Staxytaxy

Cookie Policy

Version: v2, Last updated: 2026-07-05

Cookie Policy

Version v2, effective from 2026-07-05.

This Cookie Policy explains the cookies and similar technologies used across Staxy: the website at staxy.app and the Staxy applications for web, iOS, and Android (together, the "Service"). It supplements our Privacy Policy, which describes how we handle personal data more generally.

We use only what the Service needs to run, plus privacy-preserving analytics. Our cookie-based analytics stays off until you turn it on. Before you choose, and if you decline, we measure aggregate audience data (including which links bring visitors) without storing anything on your device. We do not use advertising, marketing, or retargeting cookies.

What we use

The table below lists the cookies and browser-storage entries you may encounter. Names set by our providers (Clerk, Cloudflare, PostHog) can vary slightly between environments; the purpose and category are what matter.

NameSet byPurposeLifetimeCategory
__sessionClerk (authentication provider)Holds the short-lived session token that keeps you signed in and authenticates your requestsShort-lived, refreshed about every minuteStrictly necessary
__client_uatClerkSignals whether a valid session exists so pages render in the correct signed-in or signed-out statePersistent (set by Clerk, browser-dependent)Strictly necessary
__clientClerkLong-lived authentication cookie set on Clerk's frontend-API domain; used to issue the session tokens abovePersistent (browser-dependent)Strictly necessary
__cf_bmCloudflare (CDN and security)Distinguishes automated traffic from humans to protect the Service against bots and abuseAbout 30 minutesStrictly necessary
cf_clearanceCloudflareStores proof that a security check was passed so you are not challenged againShort-lived (set by Cloudflare)Strictly necessary
staxy.consent.v1Staxy (first-party)Browser local-storage entry (not a cookie) that remembers your consent-banner choice so we do not ask on every visitUntil you reset it or clear browser storageStrictly necessary
ph_<project>_posthogPostHog (EU-hosted analytics)Stores an anonymous analytics id (distinct, session, and device ids) so usage events can be grouped; everything else PostHog keeps in your browser's local storageUp to 365 daysAnalytics (opt-in)

Categories

  • Strictly necessary — required to run the Service: signing you in, keeping you signed in, and protecting against bots and abuse. Under Article 5(3) of the ePrivacy Directive (2002/58/EC) these do not require consent. Blocking them may stop you signing in or break parts of the Service.
  • Analytics — the cookie-based analytics in this category loads only after you give consent. We use PostHog, hosted in the EU and configured without advertising use. Once you accept, it records page views and page interactions (clicks, scroll depth, and page-performance metrics), campaign parameters such as UTM tags, and, on the website, session replays that show how a page is used. Replays mask everything you type into form fields by default. This cookie-based analytics is off by default, and the Global Privacy Control (GPC) browser signal keeps it off regardless of any other setting. Separately, we run a cookieless audience measurement that stores nothing on your device — see "Analytics without cookies" below.
  • Advertising and marketing — none. We use no advertising or retargeting cookies, no Facebook Pixel, no Google Ads, and we do not share data with data brokers.

Analytics without cookies

Some measurement runs without storing anything in your browser — no cookies and no local storage. Because it does not store or read information on your device, it does not require consent under Article 5(3) of the ePrivacy Directive.

  • PostHog — audience measurement. Before you make a choice on the consent banner, and if you decline, we use PostHog in a cookieless mode that stores nothing on your device, across both our website (staxy.app) and our web app (app.staxy.app). It counts page views and records the page address, referrer, and campaign parameters (such as UTM tags), so we can see which links and channels bring visitors, including through the move from the site to sign-up. In this mode it does not run click tracking, heatmaps, or session replay, and it does not build a profile of you; your IP address is discarded when the data is received. The legal basis is our legitimate interest in measuring our audience (Article 6(1)(f) GDPR). You can object at any time: choosing "Reject non-essential", or enabling the Global Privacy Control (GPC) signal, turns this off as well. If you choose "Accept", it upgrades to the cookie-based analytics described above.
  • Cloudflare Web Analytics. The Service is served through Cloudflare, which also runs Cloudflare Web Analytics. This is a privacy-first measurement beacon designed to work without cookies: it does not store identifiers in your browser and reports aggregate page-performance metrics only. Cloudflare may still set the strictly-necessary security cookies (__cf_bm, cf_clearance) listed above when it protects the Service.

Preferences

Your settings, such as theme, display currency, language, and time zone, are remembered as part of your account and may also be cached in your browser's local storage. They are not used to track you.

The consent banner

On your first visit the website shows a consent banner with two choices of equal visual weight, "Reject non-essential" and "Accept", and a link to this policy. Cookie-based analytics stays off unless you choose "Accept"; the cookieless audience measurement described in "Analytics without cookies" runs beforehand and stops if you choose "Reject non-essential". You can reopen the banner at any time through "Cookie settings" in the footer.

How we record your choice

  • On the website, before you sign in: your choice is stored only in your browser, in the staxy.consent.v1 local-storage entry. We do not create a server-side record for anonymous visitors. Clearing it, or using "Cookie settings", resets the banner.
  • When you are signed in: a record of the consent you give or withdraw (the document version, timestamp, and the IP address and user-agent at that moment) is kept as proof of consent under Article 7(1) GDPR, as described in the Privacy Policy. The IP address and user-agent are anonymised when you delete your account.

Managing cookies

  • Use "Cookie settings" in the website footer, or Settings in the app, to change your analytics choice at any time.
  • Your browser lets you block or delete cookies and clear local storage. Note that blocking strictly-necessary cookies may stop you signing in.
  • We honour the Global Privacy Control (GPC) signal, which disables analytics.

Changes

Each version of this policy is published as a dated, immutable version, and the current version is always available within the Service.

Contact

legal@staxy.app for any cookie-related questions.

We use analytics, including session replay, to understand what works. No ads, no third-party data sales.

Learn more about cookies