dropley_session cookie to understand whether a visitor who lands on a marketing page starts an upload or successfully publishes an artifact. It contains a random identifier only; it is not an account, a login credential, or an artifact token.HttpOnly, Secure, and SameSite=Lax, with a 90-day lifetime. It is not shared with the separate published-artifact origin. The related measurement records retain only normalized discovery source, medium, optional campaign, and landing path—not full referrer URLs, arbitrary query strings, IP addresses, uploaded files, artifact tokens, or email addresses. See the Privacy Policy for details... traversal, hidden files, and deep nesting are rejectedCross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-originframe-ancestors: 'none' prevents embedding in third-party sites