← Back to Tightly

Cookie Policy

Last updated: 3 June 2026

This policy explains what cookies and similar storage technologies we use, why, and how you can control them. It applies to our web app at tightly.nl and the embedded web views inside our iOS and Android mobile apps.

1. What are cookies?

Cookies are small text files stored by your browser when you visit a website. We use cookies for authentication, storing preferences, and (with your consent) measuring product usage.

2. Categories of cookies we use

2.1 Strictly Necessary Cookies

These cannot be disabled because the service would not work. Legal basis: GDPR Art. 6(1)(f) — legitimate interest in operating the site.

Name Purpose Expiry
sb-*-auth-token Supabase session token (keeps you signed in) 7 days
sb-*-auth-token.0 / sb-*-auth-token.1 Overflow tokens if session data is large 7 days

These are HTTP-only, so JavaScript cannot read them.

2.2 Preference Cookies (Local Storage)

We store preferences in your browser's localStorage, which is technically not a "cookie" but has similar persistence:

Key Purpose Expiry
tightly-theme Dark/light theme preference Never (until you clear browser data)
tightly-language Interface language Never
tightly-consent Your analytics consent decision Never

2.3 Analytics Cookies (PostHog, requires consent)

If you accept analytics in the consent banner, PostHog sets:

Name Purpose Expiry
ph_*_posthog Anonymous distinct ID, session ID, feature flags 365 days

We do not use Google Analytics, Facebook Pixel, or any advertising trackers.

3. No third-party tracking

We do not embed social media widgets (Facebook Like, Twitter share) or allow third-party ad networks to set cookies on our domain. The only external script (with consent) is PostHog, hosted at eu.i.posthog.com (EU datacenter).

4. How to control cookies

4.1 Consent banner

When you first visit, you'll see a consent banner asking if you accept analytics. You can change your mind at any time in Settings → Data & Privacy → Consent.

4.2 Browser settings

You can block all cookies or selectively delete them in your browser settings:

Note: blocking the Supabase auth cookies will log you out and prevent sign-in.

4.3 Do Not Track (DNT)

If your browser sends the DNT=1 header, we automatically disable PostHog even if you previously gave consent. We respect DNT as a clear opt-out signal.

5. Mobile apps (iOS & Android)

The native apps use the same web views, so the same cookies apply. In addition, the apps use:

These are local-only and not shared with third parties. You can clear them by deleting the app.

6. Changes to this policy

If we add new cookies or tracking mechanisms, we will update this page and notify you in the app or by email if you're a registered user.

7. Contact

Questions about cookies? Email hello@tightly.nl.

Privacy Policy · Terms of Service · Security