Cookie Policy
Last updated 2026-09-27
This page lists everything Hoxigen stores in your browser, what each item holds and how long it lasts. The short version: the cookies that keep you signed in need no consent; the analytics on our public pages wait until you accept them, and the dashboard runs none.
Strictly necessary cookies
These are first-party cookies set by hoxigen.app. Sign-in and connecting your accounts do not work without them, so they are set without asking. None is used for analytics or advertising, and all are marked HttpOnly so page scripts cannot read them.
| Name | What it holds | How long |
|---|---|---|
| hoxigen_session | Your signed-in session, as a signed token. Before your second sign-in step it holds only that step's state. | 30 days (8 hours for a support session; 10 minutes before the second step) |
| hoxigen_trusted | Skips the second sign-in step on this browser, only if you tick “Remember this browser”. | 30 days |
| hoxigen_totp_setup | The authenticator secret while its setup code is on screen. | 15 minutes |
| hoxigen_webauthn | A one-time passkey challenge. | 5 minutes |
| hoxigen_google_state, hoxigen_meta_state, hoxigen_linkedin_state, hoxigen_youtube_state, hoxigen_reddit_state, hoxigen_bing_state, hx_slack_link, p4m-setup | A random one-time value that ties a sign-in or connection you started to the platform's reply, so nobody else can complete it for you. | 10 minutes, or until the connection finishes |
Preferences you choose
The dashboard remembers a few choices you make, so it opens the way you left it, and our public pages remember your answer about analytics, so they do not ask again. They stay in your browser and are not used to track you.
| Name | What it holds | How long |
|---|---|---|
| hoxigen_app (cookie) | The app you last selected in the dashboard. | 1 year |
| hoxigen.sidebarPinned (cookie, and local storage in older browsers) | Whether you pinned the dashboard sidebar open. | 1 year (local storage: until you clear it) |
| hoxigen-theme (local storage) | Your light or dark choice. | Until you clear it |
| hoxigen.changelogSeen, hoxigen:item:… and cmo-panel:… (local storage) | Which “What's new” entries you have seen, the tab you last opened on a content item, and whether the CMO chat was open for an app. | Until you clear it |
| content-return:… (session storage) | Where Back from a content item returns to, with your filters. | Until you close the tab |
| hoxigen.consent.v1 (local storage) | Your answer to the analytics question on our public pages (accept or decline) and when you gave it. | Until you clear it or change your answer |
Analytics on our public pages
On our public site and the sign-in and sign-up pages, a bar at the bottom of the page asks whether you accept analytics. Nothing below loads, and no request goes to either provider, until you accept. If you decline or ignore the bar, it never loads. The signed-in dashboard runs no third-party analytics at all. Error reports are separate: when a page hits an error, it sends a report of that error to PostHog (EU), with no cookies and nothing stored in your browser.
- PostHog (EU) — page views and a recording of the visit: clicks, scrolling and the pages you open. Nothing you type is recorded: every form field is masked before it leaves your browser. It keeps its identifiers in page memory only, no cookies, so each full page load starts a new visit. If you withdraw consent after accepting, PostHog notes the opt-out in local storage (__ph_opt_in_out_ followed by our project key) until you clear it or accept again.
- Microsoft Clarity — heatmaps and a recording of clicks, scrolling and pages viewed, with typed text masked. We run it with its storage switched off, so it sets no cookies on hoxigen.app. Where your browser allows third-party cookies, Microsoft's own domain (clarity.ms) may set its MUID identifier, which lasts up to a year; your browser's third-party cookie settings control it.
You can change your mind at any time from the Cookie settings link in the site footer. Withdrawing consent stops both recordings straight away on the page you are on, and neither loads again.
What we do not use
No advertising cookies, no cross-site tracking pixels, and no Google Analytics on our site or in the dashboard. Where you connect your own Google Analytics or Clarity project, Hoxigen reads its reports on the server; nothing is added to your browser for that.
More on how we handle personal data is in the Privacy Policy, and the providers involved are on the sub-processors page.
Contact
Privacy and data requests: legal@hoxigen.app · General: support@hoxigen.app
Related: Privacy policy · Terms of service · Data processing addendum · Sub-processors