Cookie Policy
Last updated: September 3, 2026
What are cookies?
Cookies are small text files stored on your device when a website loads in your browser. This page explains which ones lupa.art uses, what each is for, and how to change your mind at any time.
How we use them
We sort cookies into two groups, and only one of them is a choice.
- Strictly necessary — signing you in, keeping your session and workspace, processing payments, protecting the site from abuse, and remembering which version of the interface to show you. The site does not work without these, and none of them identify you for measurement or advertising.
- Analytics and marketing — measuring how Lupa is used and whether our ads and affiliate links lead to sign-ups. These only run if you agree to them.
If you are in the EEA, the UK or Switzerland, nothing in the second group runs until you accept it. Elsewhere it is on by default, and you can switch it off at any time using the button below or from Settings → Account.
Manage your preferences
Change or withdraw your choice at any time. It takes effect immediately.
Strictly necessary
Always on. These cannot be switched off.
| Cookie | Duration | Purpose |
|---|---|---|
| __Secure-authjs.session-token | 30 days | Keeps you signed in. Set by Lupa when you log in. |
| lupa_consent | 12 months | Records the cookie choice you made here, so we do not ask again and so your choice is respected on every visit. |
| lupa_ff_id | 6 months | A random identifier used only to decide which version of the interface to show you, so the site does not change shape between page loads. It is never used to measure or advertise, and is deliberately not linked to your analytics identity. |
| lupa_flags | Browser session | Caches which interface features are switched on for you, so every page load does not have to ask again. |
| lupa_ref | 30 days | Set only if you arrive through a Lupa referral link (lupa.art/invite/…), so the person who invited you is credited when you sign up. Not readable by JavaScript, and never used for advertising. |
| __cf_bm | 1 hour | Set by Cloudflare to tell human visitors from bots and protect the site from automated abuse. |
| __stripe_mid | 1 year | Set by Stripe to recognise your device across sessions, for payment fraud prevention. |
| __stripe_sid | 30 minutes | Set by Stripe to identify a single checkout session, for payment fraud prevention. |
| m | 1 year 1 month | Set by Stripe for fraud prevention. Identifies the device used to access the site. |
Analytics and marketing
Only set if you accept them. Reject or withdraw at any time and none of these are written; the ones already on your device are cleared.
| Cookie | Duration | Purpose |
|---|---|---|
| ph_<project>_posthog | 12 months | Set by PostHog, our product analytics provider. Records which pages and features you use, errors you hit, and session replays, so we can see what is broken and what is worth building. Hosted in the EU. |
| _fbp | 3 months | Set by Meta to measure whether our ads led to a sign-up, and to show ads on Facebook and Instagram. |
| _twpid, guest_id, guest_id_ads, guest_id_marketing, muc_ads, personalization_id | Up to 2 years | Set by X (Twitter) to measure whether our ads led to a sign-up, and to show ads on X. |
| _fprom_tid, _fprom_ref | Up to 1 year | Set by FirstPromoter to credit the affiliate or creator whose link brought you to Lupa. |
| rewardful.referral | Up to 1 year | Set by Rewardful, our earlier affiliate programme, for the same purpose as above. |
Your browser
You can also block or delete cookies in your browser directly: Chrome, Safari, Firefox. Blocking strictly necessary cookies will stop parts of the site from working.
Questions
Write to [email protected] and we will answer. See also our Privacy Policy.


