Skip to content
CookieTosser

How cookie lifetimes work, and why a 13-month _ga matters

Published September 27, 2026

A cookie's lifetime is just a date the site chooses when it sets the cookie — there's no external limit written into the cookie standard itself. That date is also one of the more revealing things a cookie can tell you: a two-year expiry on an analytics cookie means someone decided that recognizing the same browser two years from now was worth doing, which only makes sense if the purpose is tracking a person over time, not fixing a single visit.

What "lifetime" means, technically

When a cookie is set, it can carry an Expires date or a Max-Age (a number of seconds from now); without either, it's a session cookie that disappears when the browser closes. Everything else is a persistent cookie, and the expiry is set by whoever wrote the code that creates it — the site, or a script it loaded from a vendor. Nothing forces that date to be reasonable. A cookie can legally ask to persist for years, which is why lifetime limits, where they exist, come from browsers or regulators rather than the cookie mechanism itself.

The _ga example

_ga, the identifier Google Analytics uses to distinguish one browser from another, ships with a default expiry of two years in Google's own documentation. That's a long time for a single analytics identifier to persist, and it's part of why analytics cookies are treated as needing consent rather than falling under the strictly-necessary exemption (see what counts as valid consent).

France's data protection authority, the CNIL, has published guidance recommending that cookies requiring consent should not be valid for longer than 13 months, and that the underlying measurement data shouldn't be kept longer than 25 months. This is a French regulatory recommendation rather than a rule written into the GDPR or the ePrivacy Directive text itself, but it's widely treated across the EU as the de facto ceiling for a "reasonable" cookie lifetime, and it's exactly why 13 months — not Google's 2-year default — shows up so often in cookie policies and consent-platform configuration screens.

That gap between the documented default and the recommended cap shows up in this site's own data: our scans measure the median real-world lifetime a cookie is actually observed with, separately from what a vendor's own documentation claims. For _ga, the vendor-documented retention is 2 years, but the lifetime we actually observe across sites clusters much closer to 13 months — a sign that a meaningful share of sites have configured Google Analytics to respect CNIL's recommendation rather than shipping Google's untouched default. You can see both numbers on the _ga cookie page.

Browser caps: Safari's 7-day rule

Independent of any regulator, Safari's Intelligent Tracking Prevention (ITP) puts its own ceiling on certain cookies, regardless of what expiry date a site requests. Since ITP 2.1 (introduced in 2019), any cookie set via JavaScript's document.cookie — as opposed to an HTTP Set-Cookie response header — is capped at 7 days in Safari, no matter how far in the future the script asked for. Reload the site within that window and the timer can reset, but past 7 days without a fresh visit, the cookie is gone.

This specifically targets the pattern where a tracking script sets its own identifier straight from JavaScript running on the page, which is common for analytics and ad tags loaded as third-party scripts. It's a narrower rule than it might sound: a cookie set by the site's own server, in the response headers of the page itself, isn't subject to the 7-day cap — only ones a script sets client-side. That's part of why some analytics and advertising vendors moved toward server-side tagging (mentioned in first-party vs third-party cookies) — among other reasons, it sidesteps a limit that only applies to script-set cookies. Firefox and Chrome don't currently apply an equivalent blanket lifetime cap to first-party, script-set cookies; their approach to limiting tracking mostly targets third-party cookies and storage access directly rather than expiry dates. This changes as browsers update, so treat any specific browser behavior as accurate only as of when it was checked.

Two things people often get wrong about lifetime

Clearing your browser cache doesn't clear your cookies. They're stored separately, and most browsers list "Cookies and other site data" as its own checkbox distinct from "Cached images and files" in the clear-browsing-data dialog. A cache clear alone leaves every long-lived cookie exactly where it was.

Not everything with an expiry date is a cookie. Sites also write to localStorage and IndexedDB, which can hold an identifier just as effectively as a cookie can, but neither has a browser-enforced expiry at all — data placed there persists until the site's own code deletes it, or until you clear site data by hand. It doesn't show up in the Application tab's Cookies list, so a site that's moved its tracking identifier into localStorage can look "cookie-light" while storing exactly the same kind of long-lived identifier a cookie would. It's also outside the scope of most legal analysis that talks specifically about "cookies," even though the ePrivacy Directive's actual wording — "storing information, or gaining access to information already stored" — covers it too.

Reading lifetime as a signal

When you're looking at a cookie — whether in your own browser's DevTools (see how to check what a site loads) or in the cookie dictionary here — the lifetime tells you something about intent:

  • Session or under a day: almost always functional — a login token, a form's CSRF protection, a shopping cart.
  • Weeks to a few months: common for conversion-tracking cookies like _gcl_au or _fbp, which only need to bridge an ad click to a later purchase.
  • 13 months to 2 years: the range built for recognizing a returning visitor over the long term — the core purpose of most analytics and cross-session advertising cookies, and the range CNIL's guidance specifically targets.

A long-lived cookie isn't automatically a problem — some functional cookies, like a saved theme preference, reasonably last a long time too. But paired with an advertising or analytics category (see what the tracker categories mean), lifetime is one of the clearest tells that a cookie exists to build a profile over time rather than to make one visit work.

Related guides