Cookies we set (and the ones we don't).

Last updated: April 2026. We keep cookies to a minimum — just the ones needed to run the app and understand what works.

Draft — counsel review pending. Finalized before general availability.

We don't run advertising cookies, Meta pixels, Google remarketing, or third-party trackers beyond the ones listed below. Our marketing analytics (Plausible) is cookieless and processed in the EU.

NameKindPurposeLifetime
sb-access-token / sb-refresh-tokenStrictly necessarySupabase auth session. Keeps you signed in. Without these the app can't tell who you are.1 hour (access) / 1 week (refresh)
abn.connections.returnTo (localStorage)Strictly necessaryRemembers where to send you after the OAuth round-trip when connecting a tool (so the agent wizard resumes correctly).Session — cleared on connection completion
ph_<project>_posthog (PostHog)Product analyticsTracks which features you use, funnel steps, and anonymized session flow. Helps us decide what to build next.1 year
plausible_ignore (Plausible)Analytics (cookieless in practice)Set only if you opt out — tells Plausible to ignore your visits. Plausible itself is cookieless.1 year

Opting out

Your browser's “Do Not Track” or “Global Privacy Control” signal disables PostHog analytics automatically. You can also block cookies at the browser level — the app still works, but analytics won't fire.