# Cookies and analytics | Lyro

> The cookies Lyro sets, how our first-party analytics works under the UK statistical-purposes exception, and how to turn analytics off.

Source: https://lyromusic.com/legal/cookies

# Cookies and analytics

Last updated 21 September 2026

We set a small number of first-party cookies: to keep you signed in, to remember your choices, to credit a friend's invite if you open an invite link, and to count visits so that we can improve the site. We use no advertising cookies and no third-party tracking cookies. You can turn analytics off at any time with the "Analytics: on/off" switch in the footer of every page.

This summary is a guide and is not legally binding wording.

## 1. What we use

A cookie is a small text file that a website asks your browser to store. Lyro sets eight cookies, all from our own domain. Four are essential, one is used only during Google sign-in, one is set only when you open a friend's invite link, and two support our own analytics.

We use no advertising cookies and no third-party tracking cookies. We load no advertising tags, social media widgets or third-party analytics scripts.

## 2. The cookies we set

| Name | Purpose | Duration | Type |
|---|---|---|---|
| lyro_s | Keeps you signed in. It holds a random session token. It is HttpOnly, which means scripts in the page cannot read it. | 30 days, or until you sign out | Essential |
| lyro_in | Tells our public pages that you are signed in, so the header can show "Open studio" instead of "Log in". It holds the value 1 and no identifier. | 30 days, or until you sign out | Essential |
| lyro_g | Protects Google sign-in against forgery while you are on Google's page. Set only if you choose Google sign-in. HttpOnly. | 10 minutes | Essential |
| lyro_ref | Set only when you open a friend's invite link. It holds the inviter's code, so that the invite can be credited if you create an account and start a plan. That is its only use. It holds nothing about you, and it is HttpOnly. | 30 days | Invite |
| lyro_optout | Remembers that you turned analytics off. | 12 months | Essential |
| lyro_notice | Remembers that you have seen the analytics notice, so that it is not shown again. | 12 months | Essential |
| lyro_a | A random identifier for our own analytics, so that visits from the same browser count as one visitor. It holds no name or email address. | 12 months. Deleted when you turn analytics off. | Analytics |
| lyro_v | Keeps you on the same version of a page while we test two versions against each other. It holds a short label for the version, not an identifier for you. | The length of the test, and never more than 12 months | Analytics |

## 3. Other storage in your browser

Our analytics also keeps two entries in your browser's session storage, which the browser clears when you close the tab. `lyro_sid` is a random identifier for the current visit, and it is replaced after 30 minutes without activity. `lyro_ctx` holds the address of the site that referred you and any campaign tags in the link you followed, read once on the first page. Both are removed when you turn analytics off.

The quiz, the prompt generator and the studio also keep a few entries in your browser's local or session storage, all with names that start with `lyro_`. They hold your quiz answers until you finish, an unsent draft in the studio, a generation that is waiting while you sign up or choose a plan, which first steps you have completed, and which in-app messages you closed during this visit. They exist so that your work is not lost between pages and so that messages you closed stay closed. None of them is an identifier, none is used to follow you, and clearing your browser's site data removes them.

## 4. How our analytics works

Our analytics is first-party: our own script sends events to our own server, and the data stays in our own database. We use it only to see how the site and the studio are used, so that we can improve them.

It records:

- pages viewed, page titles and the width of the browser window;

- sections that came into view, how far you scrolled and how long you stayed;

- clicks on buttons and links that we have marked, and which questions you opened;

- the site that referred you, campaign tags, browser language, device type, whether you are inside an app's built-in browser, and your country;

- steps such as finishing the quiz, signing up, starting a checkout and making a first track.

It does not record what you type, it does not fingerprint your device, and it does not follow you to other websites. Our analytics tables store the country that our host derives from your IP address, not the address itself. We share the data with nobody except the providers that host it for us.

