Cookies are small files that websites store on your computer to remember information about you

When you visit a website, the site can ask your browser to save a tiny text file called a cookie. That file sits on your device and contains information the website wants to remember — your login details, what you put in your shopping cart, your language preference, or what pages you visited. The next time you go back to that site, your browser automatically sends the cookie back, and the website reads it.

Cookies are not programs. They cannot run code, steal files from your computer, or spread viruses. They are just text — like a note that says "this person's username is alex" or "this person added a blue shirt to their cart." But because they track behavior across visits, they raise real privacy questions about what companies know about you and what they do with that information.

Key Takeaways

  • Cookies are text files that websites store on your device to remember information about you between visits.
  • First-party cookies come from the website you are visiting; third-party cookies come from advertisers or data brokers embedded in that site.
  • You can see what cookies a site has stored, delete them, and block new ones through your browser settings.
  • Websites must tell you they use cookies and get your consent in most countries, though the rules and enforcement vary.
  • Blocking all cookies can break some websites, but you can usually allow cookies from the site itself while blocking tracking cookies from advertisers.

How cookies actually work: the three-step cycle

The first time you visit a website, the site's server sends your browser a cookie. Your browser stores it in a folder on your device. The cookie includes the website's name, an expiration date (some expire when you close your browser; others last for years), and whatever data the site wants to remember.

When you visit that website again, your browser checks for cookies from that site, finds them, and automatically sends them back to the server before the page even loads. The server reads the cookie and uses the information inside it — for example, it might see your username and log you in without asking for your password again.

If you delete the cookie, the website no longer has that information. If you block cookies from that site entirely, the website cannot store new ones, though it can still see you as a new visitor each time.

First-party cookies versus third-party cookies: who is actually watching

First-party cookies come from the website you are actively visiting. Amazon stores a first-party cookie when you shop on Amazon.com. That cookie helps Amazon remember your cart, your address, and your login. This is the cookie doing the job it was designed for — making your experience on that one site smoother.

Third-party cookies come from other companies embedded in the website you are visiting. If you go to a news site and see an ad for shoes, that ad is often served by an advertising network like Google Ads or Facebook Pixel. That network stores a third-party cookie on your device. Now the ad network knows you visited a news site. If you visit another site that also uses the same ad network, that network sees that too. Over time, the ad network builds a profile of your browsing habits across dozens or hundreds of sites — even though you never directly visited the ad network's own website.

This is why you see ads for shoes following you around the internet. The ad network's third-party cookie is tracking your movement across sites and selling that information to advertisers.

What information do cookies actually contain

A cookie is usually small — often just a few hundred bytes. It typically contains a unique identifier (a random string of numbers and letters), the website's domain name, an expiration date, and whatever custom data the site chose to store. A login cookie might contain your username. A shopping cart cookie might list the product IDs and quantities you added. A tracking cookie might contain a number that identifies you as "user 4829374" across multiple websites.

Cookies do not contain your password, your credit card number, or your Social Security number — at least not in legitimate use. Websites store that sensitive information on their own servers, not in cookies. But a cookie can contain enough information to identify you or track your behavior, which is why privacy matters.

Browser settings: how to see, delete, and block cookies

Every major browser lets you see what cookies are stored on your device. In Chrome, go to Settings, then Privacy and Security, then Cookies and Other Site Data. You will see a list of websites and how many cookies each one has stored. You can delete all cookies at once, or delete cookies from a specific site.

You can also set rules for how your browser handles cookies going forward. Most browsers offer three main options: allow all cookies, block third-party cookies only, or block all cookies. Blocking all cookies will break many websites — you will not be able to stay logged in, your shopping cart will disappear, and sites may not remember your preferences. Blocking third-party cookies is usually the middle ground: you stay logged in and your cart works, but advertisers cannot track you across sites.

Firefox, Safari, and Edge all have similar settings. Safari blocks third-party cookies by default. Chrome does not yet, though Google has said it plans to phase them out. You can also install browser extensions like uBlock Origin or Privacy Badger that block tracking cookies without breaking the sites you use.

Cookie consent notices and what they actually mean

In the European Union, the ePrivacy Directive requires websites to get your consent before storing cookies. In California, the California Consumer Privacy Act gives you the right to know what data is collected and to delete it. Many other countries have similar rules, though the details vary widely.

This is why you see a cookie notice on most websites — usually a banner at the bottom or top of the page saying "We use cookies" with buttons to accept or decline. However, these notices vary in how much choice they actually give you. Some let you accept all cookies with one click but make declining harder. Some let you choose which types of cookies to allow. Some do not let you decline at all and only let you "learn more."

The notice itself does not protect you. It is just a legal requirement. What matters is what you actually do when you see it — whether you read the privacy policy, whether you block third-party cookies in your browser settings, and whether you delete cookies regularly.

Why websites use cookies and what they track

Websites use first-party cookies for legitimate reasons: to keep you logged in, to remember your preferences, to store your shopping cart, to track how many people visit the site. These functions make websites work better.

Websites use third-party cookies because advertisers and data brokers pay them to. The ad network learns what you are interested in, sells that information to other advertisers, and the website gets a cut of the revenue. This is how many free websites stay free — they trade your attention and your data for content.

Some websites also use cookies to track how you interact with the page — which links you click, how long you stay, whether you scroll to the bottom. This information helps the website owner understand what content works and what does not. But it also means the website owner knows your behavior in detail.

Frequently Asked Questions

Can cookies give me a virus or hack my computer?

No. A cookie is just text. It cannot execute code, read files, or access your hard drive. However, a hacker could theoretically steal a cookie if they intercept your internet traffic, which is why using HTTPS (the padlock icon in your address bar) matters — it encrypts cookies so they cannot be read in transit.

If I delete all my cookies, will websites still work?

Most will, but some features will break. You will be logged out of every site. Your shopping cart will empty. Sites will not remember your language or theme preference. You can delete cookies from specific sites you do not trust while keeping cookies from sites you use regularly.

Do I need to delete cookies regularly?

Not for security reasons — deleting cookies does not protect you from viruses or hacking. But deleting third-party tracking cookies regularly does limit how much data advertisers collect about you. Many people delete cookies monthly or quarterly as part of general privacy maintenance.

What is the difference between cookies and tracking pixels?

A tracking pixel is a tiny invisible image embedded in a website or email. When you load the page or open the email, your browser downloads the pixel, and the server that hosts it learns you viewed that page or email. Pixels do not require storage on your device the way cookies do, but they serve the same purpose: tracking your behavior.

Will blocking cookies stop ads from showing up?

No. Blocking cookies stops targeted ads — ads chosen based on your browsing history. You will still see ads, but they will be generic ones based on the page you are viewing, not on what you looked at last week. Some websites block access if you refuse cookies, but most will still let you browse.