Cookie Policy
What we store on your device and why.
Last updated:
1. Overview
Cookies and similar browser-storage mechanisms (localStorage, sessionStorage) let websites remember you between visits and measure how the site is used. grith.ai uses a small, defined set of them, listed below. For the full picture of how we handle personal data, see our Privacy Policy.
2. Categories we use
2.1 Strictly necessary
These are required for the site to function. They do not need your consent under UK GDPR / PECR.
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
cookie_consent | grith.ai (localStorage) | Remembers your choice in the consent banner so we don't ask on every visit. | Until cleared |
better-auth.session_token | grith.ai (httpOnly cookie) | Authenticates you when signed in. Required for the dashboard, account, and billing pages. | Session-bound; rotated on sign-in |
better-auth.csrf_token | grith.ai | Cross-site-request-forgery protection on authenticated form submissions. | Session |
2.2 Analytics (consent-gated)
These only run if you accept non-essential cookies in the banner. They tell us which pages people visit, where they come from, and which features are used — never identifying individuals to us beyond anonymous IDs.
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
ph_* (e.g. ph_user_id, ph_session_id) | PostHog (eu.i.posthog.com) | Anonymous visitor identifier and session correlation. We use PostHog's EU region; no IP-derived geo beyond country is collected. | Up to 12 months |
PostHog is configured to store identifiers in memory mode until you accept the banner — meaning before consent, nothing is written to your browser's storage and the identifiers are gone the moment you close the tab.
3. How to control cookies
- The banner appears on your first visit. Click "Accept" to enable analytics or "Decline" to opt out. You can change your mind: clear
cookie_consentfrom your browser's site storage and the banner will reappear. - Your browser can block or delete cookies globally. Doing so will sign you out and disable any account features that depend on persistent state.
- Do Not Track / GPC. We respect Global Privacy Control signals on a best-effort basis: if your browser sends GPC, we treat that as a declined-consent signal for analytics.
4. Updates
We'll update this page if we add or remove a cookie or change a provider. The "Last updated" date at the top reflects the current version.
5. Contact
Questions about cookies? Email privacy@grith.ai.