snagr

Legal

Cookie Policy

Snagr sets cookies to keep you signed in, to complete OAuth and plan-choice flows, and a first-party analytics cookie that tells us which parts of the product get used. There are no advertising cookies and no third-party trackers.

Last updated 22 September 2026

What we do not do

  • No advertising, retargeting or cross-site tracking cookies.
  • No session recording or replay, no surveys, no dead-click capture — these are disabled in our analytics configuration, and we do not load PostHog’s recorder.
  • No analytics requests to a third-party domain. PostHog is proxied through snagr.sh, so your browser never contacts an external analytics host.
  • No cookies at all in the recovery emails your customers receive. Open and click tracking uses a pixel and link redirects handled by our email provider, not cookies.

1. Strictly necessary

These make the service work. They cannot be switched off, and under UK and EU rules they do not require consent. On HTTPS the session cookies are prefixed __Secure-.

NamePurposeLifetime
better-auth.session_tokenKeeps you signed in. Without it every page load would return you to the login form.7 days, refreshed while you keep using the product
better-auth.session_dataA short-lived cache of the signed-in session so the dashboard does not hit the database on every request.5 minutes
better-auth.account_dataA short-lived cache of the linked sign-in provider (Google, Polar, or email) used with the session cache.5 minutes
better-auth.stateHolds the one-time state value during Google or Polar sign-in, so the response can be matched to the request that started it.10 minutes
snagr_planRemembers the plan you picked on the marketing site so sign-up can start on that plan.7 days
snagr_polar_oauth_stateCSRF protection while connecting a Polar organisation.30 minutes
snagr_onboardingMarks that a Polar connection started from onboarding, so the callback returns you there.30 minutes
snagr_polar_pendingHolds the Polar OAuth tokens briefly while you pick which organisation to connect. HttpOnly; cleared when you finish or leave the picker.30 minutes
snagr_polar_connectionRemembers which connected Polar organisation the dashboard is scoped to.400 days

2. Analytics

We use PostHog to see which features are used and where people get stuck. It is first-party, proxied through our own domain, and configured without session recording, surveys or dead-click capture.

NamePurposeLifetime
ph_*_posthogDistinguishes one browser from another so a visit can be counted once. Also stored in localStorage.12 months

To opt out, use any content blocker, or email tejas@snagr.sh and we will exclude your account. The product works identically either way.

3. Browser storage that is not a cookie

PostHog also writes to localStorage (the same identifier as the analytics cookie). The dashboard may use sessionStorage for UI state that is discarded when you close the tab — for example dismissing a usage banner. That data stays in your browser and is cleared when you clear site data.

4. Managing cookies

Every major browser lets you view, block and delete cookies in its settings. Blocking the strictly necessary ones will sign you out and prevent sign-in; blocking the analytics one has no effect on functionality.

Because we set no advertising or non-essential third-party cookies, we do not show a consent banner. If we ever add a cookie that requires consent we will ask for it before setting it, and update this page.

5. More detail

What we do with the data these cookies collect is described in the Privacy Policy, and the vendors involved are listed on the subprocessors page.