Cookie Policy

Last updated: July 28, 2026

This policy explains the cookies TheoStack — a product of Lordhill Digital, LLC — sets when you use the Service, why each one exists, how long it lasts, and how to change your mind. It is a complete list: if a cookie is not in the table below, we do not set it.

What cookies are

Cookies are small text files a site stores in your browser. They let the site recognise your browser between requests — which is how you stay signed in after you log in — and remember preferences such as whether you accepted analytics. Some cookies are strictly necessary: without them, core functions like signing in cannot work. Others, like analytics, are optional and only set with your consent.

Cookies we use

CookieTypePurposeDuration
ts_atStrictly necessary, httpOnlySession access token~15 minutes
ts_rtStrictly necessary, httpOnlySession refresh token~30 days
ts_metaStrictly necessary, httpOnlyToken metadata~30 days
ts-consentStrictly necessaryStores your cookie choice12 months
ph_* (PostHog)Analytics — only after consentProduct analyticsPer PostHog defaults

The httpOnly cookies cannot be read by JavaScript in your browser, which limits the damage a cross-site scripting bug could do to your session. All of our cookies are first-party, set on the TheoStack domain, with SameSite=Lax and, in production, the Secure flag.

Analytics never loads before you consent

Our analytics provider, PostHog, is not initialised and sets no cookies until you choose “Accept analytics” in the cookie banner. If you choose “Necessary only”, no ph_* cookie is ever created and no analytics events are sent. Your choice itself is recorded in the ts-consent cookie so we do not ask again on this device, and — if you are signed in — against your account, so the choice follows you to your other devices.

Error reporting uses no cookies

We use Sentry to find out when something breaks. Sentry, as we have configured it, sets no cookies at all and does not track you across sites. Error reports are scrubbed of personal information before they are sent, and they are used only to diagnose faults.

No advertising or third-party tracking

We do not use advertising cookies, social-media pixels, or cross-site tracking of any kind, and we do not sell or share your information with advertisers.

How to change or withdraw your choice

Use the Cookie settings link in the site footer, or in Settings once you are signed in. It clears your stored ts-consent choice, immediately stops analytics and clears PostHog’s cookies and local storage, records the withdrawal against your account if you are signed in, and shows you the banner again so you can make a fresh choice. You can withdraw consent at any time; withdrawal does not affect analytics already collected while consent was in place.

Browser-level controls

You can also block or delete cookies in your browser settings — every major browser (Chrome, Safari, Firefox, Edge) has controls under Privacy or Site settings, including a way to clear cookies for a single site. Be aware that blocking the strictly necessary cookies will break sign-in: without ts_at, ts_rt, and ts_meta we cannot keep you authenticated, and the app will send you back to the login page. Blocking or clearing ts-consent only means you will be asked about analytics again.

Changes to this policy

If we add, remove, or change a cookie, we will update this table and the “Last updated” date above. If we ever introduce a new optional cookie, we will ask for your consent before setting it.

Contact

Questions about cookies or tracking: legal@theostack.com. For the wider picture of what we collect and why, see our Privacy Policy.