Legal — Cookie Policy

Cookie Policy

What we set, why, and how to change your mind. Also: the specifics on our PostHog analytics setup.

Version history →
Last updated2026-07-03
Effective2026-07-03
Versionv1.0
JurisdictionUK · EU
ControllerTeam Judas Limited · 10199335
01.—

What cookies are

A cookie is a small text file a website stores on your device so the site can recognise the same browser on a later visit. We use the term loosely to also cover localStorage, sessionStorage and similar client-side storage. Same principles apply.

02.—

How we use cookies

We use only what we need to run the service and understand product usage in aggregate. No advertising cookies, no cross-site trackers, no data brokers.

03.—

Strictly necessary

  • sb-* — Supabase auth session cookies. Session-lifetime or 1-year, HTTPS, HttpOnly, SameSite=Lax.
  • mixrounds_gate_[projectId] — remembers your portal / intake password so you don't re-enter every visit. HttpOnly, 1 year.
  • mr_preview — engineer-side preview bypass for the coming-soon marketing gate. HttpOnly, 1 year, tied to an env-var secret.

No consent required for these under Art. 5(3) e-Privacy Directive.

04.—

Analytics — PostHog Cloud (EU host), opt-in only

We use PostHog Cloud on their EU-hosted infrastructure (eu.i.posthog.com). PostHog is only initialised after you explicitly accept analytics via our cookie banner — no analytics cookies exist on your device before then.

  • ph_[project]_posthog — anonymous distinct-id and feature-flag state, set only after consent. Persistence is memory by default (session-scoped) unless you enable durable persistence.
  • Signed session tokens in URLs (portal, intake) are stripped from $current_url, $pathname and $referrer before any event leaves your browser.
  • No session replay on the client portal or engineer app.
  • Automatic pageview capture is disabled — we only fire explicit events tied to product actions.
You can change your consent choice any time by clicking the cookie banner or clearing site data. Rejecting analytics never breaks the app.
05.—

Managing your cookie preferences

Change your preferences any time from the cookie banner. You can also clear cookies from your browser; the strictly-necessary cookies will be recreated on your next login.

06.—

Changes to this policy

We'll update the Last updated date above whenever we change this policy. Material changes (new vendor, new category of cookie) trigger the 30-day notice at /legal/subprocessors.

See also
99.—

Version history

2026-07-03v1.0Initial publication.