Skip to content
Hoxigen

Cookie Policy

Last updated 2026-09-27

This page lists everything Hoxigen stores in your browser, what each item holds and how long it lasts. The short version: the cookies that keep you signed in need no consent; the analytics on our public pages wait until you accept them, and the dashboard runs none.

1 · No consent needed

Strictly necessary cookies

These are first-party cookies set by hoxigen.app. Sign-in and connecting your accounts do not work without them, so they are set without asking. None is used for analytics or advertising, and all are marked HttpOnly so page scripts cannot read them.

NameWhat it holdsHow long
hoxigen_sessionYour signed-in session, as a signed token. Before your second sign-in step it holds only that step's state.30 days (8 hours for a support session; 10 minutes before the second step)
hoxigen_trustedSkips the second sign-in step on this browser, only if you tick “Remember this browser”.30 days
hoxigen_totp_setupThe authenticator secret while its setup code is on screen.15 minutes
hoxigen_webauthnA one-time passkey challenge.5 minutes
hoxigen_google_state, hoxigen_meta_state, hoxigen_linkedin_state, hoxigen_youtube_state, hoxigen_reddit_state, hoxigen_bing_state, hx_slack_link, p4m-setupA random one-time value that ties a sign-in or connection you started to the platform's reply, so nobody else can complete it for you.10 minutes, or until the connection finishes
2 · Your settings

Preferences you choose

The dashboard remembers a few choices you make, so it opens the way you left it, and our public pages remember your answer about analytics, so they do not ask again. They stay in your browser and are not used to track you.

NameWhat it holdsHow long
hoxigen_app (cookie)The app you last selected in the dashboard.1 year
hoxigen.sidebarPinned (cookie, and local storage in older browsers)Whether you pinned the dashboard sidebar open.1 year (local storage: until you clear it)
hoxigen-theme (local storage)Your light or dark choice.Until you clear it
hoxigen.changelogSeen, hoxigen:item:… and cmo-panel:… (local storage)Which “What's new” entries you have seen, the tab you last opened on a content item, and whether the CMO chat was open for an app.Until you clear it
content-return:… (session storage)Where Back from a content item returns to, with your filters.Until you close the tab
hoxigen.consent.v1 (local storage)Your answer to the analytics question on our public pages (accept or decline) and when you gave it.Until you clear it or change your answer
3 · Only if you accept

Analytics on our public pages

On our public site and the sign-in and sign-up pages, a bar at the bottom of the page asks whether you accept analytics. Nothing below loads, and no request goes to either provider, until you accept. If you decline or ignore the bar, it never loads. The signed-in dashboard runs no third-party analytics at all. Error reports are separate: when a page hits an error, it sends a report of that error to PostHog (EU), with no cookies and nothing stored in your browser.

  • PostHog (EU) — page views and a recording of the visit: clicks, scrolling and the pages you open. Nothing you type is recorded: every form field is masked before it leaves your browser. It keeps its identifiers in page memory only, no cookies, so each full page load starts a new visit. If you withdraw consent after accepting, PostHog notes the opt-out in local storage (__ph_opt_in_out_ followed by our project key) until you clear it or accept again.
  • Microsoft Clarity — heatmaps and a recording of clicks, scrolling and pages viewed, with typed text masked. We run it with its storage switched off, so it sets no cookies on hoxigen.app. Where your browser allows third-party cookies, Microsoft's own domain (clarity.ms) may set its MUID identifier, which lasts up to a year; your browser's third-party cookie settings control it.

You can change your mind at any time from the Cookie settings link in the site footer. Withdrawing consent stops both recordings straight away on the page you are on, and neither loads again.

4 · Not used

What we do not use

No advertising cookies, no cross-site tracking pixels, and no Google Analytics on our site or in the dashboard. Where you connect your own Google Analytics or Clarity project, Hoxigen reads its reports on the server; nothing is added to your browser for that.

More on how we handle personal data is in the Privacy Policy, and the providers involved are on the sub-processors page.