Cookies are small files that websites store on your computer to remember things about you

A cookie is a text file, usually a few hundred bytes, that a website saves to your device when you visit it. The website can then read that file on your next visit. Cookies let websites remember your login information, what you put in your shopping cart, your language preference, or which articles you have already read. Without cookies, you would have to log in again every time you refreshed the page.

The word "cookie" comes from an old programming term for a small piece of data that a program leaves behind. It has nothing to do with the food. When you visit a website, the site's server sends a cookie to your browser — the program you use to view the web, like Chrome or Safari. Your browser stores it in a folder on your device. The next time you visit that same website, your browser sends the cookie back to the server, and the server reads it to know who you are or what you were doing.

Cookies are not programs and cannot run code on your device. They cannot steal your passwords or install malware. They are just text files with information in them. However, they can track your behavior across the web, which is why privacy matters with cookies.

Key Takeaways

  • Cookies are text files that websites store on your device to remember information about you between visits.
  • First-party cookies come from the website you are visiting; third-party cookies come from advertisers or analytics companies and track you across multiple sites.
  • Session cookies disappear when you close your browser; persistent cookies stay on your device until they expire or you delete them.
  • You can see what cookies a website has stored, delete them, or block them entirely through your browser settings.
  • Cookies cannot run programs or steal passwords, but they do create a record of your browsing habits that advertisers and data brokers can buy and sell.

First-party cookies versus third-party cookies

First-party cookies come directly from the website you are visiting. When you log into your email, the email service stores a first-party cookie on your device so you stay logged in. When you add something to a shopping cart, the store uses a first-party cookie to remember what you picked. These cookies are generally less of a privacy concern because they only track your behavior on that one website.

Third-party cookies come from a different domain than the one you are visiting. If you are reading an article on a news site and that site has an ad from Google, Google can place a third-party cookie on your device. Google can then read that cookie when you visit other websites that also have Google ads. This lets Google build a profile of your browsing habits across many sites — what news you read, what products you search for, what videos you watch. Advertisers buy this data to show you targeted ads.

Third-party cookies are the main reason many people feel tracked online. A single advertiser or data broker can follow you across hundreds of websites. For this reason, most browsers now block third-party cookies by default. Safari, Firefox, and Chrome all have settings that prevent third-party cookies from being stored, though you can turn this protection off if a website you use requires it.

Session cookies and persistent cookies

Session cookies exist only while you are using a website. They disappear when you close your browser. These are usually the least invasive kind of cookie. A session cookie might store your login token so you stay signed in while you are shopping, but once you close the browser, the cookie is gone and you have to log in again next time.

Persistent cookies stay on your device long after you close your browser. They have an expiration date set by the website — it might be a week, a month, a year, or even longer. Persistent cookies are useful for remembering your preferences or keeping you logged in across multiple visits. But they also mean a website or advertiser can track you for months or years. When you delete your browser history, persistent cookies often remain unless you specifically delete them.

How to see, manage, and delete cookies

Every major browser lets you see what cookies are stored on your device and delete them. In Chrome, open Settings, go to Privacy and Security, then Site Settings, then Cookies and Site Data. You will see a list of every domain that has stored a cookie on your device. You can delete all cookies at once or delete cookies from a specific website.

In Firefox, go to Settings, Privacy and Security, scroll to Cookies and Site Data, and click Manage Data. In Safari, go to Preferences, Privacy, and click Manage Website Data. You can see all stored cookies and delete them individually or in bulk.

You can also block cookies before they are stored. In Chrome, go to Settings, Privacy and Security, Site Settings, Cookies and Site Data, and choose "Block all cookies" or "Block third-party cookies." In Firefox, go to Settings, Privacy and Security, Enhanced Tracking Protection, and select Standard or Strict. In Safari, go to Preferences, Privacy, and check "Prevent cross-site tracking."

Blocking all cookies may break some websites — you might not be able to stay logged in, or a site might not remember your preferences. Most people find a middle ground: block third-party cookies and delete persistent cookies regularly, but allow first-party cookies so websites work normally.

