Cookie Policy
Last updated: April 15, 2026 · Version 2.0.0
1. What a cookie is
A cookie is a small text file placed on your device by a website. We also use similar technologies (localStorage, pixels, device fingerprints) — the same rules apply to all of them, and we refer to the whole set as “cookies” in this Policy.
2. Categories we use
- Strictly Necessary — required for the Services to function (auth, CSRF, consent record). Cannot be switched off.
- Functional — remember choices you make (language, theme, referral source) to personalize your experience.
- Analytics — measure traffic and usage to improve the product. Only active if you consent.
- Marketing — we do not currently run third-party advertising cookies. If we add them, we will update this list and obtain fresh consent.
3. Current cookie list
| Cookie | Category | Purpose | Retention | Type |
|---|---|---|---|---|
| session_id | Strictly Necessary | Keeps you signed in | Session | First-party |
| csrf_token | Strictly Necessary | Prevents cross-site request forgery | Session | First-party |
| locale | Functional | Remembers your language (TR/EN) | 1 year | First-party |
| theme | Functional | Remembers light/dark mode | 1 year | First-party |
| cookie_consent | Strictly Necessary | Stores your cookie preferences | 1 year | First-party |
| hoa-cc-set | Strictly Necessary | Remembers that we captured your country once | 30 days | First-party |
| hofai_ref | Functional | Referral source attribution | 30 days | First-party |
| _ga, _ga_* | Analytics | Google Analytics traffic measurement | Up to 2 years | Third-party |
| ph_* | Analytics | PostHog product-analytics events | Up to 1 year | Third-party |
4. How to manage cookies
You can accept, reject, or customize cookie categories from the banner shown on your first visit, or from the Cookie Preferences link in the footer. You can also block or delete cookies in your browser settings at any time. Note that blocking “Strictly Necessary” cookies will break essential features like sign-in.
5. Do Not Track & Global Privacy Control
We honor the Global Privacy Control (GPC) browser signal for California residents. When we detect a GPC signal, we treat it as a valid opt-out of sale/sharing under the CCPA/CPRA.
6. Third-party cookies
Analytics cookies may be set by Google Analytics and PostHog. Those providers process data under their own privacy notices:
- Google Analytics — policies.google.com/privacy
- PostHog — posthog.com/privacy
7. Changes
We will update this list when cookies are added or removed. Material changes will be announced by banner re-prompt.
8. Contact
Questions about cookies: privacy@hofai.io.