Cookie Policy
Last updated 2026-07-21
Launch draft pending counsel review. Questions: legal@pagerox.com.
What cookies are
Cookies are small text files a website stores in your browser so it can remember things between page loads, like the fact that you are signed in. Similar technologies, such as localStorage, do the same job with a different storage mechanism. This policy covers both, and we use the word "cookies" as shorthand for all of them.
Where this policy applies
Pagerox has two surfaces: the marketing site at pagerox.com and the web app at app.pagerox.com. Both are covered here. The app sets more cookies than the marketing site because it has to keep you signed in.
Strictly necessary cookies
Authentication (Supabase session): on app.pagerox.com, Supabase Auth sets session cookies that keep you signed in. Without them, sign-in does not work at all, so they cannot be disabled.
Security: we use cookies as part of security and CSRF protections that verify requests really come from you and not from another site acting in your name.
These cookies exist so the product functions. They are not used for tracking.
Analytics
We use PostHog, hosted in the EU region, on both surfaces to understand how Pagerox is used. PostHog receives event names and allowlisted metadata only. It never receives message content or document content; a scrubbing wrapper enforces this in code, not by convention.
PostHog may set cookies or use localStorage to keep an anonymous distinct id, so we can tell that two events came from the same browser without knowing who you are.
Session replay is enabled only on the web app and never captures chat content: all inputs are masked.
Analytics respects your browser's settings; workspace owners can also request analytics exclusion for their whole workspace via support.
Third-party flows
Payments: checkout happens on Stripe-hosted pages. Stripe sets its own cookies there, governed by Stripe's cookie and privacy policies, not this one.
Google sign-in: if you sign in with Google, Google sets cookies during the OAuth flow under Google's own policies.
In both cases we chose the provider, but the cookies on their pages are theirs and their policies govern them.
What we do not do
No advertising cookies. No cross-site tracking. No third-party ad networks. We do not sell data, and no cookie we set is used to follow you around the web.
Your choices
You can block or delete cookies through your browser settings at any time. If you block strictly necessary cookies, sign-in to the app will break; the marketing site will still work.
For analytics, we respect browser-level signals, and workspace owners can request workspace-wide analytics exclusion by emailing support@pagerox.com.
Changes and contact
If we change how we use cookies, we will update this policy and the date at the top. Questions go to support@pagerox.com.