What cookies reveal about you

A single cookie is just a small piece of information — a user ID, a timestamp, a preference setting. But when thousands of cookies from different websites and advertisers are combined, they paint a detailed picture of who you are. Advertisers and data brokers can see what you search for, what you buy, what you read, what videos you watch, where you go, and how long you spend on each site.

This data is valuable. Companies buy and sell information about your browsing habits to target ads, set prices, or assess your creditworthiness. A person who searches for medical conditions might see ads for treatments. A person who visits luxury car websites might see higher prices on some shopping sites. A person who visits job search sites might be flagged as a flight risk by their employer's data broker.

You cannot see most of this tracking because it happens behind the scenes. The cookies are there, but you do not know what data they are sending back to advertisers. This is why privacy advocates recommend blocking third-party cookies and deleting cookies regularly — it limits how much of a profile can be built about you.

The difference between cookies and other tracking methods

Cookies are one way websites track you, but not the only way. Pixels are tiny, invisible images that websites embed in pages or emails. When you load the page or open the email, the pixel loads from a server, and that server logs that you viewed the page. Pixels do not require cookies and cannot be blocked the same way.

Local storage and session storage are similar to cookies but can hold much more data — up to several megabytes instead of a few kilobytes. Websites use these to store information about you without sending it back to the server on every request. They are harder to find and delete than cookies because they are not visible in most browser settings.

Fingerprinting is a technique where a website collects information about your device — your browser type, your screen resolution, your installed fonts, your timezone — and combines it into a unique identifier. Even if you block cookies and clear your history, a website can recognize you by your fingerprint. Fingerprinting is harder to defend against because there is no single setting to block it.

Why websites use cookies and what they are for

Websites use cookies for legitimate reasons. A bank uses cookies to keep you logged in securely. A shopping site uses cookies to remember your cart. A news site uses cookies to remember which articles you have read so it does not show you the same ones twice. A streaming service uses cookies to remember where you stopped watching a show.

But websites also use cookies to track you for profit. An advertiser uses cookies to follow you across the web and build a profile of your interests. A data broker uses cookies to collect information about millions of people and sell it to other companies. A website might use cookies to test different versions of its design and see which one keeps you on the page longer.

Most websites disclose their cookie use in a privacy policy, but the policy is often long, vague, and written in legal language. Some websites ask for your consent before storing cookies — you may have seen a banner asking if you accept cookies. However, these banners are often designed to make it straightforward to accept and hard to refuse, so many people click yes without reading what they are agreeing to.

Frequently Asked Questions

Can a website see cookies that other websites stored on my device?

No. A website can only read cookies that it created itself, or cookies created by advertisers and analytics companies that are embedded on that website. A news site cannot read cookies that your bank created. This is called the same-origin policy, and it is a basic security rule built into all browsers.

If I delete my cookies, will websites know I deleted them?

No. When you delete a cookie, it is gone from your device. The website has no way to know you deleted it unless you visit the site again and it tries to read the cookie and finds it missing. Even then, the website just sees that the cookie is not there — it does not know whether you deleted it or your browser blocked it.

Are cookies the same as my browsing history?

No. Your browsing history is a record of the websites you visited, stored by your browser on your device. Cookies are files that websites store on your device. You can delete your browsing history without deleting cookies, and vice versa. Deleting one does not automatically delete the other.

Do I need to allow cookies for websites to work?

Most websites work fine with first-party cookies blocked, but some may not. If a website requires you to log in or uses cookies to store your preferences, it needs first-party cookies to function. You can usually allow first-party cookies while blocking third-party cookies, which gives you most of the functionality without most of the tracking.

What happens if I block all cookies?

Many websites will not work properly. You may not be able to log in, your shopping cart may not save, and sites may not remember your language or theme preference. Some websites will refuse to load at all. For this reason, most people block only third-party cookies or delete cookies regularly instead of blocking all cookies.