Last updated: August 2, 2026 · Version 2.3
Cookie Policy
This Cookie Policy explains how SOCSimulator LLC uses cookies and similar browser storage technologies on SOCSimulator.
Table of Contents
2. How We Use Cookies
We use cookies to:
- Keep you signed in to your account
- Remember your UI preferences (sidebar state)
- Prevent fraud during payment processing
- Verify you are human during bot-challenge flows (Cloudflare Turnstile)
- Collect basic cookieless pageview and event analytics through our self-hosted Umami instance.
- Capture pseudonymous product outcomes, pageviews, web-vitals measurements, and sanitized application errors through PostHog's US cloud under our legitimate interests.
- Record diagnostic PostHog session replay for roughly one in four sessions, also under our legitimate interests. You can switch it off at any time; heatmaps are not enabled.
We do not use cookies for advertising or cross-site tracking, and we do not sell personal data. Umami is self-hosted and cookieless. PostHog stores its state in your browser's sessionStorage, which the browser discards when you close the tab, so no long-lived analytics identifier is kept on your device. Product analytics and session replay can each be switched off separately through the privacy controls described below.
3. Types of Cookies We Use
Essential Cookies
These cookies are necessary for SOCSimulator to function. They cannot be disabled.
| Cookie Name | Purpose | Duration |
|---|---|---|
sb-*-auth-token | Authentication session | 7 days |
sb-*-auth-token-code-verifier | Security token verification (PKCE flow) | Session |
__stripe_mid | Stripe fraud prevention | 1 year |
__stripe_sid | Stripe session tracking | Session |
cf_clearance, __cf_bm | Cloudflare Turnstile bot challenge verification. Set only on public forms such as the waitlist signup. | Session / 30 minutes |
Functional Cookies
These cookies enable enhanced functionality and personalization.
| Cookie Name | Purpose | Duration |
|---|---|---|
sidebar_state | Remembers whether the dashboard sidebar is open or collapsed | 7 days |
Browser Storage (not cookies)
The following are stored in your browser's localStorage, not as cookies. They are never sent to our servers.
| Key | Purpose | Cleared when |
|---|---|---|
theme | Records your color-scheme preference (dark/light), set via the next-themes provider. Default is dark. | You clear browser storage or switch theme |
soc-activity-logging-opt-out | Records whether you have paused first-party activity logging (Account Settings → Privacy) | You clear browser storage or toggle the setting off |
soc-analytics-opt-out | Records that you turned off basic Umami analytics and PostHog semantic event and sanitized error capture on this browser. | You clear browser storage or re-enable Product analytics |
soc-posthog-session-replay-objection-v1 | Records that you objected to diagnostic PostHog session replay on this browser. The preference change is audited in PostHog when analytics capture is available. | You clear browser storage or switch Diagnostic session replay back on |
soc-posthog-session-replay-objection-account | A copy of the replay objection stored on your account, so that an objection you raise on one device is honored on the next one before anything is recorded there. | You clear browser storage or switch Diagnostic session replay back on |
Analytics Cookies
Umami is self-hosted and cookieless and collects basic pageviews and events only. PostHog stores its state in sessionStorage and collects pseudonymous product outcomes, pageviews, web vitals, and sanitized errors. We rely on legitimate interest (GDPR Art. 6(1)(f)) for all of it, honor Do Not Track and Global Privacy Control, and provide the Product analytics opt-out. PostHog diagnostic session replay runs on the same basis and is sampled at roughly 25% of sessions: it masks all inputs, records no request headers, request or response bodies, browser console output, or canvas, never runs on assessment, sign-in, password, MFA, or billing pages, and can be switched off on its own at any time. Heatmaps are not enabled. Umami events are retained for no more than 12 months; PostHog events and errors target 90 days, and replay is retained for 30 days.
Marketing Cookies
We do not use marketing or advertising cookies.
4. Third-Party Services
The following third-party services may set cookies or receive data when you use SOCSimulator:
| Provider | Purpose | Cookies set | Privacy Policy |
|---|---|---|---|
| Supabase | Authentication | sb-*-auth-token | Link |
| Stripe | Payment processing | __stripe_mid, __stripe_sid | Link |
| Cloudflare Turnstile | Bot and fraud prevention on public forms such as the waitlist signup | cf_clearance, __cf_bm | Link |
| Umami (self-hosted) | Basic cookieless pageview and event analytics only. Self-hosted at stats.haridian.com and proxied via our domain. No session replay or heatmaps; sets no cookies and honors Do Not Track. Opt out in Profile → Settings → Privacy → Product analytics. | None | Link |
| PostHog (US cloud) | Pseudonymous product events, pageviews, web vitals, sanitized application errors, and diagnostic replay sampled at roughly 25% of sessions, all under legitimate interest. Requests go to t.socsimulator.com, a first-party subdomain forwarding to the same US project. All inputs are masked; request headers, bodies, browser console output, and canvas are not recorded, and replay never runs on assessment, sign-in, password, MFA, or billing pages. No autocapture, heatmaps, dead clicks, feature flags, or network timing. Honors Do Not Track, Global Privacy Control, and both in-product analytics controls. | None (browser sessionStorage only) | Link |
5. Managing Cookies
In-product controls
- Activity logging: Account Settings → Privacy → “Pause activity logging” stops first-party event writes and their PostHog mirrors for your account.
- Product analytics: Profile → Settings → Privacy → “Product analytics” turns off Umami analytics and PostHog event and exception capture on this browser (a localStorage flag).
- Diagnostic session replay: Profile → Settings → Privacy → “Diagnostic session replay” switches PostHog replay off on its own, leaving the rest of product analytics running. While you are signed in the objection is also saved to your account, so it applies on every device you use. Product analytics being off, Do Not Track, or Global Privacy Control pauses replay regardless of this switch.
Browser Settings
You can control or delete cookies through your browser settings:
Do Not Track
Umami respects the Do Not Track (DNT) browser signal.
Impact of Disabling Cookies
- Essential cookies disabled: You will not be able to sign in or use SOCSimulator.
- Functional cookies disabled: UI preferences (sidebar state) will not persist between sessions.
- Analytics cookies disabled: No impact on functionality.
6. Changes to This Policy
We may update this Cookie Policy when our use of cookies changes. Updates are posted on this page with a revised “Last updated” date.
7. Contact Us
If you have questions about our use of cookies, contact us:
- Email: support@socsimulator.com
For broader data handling information, see our Privacy Policy. Our full legal identity and registered postal address are stated once, in the Privacy Policy's contact section, so there is a single authoritative statement of them rather than several copies that could fall out of step.