Cookie Policy
Entity: Hangpost, Inc. · Last updated: June 2026 ·
Contact: privacy@hangpost.app
1. What this policy covers
This policy explains the cookies, local storage, SDKs, and similar technologies the Hangpost websites and apps use, and your choices. It supplements, and is incorporated into, our Privacy Policy. "Cookies" below is shorthand for all of these technologies (browser cookies, mobile-app local storage, device identifiers, and software development kits).
2. The technologies we use
We use only the categories below. We do not use advertising, retargeting, social-media, data-broker, or cross-app tracking technologies. We do not sell or share your information for cross-context behavioral advertising (there is nothing to opt out of because we don't do it).
| Category | Why | Examples on our stack | Can you turn it off? |
|---|---|---|---|
| Strictly necessary | Sign you in, keep you signed in, secure the session, remember basic preferences, and protect against abuse/rate-limit attacks | Clerk authentication session cookie/token; CSRF token; Upstash-backed session + rate-limit state keyed to your session | No. The Service can't function without these; no consent required for strictly-necessary cookies |
| Functional | Remember your settings (e.g., home-base view, UI preferences) so the app behaves the way you left it | App local storage; preference cookies | Partially. Clearing them resets preferences |
| Performance / diagnostics | Detect and fix errors and crashes, and keep the service reliable | Sentry (error/crash diagnostics, configured to scrub PII before send); Grafana Cloud (pseudonymous metrics/traces only; policy: no raw PII in telemetry) | Yes, where required; see § 4 |
What's deliberately absent: Google Analytics / Meta Pixel / TikTok pixel / any ad-network SDK / any "identity resolution" or fingerprinting vendor. If that ever changes, it ships only after this policy, the Subprocessor Register, and the Privacy Policy are updated to describe it, and, if it is a non-essential tracking technology, behind a consent control.
3. Mobile apps (no "cookies," same idea)
Our iOS/Android apps don't use browser cookies, but they use the equivalent local storage and SDKs above (auth token storage, crash diagnostics, push-notification tokens). We do not use the device advertising identifier (IDFA/AAID) and do not present an App Tracking Transparency tracking prompt because we do not track you across other companies' apps or websites: the honest answer to Apple's ATT question is "no tracking," so there is nothing to ask permission for.
4. Your choices
- Browser controls. You can block or delete cookies in your browser settings. Blocking strictly-necessary cookies will break sign-in and core features.
- Diagnostics opt-out. Where required by applicable law, or simply on request, you can opt out of non-essential performance/diagnostics collection at privacy@hangpost.app or in-app settings. Strictly-necessary processing continues regardless.
- Do Not Track / Global Privacy Control. Because we do not engage in cross-context behavioral advertising or "sales" of personal information, GPC/DNT signals do not change what we collect, but we honor them as an opt-out of any future non-essential analytics by policy.
- Push notifications can be turned off in your device settings or in-app.
5. Third parties setting these technologies
The only parties that set or read the technologies above are the processors acting on our behalf and listed in the Subprocessor Register (Clerk, Upstash, Sentry, Grafana, and our hosting providers). They are contractually limited to providing their service to us and may not use the data for their own advertising. There are no independent third-party advertisers on Hangpost.
6. Changes
We update this policy when the stack changes. Material changes are announced as described in the Privacy Policy. The "effective date" above and the git history of this file are the version record.