Politica de cookie-uri
v2026-08-22
Spinrun sets seven cookies of its own. Every one of them is necessary for something you asked the site to do — stay signed in, stay in the language you chose, stay in the workspace you opened, complete a sign-in without being hijacked halfway through, and remember the answer you gave about the eighth.
The eighth is analytics, and it is yours to decide. It does not load when you arrive. It loads if you say yes, it never loads if you say no, and you can change that answer from the footer of any page without having to find this one again.
01The choice you are given
Consent is required for cookies that are not strictly necessary, and it has to be given before anything is set rather than assumed afterwards. So the first time you visit, nothing optional has loaded: no request has been made to an analytics provider, and no cookie of theirs exists in your browser.
Accepting and refusing are the same size, in the same place, and one click each. Scrolling past the banner is not an answer, closing it is not an answer, and there is no version of this site that you have to accept anything to read.
We remember your answer for six months and then ask again. Changing it in the meantime takes the same one click: "Cookie settings", at the bottom of every page.
03Analytics, only if you allow it
If you accept analytics, we load PostHog on the marketing pages. It records which pages are opened and what is clicked, and it records session replays — a reconstruction of the page as you saw it — with every input field masked, so what you type is never captured. It is not loaded inside the product; the dashboard runs no analytics script at all.
PostHog is hosted in the European Union and receives no data from us before you say yes.
ph_…_posthogPostHog's own cookie: an anonymous identifier that lets it tell one visit from two. The name varies with the project. One year, or until you withdraw consent, whichever comes first.04How they are set
- Every cookie we set is SameSite=Lax, so none is sent along with a cross-site request, and every one is marked Secure over HTTPS, so none travels in the clear.
- All of them are HTTP-only — no script on the page can read one — except `sidebar_state`, which is written by the browser because the sidebar it describes is drawn there. It holds one word: whether a panel is open.
- The PostHog cookie is set by PostHog, in your browser, and follows its own rules rather than ours. It exists only after you have accepted, and expiring it is part of what withdrawing does.
05What we still do not set
No advertising or retargeting pixel. No cross-site tracker. Nothing that follows you off this site, and nothing that builds a profile of you to sell.
Content your agents author is served from routes deliberately kept outside the middleware that sets cookies, so no cookie of ours is ever attached to it, and no analytics script runs there either. That is a security property first — it means agent-authored HTML cannot borrow your session — and a privacy one second.
Separately from anything in your browser: inside the product we record a small number of events on our own servers — a workspace created, a connection added, a run finished — against your account identifier, to know which parts of Spinrun are used. Nothing is stored on your device for it, no cookie is involved, and it never includes what your agents read or wrote. The Privacy Policy explains the basis for it and how to object.
06Turning them off
Analytics: "Cookie settings" at the bottom of any page. Switching it off stores the refusal, expires PostHog's cookie and reloads the page without it. Withdrawing is meant to cost exactly what agreeing cost, and nothing you did while it was on is held against the choice.
The rest: your browser can block or delete any cookie. Blocking the session cookie will stop you signing in; blocking the others degrades the site rather than breaking it — you will land in English, and you will have to pick your workspace again.
07Contact
Questions about cookies go to legal@spinrun.ai.