Cookie Policy
Last updated: May 2026
Valevia uses a minimal, privacy-first approach to cookies and browser storage. We do not use any third-party advertising or retargeting cookies. No Facebook Pixel, no Google Ads, no remarketing — none of that.
This page explains exactly what we store in your browser and why.
1. Essential & functional cookies
We use a small number of essential and functional cookies. These keep the platform working or remember a basic preference, and do not require your consent under GDPR/ePrivacy rules.
| Name | Purpose | Duration | Flags |
|---|---|---|---|
vlv-auth-token | Authenticates your session after you log in. Contains an encrypted token — no personal data is stored in the cookie itself. | 7 days | HTTP-only, Secure, SameSite=Lax |
NEXT_LOCALE | Remembers your language preference (EN/FR/DE). | 1 year | Secure, SameSite=Lax |
| Auth library cookies | Our login library (NextAuth) sets standard session-security cookies, such as a CSRF-protection token. | Session / short-lived | HTTP-only, Secure |
2. Browser storage (not cookies)
We use your browser's local storage and session storage to remember UI preferences. This data never leaves your browser — it is not sent to our servers or any third party.
Local storage
| Key | Purpose | Duration |
|---|---|---|
vlv-consent | Stores your cookie consent preference (essential / analytics). Never sent to external servers. | Until you clear browser data or update your preference |
| UI state keys | Remembers interface preferences — collapsed panels, dismissed banners, viewed properties, demo tour completion. Approximately 12 keys, all non-tracking. | Persistent (browser storage only) |
Session storage
| Key | Purpose | Duration |
|---|---|---|
vlv_utm | Captures UTM marketing parameters (source, medium, campaign) from the URL that brought you to our site. Used to understand which channels drive signups. | Cleared when you close the browser tab |
3. Consent-gated analytics
We use PostHog for product analytics — page views, feature usage, funnel events. PostHog runs only when you grant analytics consent via our cookie banner. If you decline, no analytics events are collected and no PostHog cookies are set.
| Service | Purpose | Hosting | Loaded only on consent? |
|---|---|---|---|
| PostHog | Product analytics (anonymous user ID, page views, feature usage). No session replay, no heatmaps. | Frankfurt, Germany — PostHog EU Cloud | Yes |
When loaded, PostHog sets the following cookies:
| Name | Purpose | Duration |
|---|---|---|
ph_phc_* | PostHog distinct user identifier (pseudonymous). | 1 year |
You can withdraw analytics consent at any time by updating your preference in the cookie banner — PostHog cookies are then cleared and no further events are collected.
4. Server-side monitoring
We use two services to monitor platform health and catch errors. Neither sets cookies or tracks your behaviour. Both run on the server side only.
| Service | Purpose | Cookies |
|---|---|---|
| Sentry | Error and exception tracking. If something breaks while you use the platform, Sentry captures the error (with stack trace) so we can fix it. All personal data (email, name, phone) is automatically scrubbed before transmission. | None — Sentry does not set any cookies. |
| Azure Application Insights | Server-side infrastructure monitoring. Tracks outbound API calls (e.g. to Azure OpenAI) and unhandled server exceptions. Runs entirely on the server. | None — server-side only, no client-side code or cookies. |
5. What we do not use
For clarity, we do not use any of the following:
- Google Analytics, Plausible, or any other third-party website analytics
- Facebook Pixel, LinkedIn Insight Tag, or any advertising tracker
- Hotjar, FullStory, or any session replay / heatmap tool
- Third-party cookies of any kind
- Cross-site tracking or fingerprinting
- Retargeting or remarketing scripts
Our Content Security Policy headers actively block third-party tracking scripts from loading, even if they were accidentally introduced.
6. Your choices
You can delete our authentication cookie at any time by logging out or clearing your browser cookies. You will need to log in again on your next visit.
You can clear all local storage data via your browser's developer tools (Application → Local Storage). This will reset your UI preferences but will not affect your account.
You can withdraw analytics consent at any time via the cookie banner. PostHog cookies are then cleared and no further events are collected.
7. Changes to this policy
If we ever add additional analytics or non-essential cookies, we will update this page and ask for your consent before setting them. The date at the top of this page indicates when it was last changed.