The short version
Saignée keeps little on your device, and none of it is used for advertising or cross-site tracking. We use cookies only where they are strictly necessary to sign you in. We use Vercel aggregate performance metrics (always on; not advertising) and product analytics (PostHog — Accept/Reject in the cookie banner) to understand usage and improve the Service. A small amount of local and session storage remembers UI preferences and campaign attribution. See below for details, and our Privacy Policy for how personal data is handled.
Strictly-necessary cookies
When you sign in, our authentication provider (Supabase Auth) sets cookies that hold your login session so you stay signed in as you move between pages. These are essential for the app to function and are exempt from consent requirements. Clearing them, or signing out, removes them; you simply have to sign in again.
Analytics
Vercel Analytics & Speed Insights
We use Vercel Analytics and Vercel Speed Insights as privacy-preserving essential / aggregate performance metrics so we can keep the Service reliable (traffic volume and how fast pages load, in aggregate). Both are privacy-friendly by design: they do not set tracking cookies for advertising, do not use persistent identifiers for ads or retargeting, and do not build a profile of you across other sites. They are not controlled by the Accept / Reject choice for product analytics (PostHog) below — they load with the app so we can measure performance for everyone. We do not use them for advertising or cross-site profiling.
PostHog (product analytics)
We use PostHog to understand how the product and marketing site are used (for example page views, sign-up funnel steps, and core product actions). You choose Accept or Reject for product analytics in our cookie banner (or via Cookie settings in the footer or account settings). Until you choose, and if you Reject, we do not run full identified client analytics; Reject may still allow privacy-preserving cookieless measurement. If you Accept, events are sent via a first-party path on our domain (/ingest) to our PostHog Cloud project in the United States, and after sign-in we may associate events with your account user id. We do not enable PostHog session recording. Browser autocapture of clicks and form inputs is disabled. Full detail is in the Privacy Policy.
What we store on your device
| Name / storage | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| Supabase Auth session cookies | Supabase / Saignée | Keep you signed in | Session / as set by auth | Strictly necessary |
| Vercel Analytics / Speed Insights (network only) | Vercel | Aggregate traffic and page performance; no advertising tracking cookies | Request lifetime / vendor aggregate | Essential stats (not Accept-gated) |
| PostHog SDK storage (after Accept) | PostHog | Analytics identity and consent state when you Accept | Per SDK / until cleared or Reject | Analytics |
First-party requests to /ingest | PostHog (via Saignée) | Deliver analytics events when allowed | Request lifetime | Analytics |
saignee_analytics_consent (localStorage) | Saignée | Remember Accept or Reject for product analytics | Until cleared or changed | Functional (preference) |
saignee_utm (sessionStorage) | Saignée | Remember UTM campaign params through signup | Browser session | Functional / attribution |
| Theme / UI preferences (localStorage) | Saignée | Remember appearance and similar UI state | Until cleared | Functional |
Functional local storage
We use your browser’s local storage and session storage for small bits of UI and attribution state — for example, your analytics Accept/Reject choice, a theme preference, or UTM parameters through signup. This data stays on your device unless attached as event properties after you Accept analytics; you can clear it any time through your browser settings.
Managing what’s stored
Use Cookie settings in the site footer (or account settings when signed in) to Accept or Reject product analytics again. You can also clear cookies and local storage from your browser’s privacy settings. Removing the strictly-necessary auth cookies will sign you out. For more on how we handle personal data — including product analytics and how to object or request deletion — see our Privacy Policy.
Changes to this policy
If we change what we store on your device or how analytics work, we will update this page. Material changes that introduce new non-essential storage or a different choice mechanism will be reflected here with an updated date.