Cookies

HEADING sets a small number of cookies and browser-storage items to run the service and, only with your permission, to understand product usage. This page lists every service we use, grouped by category, why it's there, and for how long.

Strictly necessary

Required to run HEADING — signing in, security, and remembering your cookie choice. These can't be switched off.

NameProviderPurpose
next-auth.session-tokennext-auth.csrf-tokennext-auth.callback-urlNextAuth.jsKeeps you signed in and protects sign-in forms from cross-site request forgery.
heading-analytics-consentheading-anon-idheading-consent-last-sentheading-notice-at-collection-dismissedheading-gpc-toast-seenHEADINGRemembers your cookie/privacy choices so we don't ask again every visit, and proves your consent decision if asked.
No client-side storageSentryReports application errors so we can fix bugs — runs server-side only, sets no cookies or browser storage.

Performance

Helps us understand how HEADING is used so we can improve it — page views and feature usage, never sold or used for advertising.

NameProviderPurpose
ph_*PostHogPrivacy-friendly product analytics (PostHog, EU-hosted) — only runs after you grant the Performance category. No analytics cookie is ever written.

Manage your cookie choices anytime via the “Cookie settings” link in the footer, or in Settings if you’re signed in. See our Privacy policy for the full legal basis and sub-processor list.

Cookies — HEADING