Legal
Cookie Policy
Summary
Two categories, and only two:
- Strictly necessary — sign-in and payment. Set for everyone; the service does not work without them, and the ePrivacy Directive does not require consent for them.
- Analytics — PostHog, in the EU. Set only after you accept the banner. Decline it, or ignore it, and PostHog is never started: no request leaves your browser and no cookie is written.
There is no advertising category. We run no ad pixels and no ad-conversion tags of any kind.
What are cookies?
Cookies are small text files a site stores on your device. Some are essential for the site to work, such as keeping you signed in. Others measure how visitors use the site. The EU ePrivacy Directive and the GDPR require us to ask before setting anything that is not strictly necessary — which, here, means the analytics one.
Cookies we use
Strictly necessary · Clerk
Session and CSRF cookies that keep you signed in and let us reject forged requests. The service cannot function without them, so the consent banner does not apply — this is what the ePrivacy Directive calls strictly necessary.
Strictly necessary · Stripe
Fraud-prevention cookies set by Stripe during checkout. Strictly necessary to take a payment.
Analytics — only if you accept · PostHog
Identifies a returning browser so page views are not counted twice, and carries the session-replay session id. Written only after you accept the banner — decline, or ignore it, and PostHog is never started, so no request is made and no cookie is written. PostHog stores the same record in localStorage under the same name.
If you withdraw consent after granting it, we tell PostHog to stop and delete its cookie from this site. The record that you opted out is kept in your browser’s localStorage, not in a cookie.
What we don’t use
- No advertising or conversion tags — no Meta Pixel, no X pixel, no LinkedIn Insight Tag, and no ad-network conversion tracking.
- No profiling for personalised advertising.
- No sale of cookie-derived data to data brokers.
- No cross-context behavioural advertising (CCPA/CPRA terminology).
- No cookies from any processor other than the ones named above — see the full list on the privacy policy.
Managing your choice
The banner appears on your first visit. Your choice is stored on your own device for up to 12 months; after that we ask again, in line with EDPB guidance on periodic re-confirmation.
To change your mind at any time: — this reopens the banner with your current choice pre-filled. Withdrawing is one click, exactly like granting.
You can also clear cookies from your browser settings. Clearing the strictly necessary ones will sign you out and may interrupt a payment in progress; you can sign back in or start the checkout again afterwards.
Why there is a banner now
For most of this product’s life, analytics here was cookieless — it set nothing on your device and needed no consent, so we showed no banner. That changed with the 2026 rebuild: PostHog gives us session replay and client-side error reports, which is how a broken page now gets diagnosed instead of guessed at, and it does write a cookie. So there is a real, consent-gating banner, and analytics genuinely does not run until you say yes.
The trade-off is deliberate and we would rather state it than hide it: our own visitor numbers are lower than the true figure, because everyone who declines or ignores the banner is never counted.
The one thing we do record either way is the answer itself. Pressing Accept or Decline sends us a count — which button, which page, and whether the screen was phone-sized — so we can tell how much of the picture we are missing. It sets nothing on your device, reads nothing from it, and carries no identifier: it is filed under a random number made for that single request and thrown away afterwards, so two answers from the same person cannot be connected.
Contact
Questions about cookies? Email support.transcribecat@