Skip to main content
clustra
Browse legal documents

Cookies Policy

Last Modified: May 30, 2026 · Version 2026-05-30

This Cookies Policy explains how Clustra Technologies Ltd. ("Clustra") uses cookies and similar browser storage on our websites and applications. It supplements our Privacy Policy.

1. What Cookies Are

A cookie is a small text file that a website saves on your device when you visit. The next time you visit, your browser sends the cookie back so the site can recognise your session, remember a preference, or measure how the site is being used. We also use closely related browser storage mechanisms — localStorage and sessionStorage — and treat them the same way for the purposes of this policy.

Cookies can be session cookies (deleted when you close the browser) or persistent cookies (kept until they expire or you clear them). They can be first-party (set by Clustra) or third-party (set by a service we embed).

2. Why We Use Cookies

We use cookies and equivalent browser storage for exactly five purposes:

  • To keep you signed in (authentication and session management).
  • To protect sensitive actions against cross-site request forgery (CSRF).
  • To remember your settings and the choices you have made on this site (preferences, including your cookie consent decision).
  • To understand how the product is used, so we can improve it (product analytics) — only after you opt in.
  • To detect and diagnose software errors (error monitoring).

We do not use cookies for advertising, retargeting, cross-site tracking, profiling, or sale of data. We do not embed advertising networks on the Service.

3. Types of Cookies We Use

3.1 Authentication & session (essential)

Set by our authentication layer to keep you signed in across pages and requests. These cookies are HttpOnly, Secure, and use the strictest practical SameSite setting. They expire when your session ends or when your refresh token policy dictates, whichever comes first.

3.2 CSRF protection (essential)

The __Host-oauth-state-binding cookie (or oauth-state-binding in development) binds the OAuth state parameter to your browser so an attacker on another site cannot complete an OAuth sign-in on your behalf. It is HttpOnly, Secure, SameSite=Lax, scoped to Path=/, and lives for 10 minutes — only long enough for the OAuth round-trip.

3.3 Preferences (essential)

We keep a small amount of information in your browser's local storage to remember:

  • Your cookie consent decision and the policy version you decided under (clustra:consent:v1 and clustra:consent:decided:v1). When the policy version changes we re-prompt you, as required by GDPR Art. 7(3).
  • Light UI preferences such as theme. These never leave your device.

3.4 Product analytics (optional — opt-in)

When you grant analytics consent in the cookie banner, the PostHog SDK sets first-party cookies and local-storage entries so it can group your interactions into a session and identify you as the same user across pages while you are signed in. Withdrawing consent at any time stops further collection and clears the SDK state. No analytics tracking fires before you opt in.

3.5 Error monitoring (essential)

We use Sentry to capture browser errors so we can diagnose and fix them. Sentry primarily uses ephemeral browser storage (sessionStorage) for breadcrumbs and request correlation; it does not set cookies for advertising or cross-site tracking. Sensitive request headers, tokens, and email patterns are redacted before any error is transmitted.

4. Third-Party Cookies

The third parties that may set cookies or use browser storage on Clustra are limited to:

  • PostHog — first-party cookies and local storage for product analytics. Set only if you grant analytics consent.
  • Sentry — ephemeral browser storage for error monitoring. Treated as a strictly necessary security and reliability function and does not require consent under GDPR or the ePrivacy Directive.
  • Google — only during a Google sign-in flow. Google sets its own cookies on accounts.google.com as part of authenticating you; those cookies are governed by Google's Privacy Policy (opens in new tab).

We do not embed third-party advertising, marketing, social-share, or chat widgets that set tracking cookies on our pages.

5. How You Can Manage Cookies

  • The cookie banner — the first time you visit, you can accept or refuse the optional analytics category. You can change your mind at any time from your account settings, which re-opens the banner.
  • Your browser — every modern browser lets you view, block, or delete cookies and clear local storage from its settings. The pages below explain how:
  • Global Privacy Control — we honour the GPC browser signal where required by law as an opt-out of any sale or sharing. Clustra does not sell or share personal data, but the signal will also turn off optional analytics on your behalf.

Blocking the essential cookies above (authentication, CSRF, preferences) will prevent the Service from working correctly — you will not be able to sign in or your sign-in will not persist.

6. Updates & Contact

We may update this Cookies Policy when our practices change. The version and effective date at the top of the page reflect the current revision. Material changes invalidate your prior consent decision and re-prompt you the next time you visit a Clustra property.

Questions: privacy@clustra.org.

Cookies Policy · Clustra