Skip to main content

Cookie Policy

Effective 2026-05-09Version 1.0

AuditAI uses cookies and similar technologies in three categories. In jurisdictions that require it (EU, UK, California where applicable), non-essential cookies are off by default and only enabled after you opt in via the consent banner.

Essential cookies

Required for the Service to function: authentication session, CSRF token, organisation switcher selection, impersonation banner state. These cannot be disabled without breaking the Service.

Functional cookies

Remember preferences such as collapsed nav state, brand preview during white-label configuration. Disabling these does not break the Service but resets preferences each visit.

Analytics cookies

Used by PostHog to measure how the product is used so we can improve it: pageview events, feature-usage events, anonymous device id. We do not track you across third party sites.

How to manage

  • Banner: a banner is shown on first visit to the marketing or app surfaces in jurisdictions that require it. You can change preferences at any time via the "Cookies" link in the footer.
  • Browser: most browsers let you block or delete cookies. Doing so may break essential functionality.
  • Do Not Track: we honour the GPC (Global Privacy Control) signal as a CCPA opt-out request.

Third-party cookies in scope

  • Clerk (essential): authentication session, MFA challenge state.
  • Stripe (essential, on checkout pages only): fraud-prevention.
  • PostHog (analytics): anonymous device id and feature flags. EU users are routed to PostHog EU.
  • Sentry (essential for error capture): no cookies; session-replay is opt-in only.

Updates

Material changes will be communicated via banner re-prompt and an update to the effective date above.

Cookie Policy - AuditAI