MUID clarity.ms and Microsoft domains, cookies set by Microsoft Identify the browser to Clarity across sites that use it 1 year Analytics (consent)
_gcl_au howsthat.design, cookie set by Google Ads Links an ad click to a later signup 90 days Advertising (consent)
Google advertising cookies google.com and doubleclick.net, cookies set by Google Measure ad conversions Up to 13 months Advertising (consent)
ht_currency howsthat.design, local storage The currency you picked on the pricing page Until you clear your browser storage Preference you asked for
__Host-annotate app.howsthat.design, cookie Keeps you signed in 14 days, renewed while you use the app Strictly necessary
annotate-csrf app.howsthat.design, cookie Protects against cross-site request forgery 14 days Strictly necessary
annotate-integration-oauth app.howsthat.design, cookie Protects the sign-in while connecting Linear 10 minutes Strictly necessary
__Host-annotate-snap Journey snapshot addresses under howsthat.page, cookie Lets you view a journey you opened from the app 12 hours Strictly necessary
__Secure-annotate-gate Web mode addresses, cookie, only when web mode is on Lets you review a site through our servers 12 hours Strictly necessary
annotate:embed-refresh Review sidebar, local storage Keeps you signed in to the sidebar on snapshot and web mode pages Until you sign out, or 7 days without use (30 days at most) Strictly necessary
annotate:theme
annotate:onboarding-dismissed
app.howsthat.design, local storage Your theme, and whether you closed the getting-started card Until you change it or clear your browser storage Preference you asked for
annotate:reply:…
annotate:web-banner-dismissed
annotate:snapshot-banner-dismissed
The app and review sidebar, session storage Unsent replies, and notices you closed Until you close the tab Strictly necessary
Extension storage How’s that? extension, in your browser Sign-in token, project addresses, theme, drafts and unpublished journey steps Sign-in ends after 30 days without use, 90 days at most. Everything is deleted when you remove the extension Strictly necessary

6. Changing your choice

You can change or withdraw your consent to analytics or advertising at any time. It takes effect straight away and doesn’t affect anything stored before.

You can also delete cookies and site data in your browser’s settings, or block them. If you block the app’s cookies, you won’t be able to sign in.

7. Changes to this notice

We will update this notice whenever we add or change anything we store, and change the date at the top. If we add anything that needs your consent, we will ask again.

Questions? Email [email protected].

See also our privacy notice and terms of service.