Cookies & Browser Storage
A practical inventory of sessions, saved drafts and optional measurement, with controls for your choices.
Last updated:
At a glance
Necessary storage keeps sign-in and requested features working. Optional public analytics requires consent. Clear local drafts carefully: browser data and cloud projects are stored separately.
Your Current Cookie Preferences
Choose whether to allow optional public page analytics, local usage counters and diagnostic identifiers. Essential server logs are separate; automatic client exception and performance collection is inactive.
Login persistence, security
Crash & payment diagnostics
Public views, local event totals
1. Cookies and browser storage
Cookies are values a browser can send with requests. LocalStorage and sessionStorage retain data on your device. PostReady uses these mechanisms for authentication, remembering preferences and preserving work. Browser storage can contain personal data and drafts; it is not encrypted simply because it is stored in the browser.
Necessary session storage supports features you request. Optional analytics and diagnostic identifiers require the relevant choice. Declining optional preferences does not prevent you from using core account and editing features.
2. Storage inventory
PostReady’s own cookies use the postready.org domain in production and the current host in local development. Authentication cookies are managed by the authentication integration. Durations below are configured lifetimes, not guarantees that a login will remain valid for that long.
| Name or data | Type | Purpose | Retention |
|---|---|---|---|
| sb-*-auth-token (including chunks) | Cookie · necessary | Authentication session managed by Supabase. Actual validity and refresh are controlled by the authentication service. | Provider-managed expiry |
| postready_auth_session | Cookie · necessary | Account ID, email and confirmation state for the interface. This cache does not authorize access. | Up to 365 days |
| postready_cookie_consent | Cookie + localStorage | Your optional preferences and the timestamp of your choice. | Cookie: 365 days; local copy until cleared |
| postready_error_tracking | Cookie · optional | Diagnostic identifier for manually reported errors or checkout failures, only when enabled. | Up to 180 days |
| postready_perf_analytics | Cookie · inactive collector | Identifier reserved for the currently inactive client performance collector. | Up to 180 days if written |
| Theme, language, drafts, editor versions and local projects | localStorage | Your interface choices and locally saved work. Content can include source text and generated drafts. | Until removed by the app or browser |
| postready:measurement:v1 | localStorage · optional | Device-local event totals. Contains no source text, draft text or user identifiers. | Until cleared or performance consent is withdrawn |
| postready:starter:v1 and postready:event:* | sessionStorage | Starter handoff and, when enabled, event deduplication state for the current browser session. | Until removed or the browser session ends |
3. Optional analytics and diagnostics
The performance preference controls Vercel Web Analytics for public page views and device-local event totals. It is off until you opt in. Private application paths, URL query parameters and fragments are excluded from the page-view integration. Source text and generated drafts are not sent through it. Vercel Web Analytics does not use analytics cookies; see Vercel’s privacy documentation.
Withdrawing the performance choice stops optional collection and clears the local measurement counters. The automatic client performance and exception collector is currently inactive. The error-tracking choice permits a diagnostic identifier for manual error reports and checkout failures. Essential server security and error logs remain separate from these optional browser choices.
We do not use cross-site behavioral advertising cookies or sell personal data to advertising brokers.
4. Checkout and third-party services
Polar checkout and its payment providers may use their own cookies or storage for authentication, transaction security and fraud prevention on their domains. PostReady’s controls do not manage storage set by another website. Review Polar’s Privacy Policy for checkout practices.
Your PostReady session is validated separately when you return from checkout. The account-display cache alone does not grant access or confirm a successful payment.
5. Change preferences or clear storage
Use the controls above to accept optional features, keep essential storage only, or customize the two optional categories. You can return here and change your choice at any time. Withdrawing consent does not undo processing that already occurred lawfully.
Your browser’s privacy settings can block or delete cookies and site storage. Blocking necessary authentication cookies may prevent sign-in. Clearing localStorage can permanently remove local drafts, versions and unsaved projects, so export needed work first. Cloud-saved projects are stored separately with your account. Account deletion does not clear every device’s browser storage.
Consent may be remembered in both a cookie and localStorage. To completely reset the preference, remove both through your browser’s site-data controls. For personal data rights and retention details, read our Privacy Policy.
6. Questions and updates
Contact support@postready.org about storage or privacy choices. This inventory is updated when relevant functionality changes; third-party services can change their own storage independently.