Cookie Policy

Version 2026-09-25 · Effective 2026-09-25 · Last updated 2026-09-25

1. Your choice

Necessary storage is always on for sign-in, security, core features and remembering your preference. Analytics is off until you choose it. You can reject non-essential storage, accept all or customize. Declining analytics does not block FakeRich. Cookie settings in the footer lets you change your choice at any time.

2. Necessary storage

FakeRich uses the HttpOnly fakerich.session_token sign-in cookie, normally lasting up to seven days (shorter for session-only sign-in). It uses Path=/ and SameSite=Lax and is shared across fakerich.app subdomains in production and fakerich.ddev.site subdomains in development. The current HTTPS configuration sets Secure and the __Secure- name prefix in production and DDEV. Session and account cache cookies are not enabled. Sign-in can also use short-lived OAuth state and session-only preference cookies. FakeRich stores the readable fakerich_privacy choice for up to one year, shared across production subdomains and host-only in development. Cloudflare security storage depends on the deployed configuration.

3. Optional PostHog analytics

After consent, PostHog may use first-party cookies or browser storage for product analytics, autocapture, heatmaps, web vitals and masked Session Replay. Its exact generated keys and lifetime depend on current SDK/project settings and must be verified in a deployed browser. No PostHog SDK is initialized before consent. Withdrawal stops capture and replay and clears its browser persistence using SDK opt-out/reset methods. Historical PostHog data requires a separate deletion process.

4. Further information

Read the Privacy Policy for data processing, processors, retention and rights. This policy will be updated when actual deployed storage changes.