Legal
Cookie Policy
1. What cookies are
A cookie is a small file a website stores in your browser. Related technologies — local storage and session storage — do the same job in a different place. This policy covers all of them, because what matters is that data is being stored on your device, not the mechanism used.
2. How Alignex uses them
Sparingly. This website sets one cookie to remember your cookie choices, and one more only if you sign in. Everything else is optional and off until you say otherwise.
We do not use advertising cookies, we do not sell or share your data with advertisers, and we do not use cross-site tracking.
3. The full list
| Cookie / technology | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| alignex_cookie_consent | Alignex (first-party) | Stores your cookie choices so we do not ask again on every page. | Strictly necessary | 180 days |
| sb-<project>-auth-token | Supabase (first-party) | Keeps you signed in and secures the session. Set only when you sign in. | Strictly necessary | Session / until sign-out |
| ph_<project-key>_posthog | PostHog (EU), served first-party via /ingest | Assigns an anonymous device identifier so page views can be counted without identifying you. | Analytics — consent required | 365 days (PostHog default) |
| ph_<project-key>_posthog (local & session storage) | PostHog (EU) | Mirrors the identifier above and tracks whether this is the primary browser tab. Not a cookie, but treated identically for consent. | Analytics — consent required | Until cleared / end of session |
| sentryReplaySession | Sentry (session storage) | Groups the events of one browsing session when an ERROR occurs, so a fault can be diagnosed. Session recording is off; only error-triggered capture is enabled, with all text, inputs and media masked. | Strictly necessary — see §5 | End of session |
4. Strictly necessary
Required for security and core operation, and set without consent because the website cannot work without them. They are your consent choice itself, and your sign-in session if you have one. They carry no analytics identifier.
5. Analytics
Optional, and off until you accept. We use PostHog, hosted in the EU and served through our own domain so requests are first-party. It is configured not to autocapture form values or page content, not to record sessions, and to build a profile only for signed-in users.
If you have not accepted analytics, PostHog is not initialised at all — it is not loaded and then held back, so no identifier is written.
Error monitoring. We use Sentry to detect faults. Continuous session recording is disabled; capture happens only around an error, with text, inputs and media masked. We treat this as strictly necessary for security and reliability. ⚠️ Whether it should instead sit behind consent is a legal decision that has not yet been taken — see §9.
6. Marketing
We do not use any. There is no advertising, remarketing or ad-measurement technology on this website. The marketing category appears in Cookie Settings so you can see that it is empty, and so the control already exists if that ever changes.
7. Managing your choice
Your decision is stored in a first-party cookie named alignex_cookie_consent for 180 days. We ask again after that.
You can change or withdraw consent at any time using the cookie button at the bottom left of every page on this website, or the Cookie settings link in the footer. Withdrawing analytics consent stops collection and deletes the identifier PostHog had stored.
Closing the panel, scrolling or continuing to browse is not consent. If you dismiss the panel without choosing, nothing optional is enabled.
8. Browser controls
You can block or delete cookies in your browser settings, and most browsers let you refuse them entirely. Blocking strictly necessary cookies will stop you signing in and will make us ask about cookies on every page, because the record of your choice is itself a cookie.
9. ⚠️ Pending confirmation
These items need legal or operational sign-off and have deliberately not been guessed:
- Whether Sentry error monitoring is strictly necessary or requires consent. It is currently treated as necessary.
- The 180-day re-consent interval. Defensible, but not a ruling.
- The exact Supabase auth cookie name and lifetime, which depend on the project reference and session configuration.
- Whether the signed-in product should present its own consent control, or rely on a different lawful basis. Consent currently gates the marketing website only.
- Company registration details and a formal legal contact address.
10. Changes and contact
We will update this policy when the technologies we use change, and the date at the top will change with it. Questions about cookies or privacy: hello@alignex.app.
See also our Privacy Policy.
