Legal
Cookie & Storage Policy
Effective date: September 4, 2026
This policy explains what cookies and browser storage Intraview uses, why they are used, how long they are kept, and how to manage or withdraw consent.
1. What are cookies and local storage?
Cookies are small text files stored on your device by your browser. Local storage (also called “web storage”) is a similar browser mechanism that stores data as key-value pairs. Both can be used for essential operations such as keeping you signed in or remembering your preferences. Under privacy regulations like GDPR and ePrivacy, both technologies are subject to the same transparency and consent requirements.
2. Consent model
- Authentication and onboarding cookies are strictly necessary for the app to function and are set without requiring separate consent.
- Intraview uses a first-party anonymous visitor identifier (
iv_visitor_id) for internal product experiments and conversion analysis. This cookie contains a random UUID and is not shared with third parties. It does not track you across other websites. - Analytics tools (PostHog, Vercel Analytics, Vercel Speed Insights, and Sentry Session Replay) run by default and stop as soon as you opt out, either in the cookie notice or in Cookie settings. They never start if your browser sends a Global Privacy Control signal, or if your browser cannot store your preference. Sentry error monitoring (without session replay) runs as strictly necessary for application reliability.
- Intraview does not use any advertising, marketing, or cross-site tracking cookies. No data is sold to third parties.
- You can clear all local storage and cookies at any time through your browser settings or the Cookie settings link in the page footer.
3. HTTP cookies
The following HTTP cookies are set by Intraview and its authentication infrastructure:
| Cookie | Category | Purpose | Retention | Provider / Access |
|---|---|---|---|---|
| Supabase authentication tokens | Strictly necessary | Maintains authenticated sessions, secures API requests, and handles token refresh. | Session-scoped (cleared on sign-out) | Supabase (first-party infrastructure) |
| iv_onboarding_complete | Strictly necessary | Flags that onboarding has been completed so the app does not redirect you back to the onboarding flow on each visit. | 90 days | Intraview (first-party) |
| iv_consent_optout | Strictly necessary | Records that you opted out of analytics when your browser could not save the full preference. Contains no personal information and is only set if that save fails. | 1 year | Intraview (first-party) |
| iv_visitor_id | Product telemetry | Anonymous visitor identifier used for internal product experiments and conversion analysis. Contains a random UUID — no personal information. Set and read only while the Analytics category is active. | 1 year | Intraview (first-party) |
| PostHog analytics (ph_*) | Analytics (on by default, opt out any time) | Product analytics, session recordings, feature flags, and A/B testing. Tracks page views, button clicks, and user flows to improve the product. Active unless you opt out or your browser sends a Global Privacy Control signal, or your browser cannot store your preference. | 1 year | PostHog (proxied through intraview.work/ingest) |
| Sentry Session Replay | Analytics (on by default, opt out any time) | Records anonymized session replays when errors occur, helping us reproduce and fix bugs. Active unless you opt out or your browser sends a Global Privacy Control signal, or your browser cannot store your preference. Sentry error monitoring (without replay) runs as strictly necessary for application reliability. | Session-scoped | Sentry (third-party) |
| Vercel Analytics & Speed Insights | Analytics (on by default, opt out any time) | Privacy-friendly page-level web analytics and Core Web Vitals measurement. No cross-site tracking. Active unless you opt out or your browser sends a Global Privacy Control signal, or your browser cannot store your preference. | Session-scoped | Vercel (first-party infrastructure) |
4. Browser local storage
Intraview stores the following data in your browser’s local storage. This data never leaves your device and is not transmitted to our servers unless you explicitly save or publish your work.
| Storage key | Purpose | Retention |
|---|---|---|
| iv_cookie_consent_v1 | Stores your cookie and storage consent preferences and the timestamp of your decision. | Until manually cleared |
| intraview_manuals | Stores your in-progress IV profile drafts locally so you can resume editing without signing in. | Until manually cleared |
| intraview_current_manual | Remembers which IV draft you were last working on. | Until manually cleared |
| intraview_try_draft | Carries onboarding answers into the IV builder so fields are pre-filled when you start creating. | Cleared after first use |
| iv-chat-{slug} | Stores recruiter chat threads on the public agent profile page so conversations persist across page reloads. | 30 days (automatic expiry) |
| iv_view_mode | Remembers your preferred IV viewing mode (Skim or Deep). | Until manually cleared |
5. Third-party services
Intraview uses Supabase for authentication and database services. Supabase sets HTTP-only authentication cookies on your device to maintain your session. These cookies are first-party (set under the Intraview domain) and are not shared with third parties for advertising or tracking purposes.
Intraview loads fonts from Google Fonts (fonts.googleapis.com) to render the interface. This sends your IP address and basic browser information to Google when pages load. Google’s Fonts privacy FAQ states that font requests are not used for tracking.
Server and edge request logs are forwarded to Axiom for security monitoring and debugging. This is strictly necessary for service reliability and does not require your consent. Log data (including IP addresses, URL paths, and browser identifiers) is retained for 30 days and is not used for advertising. Axiom does not set cookies on your device.
The following third-party services run under the Analytics category. They are active unless you opt out or your browser sends a Global Privacy Control signal, or your browser cannot store your preference:
- PostHog — product analytics, session recordings, feature flags, and A/B testing. PostHog requests are proxied through intraview.work and are not shared with advertisers.
- Sentry Session Replay — records anonymized session replays when errors occur to help reproduce and fix bugs. Sentry error monitoring (without replay) runs independently as strictly necessary for reliability.
- Vercel Analytics & Speed Insights — privacy-friendly page-level web metrics and Core Web Vitals measurement. No cross-site tracking.
No advertising or social-media scripts are loaded.
6. Managing and clearing storage
You can clear cookies and local storage at any time using your browser settings. Clearing authentication cookies will sign you out. Clearing local storage will remove any unsaved IV drafts stored on your device. You can also use the Cookie settings link in the page footer to review your preferences.
7. Changes to this policy
If we add or change analytics or other optional tracking technologies, we will update this policy, present a new consent banner, and give you a clear way to opt out before enabling them. Marketing and advertising technologies would require your explicit opt-in.
8. Contact
Questions about this policy can be sent to privacy@intraview.work.