Cookies
HEADING sets a small number of cookies and browser-storage items to run the service and, only with your permission, to understand product usage. This page lists every service we use, grouped by category, why it's there, and for how long.
Strictly necessary
Required to run HEADING — signing in, security, and remembering your cookie choice. These can't be switched off.
| Name | Provider | Purpose |
|---|---|---|
next-auth.session-tokennext-auth.csrf-tokennext-auth.callback-url | NextAuth.js | Keeps you signed in and protects sign-in forms from cross-site request forgery. |
heading-analytics-consentheading-anon-idheading-consent-last-sentheading-notice-at-collection-dismissedheading-gpc-toast-seen | HEADING | Remembers your cookie/privacy choices so we don't ask again every visit, and proves your consent decision if asked. |
| No client-side storage | Sentry | Reports application errors so we can fix bugs — runs server-side only, sets no cookies or browser storage. |
Performance
Helps us understand how HEADING is used so we can improve it — page views and feature usage, never sold or used for advertising.
| Name | Provider | Purpose |
|---|---|---|
ph_* | PostHog | Privacy-friendly product analytics (PostHog, EU-hosted) — only runs after you grant the Performance category. No analytics cookie is ever written. |
Manage your cookie choices anytime via the “Cookie settings” link in the footer, or in Settings if you’re signed in. See our Privacy policy for the full legal basis and sub-processor list.