Privacy

Persistent cookie

Also called stored cookie.

Persistent cookie is a cookie with an explicit expiry in the future, so it survives closing the browser. The date comes from Expires or Max-Age.

How it is measured

Read the Expires column in the storage panel. A date means persistent, and "Session" means it is not. Browsers cap the length; Chrome limits cookie lifetime to 400 days.

Sort your cookies by remaining lifetime. The longest ones show which tools remember visitors the longest, and which deserve the closest look.

Worked example

A flower shop's list has a login token at 30 days, a language setting at 1 year, and an ad ID at 400 days. The ad ID is the longest and the least necessary.

The owner removes the ad tool. The cookie list drops from nine items to six, and none of the remaining ones is over a year.

How it differs

A persistent cookie carries an expiry date and outlives the browser. A session cookie is dropped when the session ends. Persistent excludes automatic cleanup; session excludes memory across visits.

Common errors

Setting very long lifetimes by default. Assuming consent does not apply. Trusting the date in Safari. Never listing them. Keeping one with no purpose.

In practice

Pull the list, sort by lifetime, and ask what each is for. Shorten what can be shortened. Delete the rest.

See also

Session cookie, First-party cookie, Client ID

Sources

Count this on a real site.

Watch my website