Skip to main content

Last updated: August 2, 2026 · Version 2.3

Cookie Policy

This Cookie Policy explains how SOCSimulator LLC uses cookies and similar browser storage technologies on SOCSimulator.

1. What Are Cookies

Cookies are small text files stored on your device when you visit a website. They are used to maintain sessions, remember preferences, and support security checks.

We also use the following browser storage technologies:

  • Local Storage: Stores data in your browser with no expiration date. We use this for theme and analytics opt-out preferences, not as an analytics identifier.
  • Session Storage: Stores data for the duration of your browser session only.

2. How We Use Cookies

We use cookies to:

  • Keep you signed in to your account
  • Remember your UI preferences (sidebar state)
  • Prevent fraud during payment processing
  • Verify you are human during bot-challenge flows (Cloudflare Turnstile)
  • Collect basic cookieless pageview and event analytics through our self-hosted Umami instance.
  • Capture pseudonymous product outcomes, pageviews, web-vitals measurements, and sanitized application errors through PostHog's US cloud under our legitimate interests.
  • Record diagnostic PostHog session replay for roughly one in four sessions, also under our legitimate interests. You can switch it off at any time; heatmaps are not enabled.

We do not use cookies for advertising or cross-site tracking, and we do not sell personal data. Umami is self-hosted and cookieless. PostHog stores its state in your browser's sessionStorage, which the browser discards when you close the tab, so no long-lived analytics identifier is kept on your device. Product analytics and session replay can each be switched off separately through the privacy controls described below.

3. Types of Cookies We Use

Essential Cookies

These cookies are necessary for SOCSimulator to function. They cannot be disabled.

Cookie NamePurposeDuration
sb-*-auth-tokenAuthentication session7 days
sb-*-auth-token-code-verifierSecurity token verification (PKCE flow)Session
__stripe_midStripe fraud prevention1 year
__stripe_sidStripe session trackingSession
cf_clearance, __cf_bmCloudflare Turnstile bot challenge verification. Set only on public forms such as the waitlist signup.Session / 30 minutes

Functional Cookies

These cookies enable enhanced functionality and personalization.

Cookie NamePurposeDuration
sidebar_stateRemembers whether the dashboard sidebar is open or collapsed7 days

Browser Storage (not cookies)

The following are stored in your browser's localStorage, not as cookies. They are never sent to our servers.

KeyPurposeCleared when
themeRecords your color-scheme preference (dark/light), set via the next-themes provider. Default is dark.You clear browser storage or switch theme
soc-activity-logging-opt-outRecords whether you have paused first-party activity logging (Account Settings → Privacy)You clear browser storage or toggle the setting off
soc-analytics-opt-outRecords that you turned off basic Umami analytics and PostHog semantic event and sanitized error capture on this browser.You clear browser storage or re-enable Product analytics
soc-posthog-session-replay-objection-v1Records that you objected to diagnostic PostHog session replay on this browser. The preference change is audited in PostHog when analytics capture is available.You clear browser storage or switch Diagnostic session replay back on
soc-posthog-session-replay-objection-accountA copy of the replay objection stored on your account, so that an objection you raise on one device is honored on the next one before anything is recorded there.You clear browser storage or switch Diagnostic session replay back on

Analytics Cookies

Umami is self-hosted and cookieless and collects basic pageviews and events only. PostHog stores its state in sessionStorage and collects pseudonymous product outcomes, pageviews, web vitals, and sanitized errors. We rely on legitimate interest (GDPR Art. 6(1)(f)) for all of it, honor Do Not Track and Global Privacy Control, and provide the Product analytics opt-out. PostHog diagnostic session replay runs on the same basis and is sampled at roughly 25% of sessions: it masks all inputs, records no request headers, request or response bodies, browser console output, or canvas, never runs on assessment, sign-in, password, MFA, or billing pages, and can be switched off on its own at any time. Heatmaps are not enabled. Umami events are retained for no more than 12 months; PostHog events and errors target 90 days, and replay is retained for 30 days.

Marketing Cookies

We do not use marketing or advertising cookies.

4. Third-Party Services

The following third-party services may set cookies or receive data when you use SOCSimulator:

ProviderPurposeCookies setPrivacy Policy
SupabaseAuthenticationsb-*-auth-tokenLink
StripePayment processing__stripe_mid, __stripe_sidLink
Cloudflare TurnstileBot and fraud prevention on public forms such as the waitlist signupcf_clearance, __cf_bmLink
Umami (self-hosted)Basic cookieless pageview and event analytics only. Self-hosted at stats.haridian.com and proxied via our domain. No session replay or heatmaps; sets no cookies and honors Do Not Track. Opt out in Profile → Settings → Privacy → Product analytics.NoneLink
PostHog (US cloud)Pseudonymous product events, pageviews, web vitals, sanitized application errors, and diagnostic replay sampled at roughly 25% of sessions, all under legitimate interest. Requests go to t.socsimulator.com, a first-party subdomain forwarding to the same US project. All inputs are masked; request headers, bodies, browser console output, and canvas are not recorded, and replay never runs on assessment, sign-in, password, MFA, or billing pages. No autocapture, heatmaps, dead clicks, feature flags, or network timing. Honors Do Not Track, Global Privacy Control, and both in-product analytics controls.None (browser sessionStorage only)Link

5. Managing Cookies

In-product controls

  • Activity logging: Account Settings → Privacy → “Pause activity logging” stops first-party event writes and their PostHog mirrors for your account.
  • Product analytics: Profile → Settings → Privacy → “Product analytics” turns off Umami analytics and PostHog event and exception capture on this browser (a localStorage flag).
  • Diagnostic session replay: Profile → Settings → Privacy → “Diagnostic session replay” switches PostHog replay off on its own, leaving the rest of product analytics running. While you are signed in the objection is also saved to your account, so it applies on every device you use. Product analytics being off, Do Not Track, or Global Privacy Control pauses replay regardless of this switch.

Browser Settings

You can control or delete cookies through your browser settings:

Do Not Track

Umami respects the Do Not Track (DNT) browser signal.

Impact of Disabling Cookies

  • Essential cookies disabled: You will not be able to sign in or use SOCSimulator.
  • Functional cookies disabled: UI preferences (sidebar state) will not persist between sessions.
  • Analytics cookies disabled: No impact on functionality.

6. Changes to This Policy

We may update this Cookie Policy when our use of cookies changes. Updates are posted on this page with a revised “Last updated” date.

7. Contact Us

If you have questions about our use of cookies, contact us:

For broader data handling information, see our Privacy Policy. Our full legal identity and registered postal address are stated once, in the Privacy Policy's contact section, so there is a single authoritative statement of them rather than several copies that could fall out of step.