Legal
Cookie Policy
Last updated: October 9, 2026
Learn which cookies GAMESLIKE uses for essential account features and optional analytics, how consent works, and how to update your preferences.
Current Position
Where we ask first, GAMESLIKE loads Cloudflare Web Analytics and EU-hosted PostHog with Usage analytics consent, and Sentry with separate Error reports consent; the Privacy Policy lists those regions. Elsewhere these providers run by default until you turn them off in Cookie settings, and Global Privacy Control or DNT turns them off automatically. Reject all keeps all optional providers off and leaves the site available.
Anonymous server totals for public page requests, broad referring sources, device types and countries, automated requests by type, search outcomes and outgoing store links continue before a choice and after rejection. They use no analytics cookies or browser storage and send no visitor IP addresses or visitor identifiers to PostHog. See Anonymous Request and Store-Link Counts in the Privacy Policy.
Simple Analytics, Google Analytics, advertising tags, affiliate pixels, and affiliate attribution cookies are not loaded by the application.
Strictly Necessary Storage
The site may use strictly necessary cookies or storage for authentication, Steam sign-in state, security, account consent records, and protection against broken script reload loops.
Play Together uses one essential HttpOnly `pt_room_` cookie per room you create or join, lasting at most 24 hours. It authorizes only that room and is not used for analytics. Removing the cookie ends that browser's guest access; a room invitation can be used to join again while valid.
`gameslike_steam_openid_state` keeps the Steam sign-in request tied to the browser that started it. It is HttpOnly, same-site, and expires after 10 minutes.
Google and Steam may create a short-lived, unfinished local account after they verify your identity. It cannot access account features until you accept the account terms. Choosing Not now removes the unfinished account and its local session. Accounts abandoned for more than 24 hours are removed during normal account-session maintenance after that point.
GAMESLIKE sets a strictly necessary session cookie after sign-in so the account stays signed in. Its lifetime follows the configured GAMESLIKE session settings.
Cloudflare may set `cf_clearance` when JavaScript detections or security challenges are enabled at the edge. This cookie supports bot and security checks; Cloudflare controls the exact lifetime and attributes.
The `gameslike-chunk-reload` sessionStorage key is only written after a failed Next.js chunk script load and prevents repeated reload loops.
The `gameslike-pending-save` sessionStorage key temporarily remembers one game you chose to save before signing in. It expires after 15 minutes and is cleared when the save is resumed or you cancel sign-in.
Analytics Preference
The necessary gameslike_referrals_consent_v1 cookie stores the separate Referral tracking choice and timestamp for 180 days, with Path=/, SameSite=Lax, and Secure on HTTPS. Missing, malformed, expired or future-dated acceptance keeps Impact attribution off. This choice never inherits the regional analytics default. Reject all records a refusal for referral tracking as well as analytics and error reports. Turning off Referral tracking stops future GameBoost links using Impact; requests already sent may finish and earlier records on external sites remain subject to those sites' controls.
The necessary `gameslike_consent_v10` cookie records `accepted` or `rejected` with the decision timestamp for 180 days, Path=/, SameSite=Lax, and Secure on HTTPS. A missing or malformed value counts as no choice: where we ask first, optional providers stay off; elsewhere the regional default applies. A regional default is never stored; it is looked up on each visit. A valid rejection in the earlier `gameslike_consent_v4` cookie remains respected, as do v5, v6, v7, v8 and v9 rejections. Earlier acceptance requires a fresh purpose-specific choice. The necessary `gameslike_diagnostics_consent_v1` cookie separately stores the Error reports choice and timestamp for 180 days with the same cookie attributes.
Usage analytics lets Cloudflare and PostHog measure visits and performance. PostHog additionally measures traffic sources, campaigns, approximate location, repeat visits, clicks, search outcomes, game selections, filters, saving friction, and store interest. Only with your acceptance does EU-hosted PostHog also measure account creation method, return use, and whether you save or import games. These account events use a random account analytics identifier, not your email, name, Steam ID, Google account, or browser history. Heatmaps and masked session replays help explain usability problems, with form contents excluded and account pages omitted from replay. Error reports lets Sentry receive exception types and source-code locations without error-message text, account identifiers or replay, and PostHog error categories when Usage analytics is also on.
PostHog's `ph_*_posthog` first-party cookie keeps a pseudonymous browser identifier, session state, and attribution information for up to 180 days from its last update. It is restricted to the current host and uses Secure on HTTPS. PostHog also uses sessionStorage for temporary tab and session state. This optional storage is only enabled while Usage analytics is on. Cookie lifetime is separate from server-side event retention, described in the Privacy Policy.
Use Cookie settings on any page to reopen the choice. Selecting Reject all stops new browser PostHog and Sentry events and replay capture, removes PostHog analytics storage, and reloads the page to stop the other optional providers. Requests already sent may finish. Necessary authentication and security storage is not removed.