# Storage & privacy

URL: https://docs.ablyft.com/developers/consent-and-security/storage-and-privacy/

> What ABlyft stores in the visitor's browser, how to configure it, and how visitors can opt out.



ABlyft remembers which variation a visitor has seen, so that the visitor sees the same version on every visit. For this, the
snippet writes a few entries to the browser. This page lists them and explains the settings that control them.

## Storage settings

Go to **Settings → Data Protection & Compliance** in your project. The section **Storage/Browser Settings** contains:

| Setting                    | What it does                                                                                           |
| -------------------------- | ------------------------------------------------------------------------------------------------------ |
| **Storage**                | Where ABlyft stores its data in the browser. See the table below. Default: **localStorage (default)**. |
| **Encode storage values**  | URL-encodes values written to cookies. Helps if cookie values cause problems in your setup.            |
| **Adhere to Do Not Track** | If enabled, ABlyft does not run for visitors whose browser has Do Not Track turned on.                 |

Options for **Storage**:

| Option                     | Behavior                                                                                                                    |
| -------------------------- | --------------------------------------------------------------------------------------------------------------------------- |
| **localStorage (default)** | All persistent data is stored in `localStorage`.                                                                            |
| **sessionStorage**         | All data is stored in `sessionStorage` and is gone when the tab is closed. Visitors can be re-assigned on their next visit. |
| **cookie**                 | All persistent data is stored in cookies.                                                                                   |
| **default (legacy)**       | Each entry uses its own storage type, as listed in the table below. Kept for existing projects.                             |

Entries marked "session" in the table below are always kept in `sessionStorage`, whichever option you choose.

> **Subdomains:** `localStorage` and `sessionStorage` belong to one exact host name (for example `www.example.com`). If visitors move
> between subdomains and should keep their assignment, use the **cookie** option. Cookies are shared across subdomains by
> default, see [Cookie settings](#cookie-settings).

## Cookie settings

The section **Cookie Settings** appears when **Storage** is **cookie** or **default (legacy)**.

| Setting                  | What it does                                                                                                                                                                                                                                                |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Max cookie lifetime**  | How long cookies are kept, in days. Required.                                                                                                                                                                                                               |
| **Custom cookie domain** | The domain the cookies are set for. If empty, `.domain.tld` of the current site is used, so cookies work across subdomains. Enter `only_current` to set cookies only for the exact (sub)domain. Handle with care; contact ABlyft support if you are unsure. |

ABlyft's cookies are set with `SameSite=Lax` and `Path=/`.

## What ABlyft stores

All entries start with `ablyft_`. They contain IDs and counters. Variation assignments are stored as experiment and
variation IDs.

| Key                       | Purpose                                                                                                                                                         | Storage                                                  |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
| `ablyft_exps`             | The variation assignment of the visitor: experiment ID to variation ID, for example `{"12345678":87654321}`                                                     | Configured storage (legacy: cookie)                      |
| `ablyft_uvs`              | Visit counters: first and last visit time, number of sessions and page views. Used for audiences such as new versus returning visitors.                         | Configured storage (legacy: cookie)                      |
| `ablyft_queue`            | Events waiting to be sent. Removed after sending, or when older than one hour.                                                                                  | Configured storage (legacy: cookie, kept for 30 seconds) |
| `ablyft_tgoals`           | Goals the visitor already triggered, per variation. Used to count a goal only once where required.                                                              | Configured storage (legacy: `localStorage`)              |
| `ablyft_tracking_consent` | The consent state: `1` consented, `0` declined. Set by [`enableTrackingConsent` / `disableTrackingConsent`](https://docs.ablyft.com/developers/consent-and-security/consent-manager/). | Configured storage (legacy: cookie)                      |
| `ablyft_opt_out`          | Set to `true` when the visitor [opted out](#opt-out).                                                                                                           | Configured storage (legacy: cookie)                      |
| `ablyft_redirect`         | Time of the last redirect, to prevent redirect loops.                                                                                                           | Configured storage (legacy: `sessionStorage`)            |
| `ablyft_session_check`    | Marks that a session is running.                                                                                                                                | Session                                                  |
| `ablyft_temp_events`      | Events held back until the tracking rule allows tracking, see [Consent manager](https://docs.ablyft.com/developers/consent-and-security/consent-manager/).                             | Session                                                  |

Further entries exist only in special modes and only in `sessionStorage`: `ablyft_pinged_goals` (goals recorded in preview
mode), `ablyft_preview_combs`, `ablyft_exclude_running` and `ablyft_qa_token` (preview and QA, see [URL parameters](https://docs.ablyft.com/developers/reference/url-parameters/)),
and `ablyft_show_debug` (debug mode).

Without consent, persistent entries are kept in memory only, see
[Consent manager](https://docs.ablyft.com/developers/consent-and-security/consent-manager/#how-it-works).

## What is sent to ABlyft

Events are sent to the tracker (`https://log.ablyft.com`) when a visitor is assigned to a variation or triggers a goal. See
[Security](https://docs.ablyft.com/developers/consent-and-security/security/#what-the-snippet-sends) for the content.

## Do Not Track

If **Adhere to Do Not Track** is enabled and the visitor's browser reports `doNotTrack` as `1`, the snippet stops for
this visitor: it shows no variations and sends no events.

## Opt out

Visitors can exclude themselves from ABlyft on your site with a URL parameter:

| URL                                             | Effect                                                                                                                          |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| `https://www.example.com/?ablyft_opt_out=true`  | Stores `ablyft_opt_out=true`. ABlyft no longer runs for this browser. A message "Opted out of ABlyft for this domain" is shown. |
| `https://www.example.com/?ablyft_opt_out=false` | Removes the opt-out. A message "Opted in of ABlyft for this domain" is shown.                                                   |

The opt-out applies per site (and storage), so it has to be done on every site where it should apply. It is also a handy
way to exclude your own team from experiments.

> The opt-out is stored with the configured storage option. If you use `localStorage` or `sessionStorage`, it is not
> shared between subdomains, and clearing the browser data removes it.

## Next steps

- [Consent manager](https://docs.ablyft.com/developers/consent-and-security/consent-manager/): Wait for consent before storing and tracking.
- [URL parameters](https://docs.ablyft.com/developers/reference/url-parameters/): All parameters the snippet reads.

