Legal
Cookie Policy
Snagr sets cookies to keep you signed in, to complete OAuth and plan-choice flows, and a first-party analytics cookie that tells us which parts of the product get used. There are no advertising cookies and no third-party trackers.
Last updated 22 September 2026
What we do not do
- No advertising, retargeting or cross-site tracking cookies.
- No session recording or replay, no surveys, no dead-click capture — these are disabled in our analytics configuration, and we do not load PostHog’s recorder.
- No analytics requests to a third-party domain. PostHog is proxied through
snagr.sh, so your browser never contacts an external analytics host. - No cookies at all in the recovery emails your customers receive. Open and click tracking uses a pixel and link redirects handled by our email provider, not cookies.
1. Strictly necessary
These make the service work. They cannot be switched off, and under UK and EU rules they do not require consent. On HTTPS the session cookies are prefixed __Secure-.
| Name | Purpose | Lifetime |
|---|---|---|
| better-auth.session_token | Keeps you signed in. Without it every page load would return you to the login form. | 7 days, refreshed while you keep using the product |
| better-auth.session_data | A short-lived cache of the signed-in session so the dashboard does not hit the database on every request. | 5 minutes |
| better-auth.account_data | A short-lived cache of the linked sign-in provider (Google, Polar, or email) used with the session cache. | 5 minutes |
| better-auth.state | Holds the one-time state value during Google or Polar sign-in, so the response can be matched to the request that started it. | 10 minutes |
| snagr_plan | Remembers the plan you picked on the marketing site so sign-up can start on that plan. | 7 days |
| snagr_polar_oauth_state | CSRF protection while connecting a Polar organisation. | 30 minutes |
| snagr_onboarding | Marks that a Polar connection started from onboarding, so the callback returns you there. | 30 minutes |
| snagr_polar_pending | Holds the Polar OAuth tokens briefly while you pick which organisation to connect. HttpOnly; cleared when you finish or leave the picker. | 30 minutes |
| snagr_polar_connection | Remembers which connected Polar organisation the dashboard is scoped to. | 400 days |
2. Analytics
We use PostHog to see which features are used and where people get stuck. It is first-party, proxied through our own domain, and configured without session recording, surveys or dead-click capture.
| Name | Purpose | Lifetime |
|---|---|---|
| ph_*_posthog | Distinguishes one browser from another so a visit can be counted once. Also stored in localStorage. | 12 months |
To opt out, use any content blocker, or email tejas@snagr.sh and we will exclude your account. The product works identically either way.
3. Browser storage that is not a cookie
PostHog also writes to localStorage (the same identifier as the analytics cookie). The dashboard may use sessionStorage for UI state that is discarded when you close the tab — for example dismissing a usage banner. That data stays in your browser and is cleared when you clear site data.
4. Managing cookies
Every major browser lets you view, block and delete cookies in its settings. Blocking the strictly necessary ones will sign you out and prevent sign-in; blocking the analytics one has no effect on functionality.
Because we set no advertising or non-essential third-party cookies, we do not show a consent banner. If we ever add a cookie that requires consent we will ask for it before setting it, and update this page.
5. More detail
What we do with the data these cookies collect is described in the Privacy Policy, and the vendors involved are listed on the subprocessors page.