Cherry Seed

Does the 7-day limit apply to all Safari users?

safari 7-day limit itp all users webkit restriction ios cookie cap javascript cookies 24-hour expiration apple devices

Quick Answer

Yes — Safari's seven-day cookie expiration for JavaScript-set cookies applies to every Safari user on macOS, iOS, and iPadOS by default. It is not a setting users enable or can disable — Intelligent Tracking Prevention is built into WebKit and runs automatically. In stricter cases, cookies set after a user clicks an ad or navigates from a classified tracking domain expire after just 24 hours. All browsers using the WebKit engine on Apple devices inherit these restrictions, including in-app browsers within Instagram, Facebook, TikTok, and other iOS apps. Apple reports over 1.8 billion active devices globally, making this restriction the single largest source of cookie-based attribution loss for WooCommerce stores.

Full Answer

Safari's ITP cookie restrictions are not optional privacy settings — they are architectural decisions embedded in the WebKit rendering engine that Apple mandates for all browsers on its platforms.

On macOS, Safari is the default browser and holds approximately 20% of desktop browser market share in most Western markets. Every Safari user on macOS runs ITP with the seven-day cookie cap active. There is no Safari preference to disable it. Users who want longer cookie lifespans must switch to a different browser entirely.

On iOS and iPadOS, the impact is significantly larger. Apple requires all browsers on iOS to use the WebKit rendering engine — Chrome on iOS, Firefox on iOS, and every other browser on iPhone and iPad are WebKit browsers under the hood. This means the seven-day cookie limit applies not just to Safari but to every browser on every iPhone and iPad, regardless of which browser icon the user taps.

The 24-hour restriction is even more aggressive. When Safari classifies a referring domain as a tracker — using machine-learning classification that evaluates cross-site request patterns — cookies set by JavaScript after navigating from that domain expire in 24 hours instead of seven days. This means a visitor who clicks a Facebook ad and lands on your WooCommerce store has just 24 hours before their attribution cookie expires.

For WooCommerce stores, the practical impact is straightforward: any customer journey that spans more than seven days — or more than 24 hours from an ad click — breaks client-side attribution completely. Server-side cookies set via HTTP headers from a first-party domain are not subject to these restrictions, which is why server-side tracking preserves full cookie lifespans where client-side JavaScript cannot.

Sources

Programmatic Access

GET https://seresa.io/wp-json/cherry-tree-by-seresa/v1/seeds/679

Cite This Answer

Cherry Tree by Seresa - https://seresa.io/seed/safari-browser-privacy/safari-7day-cookie-limit-7day-all-safari-users