We do not join your browsing on our public pages to an account. A visit is recorded under the random identifier in `lyro_a`, with no account identifier. If a visit leads to a sign-up or a purchase, our server marks the visit with a yes, so that we can see which pages help people get started. The [privacy notice](https://lyromusic.com/legal/privacy#analytics) explains this in full. Events are deleted after 120 days and visit summaries after 400 days.

## 5. Why you see a notice and not a consent banner

UK law normally requires consent before a website stores anything on your device that is not essential. Since 5 February 2026 the Privacy and Electronic Communications Regulations have an exception for statistical purposes. It applies when:

- the only purpose is to collect statistics about how a service is used, in order to improve it;

- the information is not shared with anyone else, except to help with that improvement;

- visitors are told clearly what is happening;

- visitors have a simple, free way to object.

We rely on that exception for `lyro_a`, `lyro_v` and the two session storage entries. This page and the notice on your first visit are the explanation. The footer switch is the way to object.

The other cookies need no consent because each is strictly necessary for something you asked for: signing in, Google sign-in, remembering your analytics choice, and, for `lyro_ref`, crediting the invite whose link you opened.

## 6. How to turn analytics off, and what happens

There are two ways, and both work without an account:

- In the footer of every page, select "Analytics: on". The label changes to "Analytics: off".

- On your first visit, choose "Turn off" in the analytics notice at the bottom of the page.

When you turn analytics off:

- we set `lyro_optout` for 12 months and delete `lyro_a`;

- the session storage entries are removed, and any events waiting to be sent are discarded;

- the tracker stops recording, and our server ignores any analytics request that arrives with the opt-out cookie;

- the page version in `lyro_v` is no longer reported to us;

- our server still counts each page request in a daily total for that page, with no cookie and no identifier.

The choice is stored in that browser only. If you clear your cookies, or use another browser or device, set it again. Select the switch again to turn analytics back on.

Data collected before you objected is deleted on the normal schedule. If you have an account, you can ask us to erase the analytics linked to it sooner.

## 7. Resources from other companies

Four things involve another company's servers.

- **Google Fonts.** Our pages use the Instrument Sans typeface. Your browser fetches the stylesheet from fonts.googleapis.com and the font files from fonts.gstatic.com, which are Google's servers. Google therefore receives your IP address and basic browser details, as with any web request. Google says in its [Google Fonts privacy FAQ](https://developers.google.com/fonts/faq/privacy) that the fonts service does not set cookies.

- **Stripe Checkout.** When you pay, you leave our site for a checkout page on Stripe's own domain. Stripe sets its own cookies there, including cookies that it uses to prevent fraud. See the [Stripe cookies policy](https://stripe.com/legal/cookies-policy).

- **Google sign-in.** If you choose it, you pass through Google's sign-in page, where Google's own cookies apply.

- **Cloudflare Turnstile.** When we switch this check on, the sign-up page loads it from challenges.cloudflare.com to tell people from automated programs. To do that, Cloudflare receives your IP address and details of your browser, and it may store and read information in your browser, such as a short-lived challenge cookie. This is used only for security and is strictly necessary for the check, so the analytics switch does not affect it. See Cloudflare's [Turnstile privacy addendum](https://www.cloudflare.com/turnstile-privacy-policy/) and its [list of cookies](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/).

## 8. Controlling cookies in your browser

Every browser lets you see, block and delete cookies, usually under Settings and then Privacy. You can delete cookies for one site or for all sites, and you can block them in advance.

Three things to know. If you block `lyro_s`, you cannot sign in. If you delete all cookies, you also delete `lyro_optout`, so analytics turns back on until you switch it off again. If you block or delete `lyro_ref` before you sign up, the invite cannot be credited.

## 9. Changes and contact

If we add, remove or change a cookie, we update the table on this page and the date at the top. The [privacy notice](https://lyromusic.com/legal/privacy) explains what else we do with personal data and the rights you have. For questions, use [the contact form](https://lyromusic.com/contact) or [hello@lyromusic.com](mailto:hello@lyromusic.com).
