Cookie Policy
Cookies and similar technologies (local storage) are small pieces of data stored in your browser. This page lists what PostRush uses. You can change your analytics choice at any time: Cookie settings.
Strictly necessary (always on)
These make the service work and can’t be switched off. They don’t track you across other sites, and under EU rules they don’t need consent.
| Name | Purpose | Lifetime |
|---|---|---|
postpilot_session | Keeps you signed in (httpOnly, random token; only its hash is stored on our servers) | 14 days |
postpilot_ws, postpilot_brand | Remember which workspace and brand you were working in | 1 year |
postpilot_google | Protects the “Continue with Google” sign-in flow (state and PKCE) | Minutes |
postpilot_did | Random browser identifier, set when you create an account, used only to enforce the limit on accounts per browser and to prevent abuse | 13 months |
postpilot_consent (local storage) | Remembers your cookie choice | Until you change it |
Analytics (only with your consent where required)
If you accept analytics, or you are in a region where opt-in isn’t required and haven’t objected, we use:
| Name / storage | Provider | Purpose | Lifetime |
|---|---|---|---|
postpilot_aid, postpilot_vid (local and session storage) | PostRush (first party) | Random ids that group your page views and clicks into visits, so we can see which pages and steps lose people. No IP address is stored. | Until you withdraw consent / end of the browser session |
ph_* cookies and local storage | PostHog (we send events through our own domain) | Product analytics, funnels, session recordings and automatically captured clicks and form submits, with text and inputs masked. When you’re signed in, your account id and plan are attached so we can understand usage by plan. | Up to 1 year |
We do not use advertising cookies or sell data. We honour the Global Privacy Control signal and Do Not Track: if your browser sends either, optional browser analytics stay off.
PostHog browser recordings mask text and inputs and block images, videos and canvas content. Console logs, request bodies and network headers are not recorded. Page-view events omit query strings. Signed-in analytics may include your account id, name, email, workspace, plan and app version. Events are processed in the United States. Server-side account, billing and service usage events do not depend on browser cookies; they are described in our Privacy Policy.
Your choices
- Use Cookie settings (also in the site footer) to accept or withdraw analytics at any time. Withdrawing clears our analytics identifiers and stops recording.
- You can also block or delete cookies in your browser settings; strictly necessary cookies are needed to sign in.
More about how we use personal data: Privacy Policy.
Contact
PostRush. Questions about this document: [email protected]. Privacy requests: [email protected].