> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://contentful.com/developers/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://contentful.com/developers/docs/_mcp/server.

# Cookie policy

> The cookie policy for Contentful Personalization.

## Overview

Contentful Personalization uses browser storage and cookies to maintain visitor identity and cache personalization state. This page documents what is stored, where, and why.

## localStorage

Using any of our JavaScript SDKs will add the following `localStorage` items:

| Key               | Purpose                                                                                                                                                           |
| ----------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `nt_anonymous_id` | The visitor's anonymous profile ID. Used to identify the visitor across page loads without server-side cookies.                                                   |
| `nt_experiences`  | Cached experience selections (which variant was assigned to which experience). Allows the SDK to render the correct variant immediately on subsequent page loads. |
| `nt_profile`      | Cached visitor profile data (traits, audiences, session statistics). Reduces API calls on page load.                                                              |

If you use the [Privacy Plugin](/personalization/privacy-plugin), it also stores:

| Key          | Purpose                                                                                                         |
| ------------ | --------------------------------------------------------------------------------------------------------------- |
| `nt-consent` | The visitor's consent state. Used to determine whether the SDK should send events and enable location features. |

## Cookies

If you implement server-side or edge-side personalization, your middleware or server code should set the following HTTP cookie:

| Cookie  | Purpose                                                                                                                                                                                       | Recommended attributes                           |
| ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------ |
| `ntaid` | The visitor's anonymous profile ID for server-side personalization. Allows middleware and edge functions to identify returning visitors and call the Experience API with the correct profile. | `Path=/; Max-Age=31536000; SameSite=Lax; Secure` |

> **Info**
>
> **Important**:
> The `ntaid` cookie must always be set from the Experience API response (`response.data.profile.id`), not from the incoming request cookie. After profile merges or relocations, the canonical profile ID may change. Using the old value leads to duplicate profiles.

The `ntaid` cookie and `nt_anonymous_id` `localStorage` value represent the same profile ID. The SDK reads `nt_anonymous_id` in the browser. Server-side code reads `ntaid` from the cookie. Both should refer to the same visitor.

## sessionStorage

Contentful Personalization does not set any `sessionStorage` keys.

## Source reference

For reference, the storage key constants are visible in our [open-source SDKs](https://github.com/ninetailed-inc/experience.js/blob/eb4697294c0fdd43c6871ddcf28d094b08a1cd12/packages/sdks/shared/src/lib/constants.ts#L4).