Cookie Policy
Last updated 27 September 2026
The short version
Eligna stores a small amount of data in your browser. Some is necessary to sign you in, keep the app working, and keep it secure. Analytics and session replay run only if you turn them on. Error monitoring runs to keep the app reliable, and is kept minimal. We do not use advertising cookies, cross-site tracking, or fingerprinting, and we do not sell your data. You can change your choice at any time in Cookie preferences.
Necessary (always on)
These are needed for the app to work and stay secure, so they do not need consent.
- Supabase auth session. Keeps you signed in so you do not have to log in every time. Stored in your browser’s local storage, not a cookie. Set when you sign in, cleared when you sign out. Set by Supabase (our backend, EU). Duration: until you sign out or the session expires.
eligna_cookie_consent. Remembers your cookie choices on this device, so we do not ask again and can honour what you picked. Set by Eligna, on your device. Duration: until you clear it or change your choice.- App data and preferences. Storage on your device (local storage and IndexedDB) that keeps the app quick and usable offline: a copy of your recent data and screens, a copy of your AI chat history (the conversations themselves are saved to your account), changes made offline that are waiting to be sent, unsaved drafts, view preferences, light/dark theme, and the last tab you were on. Set by Eligna. Duration: the copies of your data and your offline changes are cleared when you sign out; preferences stay until you clear them.
- Cloudflare Turnstile. Runs a privacy-friendly check on the sign-in and sign-up pages to tell real people from bots. Cloudflare may set a short-lived cookie on its own check domain as part of this. It is not used to track you across sites. Set by Cloudflare. Duration: short-lived, per check.
Analytics (off unless you turn it on)
Privacy-friendly product analytics that show us which pages and features are used, so we know what to improve. Provided by PostHog and stored in the EU. No ads. Declining does not change how the app works.
ph_[project key]_posthog. A device and session identifier so page views and events can be grouped into a session. This is how usage is measured. Not used for advertising. Set by PostHog (EU cloud). Duration: up to 12 months.__ph_opt_in_out_[project key]. Records that you allowed analytics, so PostHog respects your choice. Set by PostHog (EU cloud). Duration: up to 12 months.
Session replay (off unless you turn it on)
A separate choice from analytics, because it is more revealing. It can only be turned on if analytics is on. Session replay records how the interface responds while you use it, so we can find confusing screens and bugs. Your text, form fields, and photos are masked before anything leaves your device. It is provided by PostHog (EU) and Sentry (US), and reuses their storage rather than setting extra cookies. Recordings are kept for 30 days by PostHog, and up to 30 days by Sentry on our current plan; if our plan changes this may be longer, and we will update this policy. See how long we keep data in the Privacy Policy. Turning it off stops recording.
Error monitoring (always on, kept minimal)
Runs without consent, to keep the app reliable and secure (a legitimate interest). When something crashes, a technical error report is sent to Sentry, a US provider. Because this data leaves the EU, it is kept minimal: no IP address, and no record of your clicks, typing, or the details in page addresses. You can object by emailing us.
- Sentry error diagnostics. A small amount of browser storage used to group errors from the same visit, so a crash report is useful. Not used to track you or to profile your behaviour. Set by Sentry (United States). Duration: per visit / short-lived.
What we do not use
Advertising or marketing cookies; cross-site or social media tracking cookies; fingerprinting or device tracking; selling or sharing your data with data brokers.
Changing or withdrawing consent
You can change your choice at any time, from Cookie preferences in your account settings. Turning something off stops it going forward. You can also delete stored data through your browser settings, though deleting the sign-in data will sign you out.
Changes
If we add or materially change what we store, we will update this policy and ask for your choice again before the change takes effect.
Contact
Questions about cookies or data: privacy@eligna.app.