Ultima actualizare

Politica de cookie-uri

v2026-08-22

Spinrun sets seven cookies of its own. Every one of them is necessary for something you asked the site to do — stay signed in, stay in the language you chose, stay in the workspace you opened, complete a sign-in without being hijacked halfway through, and remember the answer you gave about the eighth.

The eighth is analytics, and it is yours to decide. It does not load when you arrive. It loads if you say yes, it never loads if you say no, and you can change that answer from the footer of any page without having to find this one again.

  1. 01The choice you are given

    Consent is required for cookies that are not strictly necessary, and it has to be given before anything is set rather than assumed afterwards. So the first time you visit, nothing optional has loaded: no request has been made to an analytics provider, and no cookie of theirs exists in your browser.

    Accepting and refusing are the same size, in the same place, and one click each. Scrolling past the banner is not an answer, closing it is not an answer, and there is no version of this site that you have to accept anything to read.

    We remember your answer for six months and then ask again. Changing it in the meantime takes the same one click: "Cookie settings", at the bottom of every page.

  2. 02The cookies we set

    These are ours, they are necessary, and they are not part of the choice above — without them the things you asked the site to do would not work.

    sb-…-auth-token
    Your signed-in session, issued by Supabase and refreshed as you browse. The name varies with the project. Cleared when you sign out.
    spinrun_locale
    Remembers whether you asked for English or Romanian, so the choice survives a visit. One year.
    spinrun_ws
    Remembers which workspace this browser is currently working in. It is a selector, never an authorisation — what you can actually reach is checked against your real memberships on every request.
    spinrun_google_state
    Protects the Google sign-in flow against cross-site request forgery. Ten minutes, then deleted.
    spinrun_google_verifier
    The PKCE verifier that ties the end of a Google sign-in to the browser that started it. Ten minutes, then deleted.
    spinrun_consent
    The answer you gave about analytics, and when you gave it. This one is necessary because the alternative to remembering your answer is asking again on every page. Six months.
    sidebar_state
    Whether you left the dashboard sidebar open or collapsed. A layout preference and nothing else. Seven days.
  3. 03Analytics, only if you allow it

    If you accept analytics, we load PostHog on the marketing pages. It records which pages are opened and what is clicked, and it records session replays — a reconstruction of the page as you saw it — with every input field masked, so what you type is never captured. It is not loaded inside the product; the dashboard runs no analytics script at all.

    PostHog is hosted in the European Union and receives no data from us before you say yes.

    ph_…_posthog
    PostHog's own cookie: an anonymous identifier that lets it tell one visit from two. The name varies with the project. One year, or until you withdraw consent, whichever comes first.
  4. 04How they are set

    • Every cookie we set is SameSite=Lax, so none is sent along with a cross-site request, and every one is marked Secure over HTTPS, so none travels in the clear.
    • All of them are HTTP-only — no script on the page can read one — except `sidebar_state`, which is written by the browser because the sidebar it describes is drawn there. It holds one word: whether a panel is open.
    • The PostHog cookie is set by PostHog, in your browser, and follows its own rules rather than ours. It exists only after you have accepted, and expiring it is part of what withdrawing does.
  5. 05What we still do not set

    No advertising or retargeting pixel. No cross-site tracker. Nothing that follows you off this site, and nothing that builds a profile of you to sell.

    Content your agents author is served from routes deliberately kept outside the middleware that sets cookies, so no cookie of ours is ever attached to it, and no analytics script runs there either. That is a security property first — it means agent-authored HTML cannot borrow your session — and a privacy one second.

    Separately from anything in your browser: inside the product we record a small number of events on our own servers — a workspace created, a connection added, a run finished — against your account identifier, to know which parts of Spinrun are used. Nothing is stored on your device for it, no cookie is involved, and it never includes what your agents read or wrote. The Privacy Policy explains the basis for it and how to object.

  6. 06Turning them off

    Analytics: "Cookie settings" at the bottom of any page. Switching it off stores the refusal, expires PostHog's cookie and reloads the page without it. Withdrawing is meant to cost exactly what agreeing cost, and nothing you did while it was on is held against the choice.

    The rest: your browser can block or delete any cookie. Blocking the session cookie will stop you signing in; blocking the others degrades the site rather than breaking it — you will land in English, and you will have to pick your workspace again.

  7. 07Contact

    Questions about cookies go to legal@spinrun.ai.

Înainte să se încarce ceva

Am vrea să activăm analiza traficului, ca să vedem ce pagini merită păstrate. Nu s-a încărcat încă nimic și nu se va încărca nimic până nu alegi. Cookie-urile care te țin autentificat și îți rețin limba nu fac parte din asta.

Citește Politica de cookie-uri