Cookie Policy for Obsidian Stats

Last updated: November 22, 2025

Summary: Obsidian Stats uses minimal cookies. We use ONE httpOnly secure cookie for authentication (refresh token, 7 days expiry). Our analytics platform (Plausible), advertising network (EthicalAds), and feature flag platform (GrowthBook) are all self-hosted and use NO cookies at all.


Cookies Used by Obsidian Stats

1. Essential Authentication Cookie (First-Party)

Cookie Name: Refresh Token (httpOnly, secure)
Purpose: Used to maintain your login session and automatically refresh your access token
Duration: 7 days
Type: First-party, httpOnly, secure, SameSite=Strict
Category: Strictly Necessary - Required for authentication functionality
Personal Data: Session identifier (no readable personal data in cookie itself)
Optional: Yes - Only set if you choose to sign in with Google OAuth

2. Analytics (Cookieless)

Service: Plausible Analytics (Self-Hosted)
Cookies Used: NONE
Tracking: Cookieless, privacy-focused analytics
Personal Data: None - fully anonymized
Opt-out: Not available (no personal data collected, GDPR compliant)

Plausible Analytics is a privacy-focused analytics service that we self-host at plausible.obsidianstats.com. It does not use cookies, does not collect personal data, and does not track users across websites. All data collected is fully anonymized and aggregated. Learn more at Plausible Privacy Policy.

3. Local Storage (Browser-Only, Not Transmitted)

Data Stored: Favorite plugins list, access token (15-minute expiry), feature flag user ID, user email (when logged in)
Purpose: Store your favorite plugins locally, cache authentication tokens, and identify you for feature flags and A/B testing
Transmission: Never sent to our servers
Duration: Until you clear browser storage
Category: Functional - Enhances user experience
Optional: Yes - You can clear localStorage at any time

4. Feature Flags & A/B Testing (Cookieless, Uses localStorage)

Service: GrowthBook (Self-Hosted on Our Infrastructure)
Cookies Used: NONE
Storage: Uses browser localStorage only (no cookies)
Data Stored: User identifier (email if logged in, random UUID otherwise), feature flag evaluations
Self-Hosted: Fully hosted on our own infrastructure - no data shared with GrowthBook, Inc. or external parties
Tracking: No cross-site tracking, client-side only
Personal Data: User identifier for feature targeting (remains on our servers, not sold or shared)
Opt-out: Not available - feature flags are essential for site functionality

GrowthBook is an open-source feature flagging and A/B testing platform that we fully self-host on our own infrastructure at growthbookapi.obsidianstats.com. Because it is self-hosted, we maintain complete control over all data and no information is transmitted to GrowthBook, Inc. or any third-party services. It does not use cookies and stores all data in browser localStorage. Feature evaluations happen client-side in your browser. Learn more about the open-source project at GrowthBook Open Source.

5. Advertising (Cookieless)

Service: EthicalAds
Cookies Used: NONE
Tracking: No tracking, contextual ads only
Personal Data: None - no personal data collected
Privacy-focused: GDPR compliant, no cross-site tracking

EthicalAds is a privacy-focused advertising network that serves contextual ads based on page content only. It does not use cookies, does not collect personal data, and does not track users across websites. Learn more at EthicalAds Privacy Policy.


Analytics Disclosure

Important: Obsidian Stats uses Plausible Analytics to collect anonymized usage statistics automatically for all visitors. This analytics service:

  • Does not use cookies or any tracking technologies
  • Does not collect any personal information
  • Does not track users across websites
  • Collects only aggregated, anonymized data (page views, referrers, browser types, device types, country)
  • Is fully GDPR, CCPA, and PECR compliant
  • Cannot identify individual users

There is no opt-out mechanism for analytics because no personal data is collected. By using this website, you acknowledge that anonymized, non-personal analytics data will be collected.


How to Manage Cookies

Browser Settings

You can control cookies through your browser settings. Most browsers allow you to:

  • View what cookies are stored
  • Delete cookies individually or all at once
  • Block cookies from specific sites
  • Block all third-party cookies
  • Block all cookies (this may prevent you from using some features)

Learn how to manage cookies in popular browsers:

Authentication Cookie

If you block or delete the authentication cookie:

  • You will be logged out
  • You will need to sign in again to rate or review plugins
  • You can still browse and use all other site features without signing in

Local Storage

You can clear local storage through your browser's developer tools or privacy settings. This will clear your favorites list, feature flag identifier, and require you to sign in again if you were authenticated.


Contact Information

Owner and Data Controller

Contact email: [email protected]

For more information about how we handle your data, please see our Privacy Policy.