Legal
Cookie & Storage Policy
Effective date: March 18, 2026
This policy explains what cookies and browser storage Intraview uses, why they are used, how long they are kept, and how to manage or withdraw consent.
1. What are cookies and local storage?
Cookies are small text files stored on your device by your browser. Local storage (also called “web storage”) is a similar browser mechanism that stores data as key-value pairs. Both can be used for essential operations such as keeping you signed in or remembering your preferences. Under privacy regulations like GDPR and ePrivacy, both technologies are subject to the same transparency and consent requirements.
2. Consent model
- Authentication and onboarding cookies are strictly necessary for the app to function and are set without requiring separate consent.
- Intraview uses a first-party anonymous visitor identifier (
iv_visitor_id) for internal product experiments and conversion analysis. This cookie contains a random UUID and is not shared with third parties. It does not track you across other websites. - Optional analytics tools (PostHog, Vercel Analytics, Vercel Speed Insights, and Sentry Session Replay) are only activated after you accept the “Analytics” category in the cookie consent banner. Sentry error monitoring (without session replay) runs as strictly necessary for application reliability.
- Intraview does not use any advertising, marketing, or cross-site tracking cookies. No data is sold to third parties.
- You can clear all local storage and cookies at any time through your browser settings or the Cookie Settings button at the bottom of any page.
3. HTTP cookies
The following HTTP cookies are set by Intraview and its authentication infrastructure:
| Cookie | Category | Purpose | Retention | Provider / Access |
|---|---|---|---|---|
| Supabase authentication tokens | Strictly necessary | Maintains authenticated sessions, secures API requests, and handles token refresh. | Session-scoped (cleared on sign-out) | Supabase (first-party infrastructure) |
| iv_onboarding_complete | Strictly necessary | Flags that onboarding has been completed so the app does not redirect you back to the onboarding flow on each visit. | 90 days | Intraview (first-party) |
| iv_visitor_id | Product telemetry | Anonymous visitor identifier used for internal product experiments and conversion analysis. Contains a random UUID — no personal information. | 1 year | Intraview (first-party) |
| PostHog analytics (ph_*) | Analytics (opt-in) | Product analytics, session recordings, feature flags, and A/B testing. Tracks page views, button clicks, and user flows to improve the product. Only active after you accept the analytics cookie category. | 1 year | PostHog (proxied through intraview.work/ingest) |
| Sentry Session Replay | Analytics (opt-in) | Records anonymized session replays when errors occur, helping us reproduce and fix bugs. Only active after you accept the analytics cookie category. Sentry error monitoring (without replay) runs as strictly necessary for application reliability. | Session-scoped | Sentry (third-party) |
| Vercel Analytics & Speed Insights | Analytics (opt-in) | Privacy-friendly page-level web analytics and Core Web Vitals measurement. No cross-site tracking. Only active after you accept the analytics cookie category. | Session-scoped | Vercel (first-party infrastructure) |
4. Browser local storage
Intraview stores the following data in your browser’s local storage. This data never leaves your device and is not transmitted to our servers unless you explicitly save or publish your work.
| Storage key | Purpose | Retention |
|---|---|---|
| iv_cookie_consent_v1 | Stores your cookie and storage consent preferences and the timestamp of your decision. | Until manually cleared |
| intraview_manuals | Stores your in-progress IV profile drafts locally so you can resume editing without signing in. | Until manually cleared |
| intraview_current_manual | Remembers which IV draft you were last working on. | Until manually cleared |
| intraview_try_draft | Carries onboarding answers into the IV builder so fields are pre-filled when you start creating. | Cleared after first use |
| iv-chat-{slug} | Stores recruiter chat threads on the public agent profile page so conversations persist across page reloads. | 30 days (automatic expiry) |
| iv_view_mode | Remembers your preferred IV viewing mode (Skim or Deep). | Until manually cleared |
5. Third-party services
Intraview uses Supabase for authentication and database services. Supabase sets HTTP-only authentication cookies on your device to maintain your session. These cookies are first-party (set under the Intraview domain) and are not shared with third parties for advertising or tracking purposes.
Intraview loads fonts from Google Fonts (fonts.googleapis.com) to render the interface. This sends your IP address and basic browser information to Google when pages load. Google’s Fonts privacy FAQ states that font requests are not used for tracking.
Server and edge request logs are forwarded to Axiom for security monitoring and debugging. This is strictly necessary for service reliability and does not require your consent. Log data (including IP addresses, URL paths, and browser identifiers) is retained for 30 days and is not used for advertising. Axiom does not set cookies on your device.
When you accept the Analytics cookie category, the following third-party services are activated:
- PostHog — product analytics, session recordings, feature flags, and A/B testing. PostHog requests are proxied through intraview.work and are not shared with advertisers.
- Sentry Session Replay — records anonymized session replays when errors occur to help reproduce and fix bugs. Sentry error monitoring (without replay) runs independently as strictly necessary for reliability.
- Vercel Analytics & Speed Insights — privacy-friendly page-level web metrics and Core Web Vitals measurement. No cross-site tracking.
No advertising or social-media scripts are loaded.
6. Managing and clearing storage
You can clear cookies and local storage at any time using your browser settings. Clearing authentication cookies will sign you out. Clearing local storage will remove any unsaved IV drafts stored on your device. You can also use the Cookie Settings button at the bottom of any page to review your preferences.
7. Changes to this policy
If we add or change analytics, marketing, or other optional tracking technologies, we will update this policy, present a new consent banner, and require your explicit opt-in before enabling them.
8. Contact
Questions about this policy can be sent to privacy@intraview.work.