DRAFT — PENDING LEGAL REVIEW. This document is not final and is not legal advice.

EnKrist — Cookie & Analytics Notice


1. What this covers

This notice explains the cookies and similar technologies (local storage, analytics identifiers) EnKrist uses, and how you can control them. It supplements our [Privacy Policy], which explains how we handle personal data generally.

EnKrist, operated by EnKrist LLC (a for-profit company), uses only two kinds of cookie/technology: strictly-necessary (to sign you in and keep the service secure) and analytics (to understand product usage so we can improve). We do not use advertising cookies, and we do not track you across other websites.

2. The categories we use

(a) Strictly-necessary — always on

These are required for the service to function and are set when you sign in. Without them you cannot stay logged in. They are exempt from consent under the ePrivacy rules because they are strictly necessary to provide the service you requested.

  • Authentication / session — set by our authentication provider (Supabase Auth) to keep you signed in and to protect your session (e.g., an access-token and a refresh-token cookie, and related state). [dev-to-confirm exact names, e.g. sb-<project-ref>-auth-token]

(b) Analytics — product improvement

We use PostHog to understand how members use the service (which features are used, where flows break) so we can improve it. This may set analytics cookies and/or use local storage to hold an anonymous usage identifier. We use analytics in aggregate; we do not build advertising profiles and do not use it for cross-context behavioural advertising (see the Privacy Policy §6 and §10).

3. What we do NOT use

  • No advertising or marketing cookies.
  • No third-party cross-site tracking / social-media pixels.
  • No sale or "sharing" of data via advertising technologies (see Privacy Policy §10 on US-state "sell/share" definitions).

4. The cookies/technologies in detail

Read from the application source on 2026-07-16 (no longer placeholders). Two durations are marked [confirm on prod] because they depend on runtime configuration, not the code.

Name / keyTypeSet byPartyCategoryDuration
sb-<project-ref>-auth-token (chunked …-auth-token.0, .1)cookieSupabase Auth (SSR)first-partystrictly-necessarysession / refresh-token lifetime — [confirm on prod: the Supabase project's JWT + refresh-token settings]
ph_<posthog-key>_posthogcookie + localStoragePostHogfirst-party cookie; data sent to us.i.posthog.comanalytics~365 days (posthog-js default) — set only after the member accepts the analytics banner, and only if a PostHog key is configured [confirm on prod: key currently unset]
enkrist:last_seen_datelocalStorageEnKrist (returning-visitor day marker)first-partystrictly-necessary / functionaluntil cleared
pending_emailsessionStorageEnKrist (sign-up → verify hand-off)first-partystrictly-necessary / functionaltab session (cleared when the tab closes)
enkrist:analytics_consentlocalStorageEnKrist (records your analytics choice)first-partystrictly-necessary / functionaluntil cleared

We use no advertising, marketing, or third-party cross-site cookies.

5. How to control cookies

  • Strictly-necessary cookies cannot be switched off without breaking sign-in.
  • Analytics — you can accept or decline analytics via our banner; analytics stays off until you accept, and doing nothing leaves it off. [Counsel/dev to add: where a member changes the choice later — clearing the choice re-shows the banner today.] You can also block or delete cookies through your browser settings; doing so may affect how the service works.

6. Changes

We may update this notice as the service changes (see the Privacy Policy §2 on staged capabilities). Material changes will be handled consistently with how we version our other agreements.