Cookie policy

Small files, limited purpose

Postiva uses browser storage for security and requested preferences. Measurement before your choice is cookieless. PostHog analytics storage and fully masked replay are enabled only after you allow analytics.

Last updated 2 September 2026

Your analytics choice

Before you choose, and if you continue anonymously, PostHog receives cookieless pageviews, page performance timings, and browser errors without a persistent identity. No cookies and no browser storage are used for this, and no identifier follows you between visits. If you allow analytics, Postiva also sends curated product events under a pseudonymous identifier and enables session replay with all rendered text and form inputs masked.

Advertising, cross-site tracking, and automatic interaction capture are disabled. Replay does not record console logs, request or response bodies, or network headers. You can change your choice at any time below.

Cookies used

NameProvider and purposeTypical durationParty and attributes
ph_*_posthogPostHog. Maintains pseudonymous analytics and replay continuity only after you allow analytics.Up to 1 year, or until withdrawal or browser deletionFirst party analytics storage, consent only
postiva-sessionPostiva. Authentication, security, CSRF protection, and session continuity.120 minutes of inactivity by defaultFirst party, essential, HttpOnly, SameSite=Lax, Secure in production
remember_web_*Postiva. Keeps you signed in when you actively choose the remember option.30 days or until sign-outFirst party, requested authentication, HttpOnly, SameSite=Lax, Secure in production
appearancePostiva. Remembers light, dark, or system appearance after you select it.180 daysFirst party, requested preference, SameSite=Lax, Secure in production
sidebar_statePostiva. Remembers whether the application sidebar is open.7 daysFirst party, requested preference, SameSite=Lax, Secure in production

Local storage used

NameProvider and purposeDurationCategory
postiva_analytics_consentPostiva. Remembers whether this browser may use consented analytics or should remain cookieless. Signed-in preferences are also saved to the account.Until you change the choice or clear browser storagePrivacy preference
appearance and appearance_expires_atPostiva. Stores a selected theme and its expiry.180 days, then deletedRequested preference
postiva_pwa_prompt_dismissed_atPostiva. Avoids repeating an install prompt after dismissal.30 days, then deletedRequested interface preference

Third-party flows

PostHog EU Cloud processes the analytics choices described above. Measurement requests are sent to e.postiva.app, a Postiva subdomain that forwards them to PostHog EU Cloud. PostHog remains the processor and the data is unchanged. IP capture is disabled. URLs are reduced to route patterns such as /:current_team/projects/:project, so fragments, team slugs, and entity IDs stay in your browser. The only query parameters kept are the campaign tags Postiva adds to its own links, and only the domain that referred you is recorded, never the full referring address. Google and Paddle may set their own cookies when you deliberately start Google sign-in, checkout, or billing management.

  • Google is used only for optional account authentication.
  • Paddle acts as Merchant of Record for checkout, payment, tax, invoicing, and subscription management.

Your controls

You can remove cookies and local storage through your browser settings. Blocking essential storage can prevent sign-in, security checks, saved preferences, and other core functions from working.