Xerg Cookies
Xerg uses a small number of cookies. This page lists what they are, why they exist, and how to manage them.
Consent and privacy controls on xerg.ai
The marketing site loads CookieYes privacy controls on every page. CookieYes sets a
first-party cookie (cookieyes-consent) that stores your choices. In the
United States, optional tracking is initially enabled with disclosure and opt-out
controls without requiring a response to a first-visit notice. Use the lower-left
privacy icon to open the full settings. Everywhere outside the United States, an
opt-in notice is shown and optional categories stay blocked until you opt in.
CookieYes reloads the page after a consent change so the new choice applies to all
optional scripts.
Advertising measurement on xerg.ai
The marketing site loads conversion tracking pixels from X, Meta, Reddit, and LinkedIn to measure whether visits from our ads on those platforms lead to sign-ups. Each platform may set cookies as part of this measurement; see the privacy policy of X, Meta, Reddit, or LinkedIn for how it handles that data. Xerg classifies these pixels as selling or sharing personal data for targeted advertising. They load by default in the United States unless you opt out, and stay blocked everywhere else until you accept Advertisement. A Global Privacy Control signal blocks them even if CookieYes reports Advertisement as allowed. The advertising scripts are omitted from local development and Xerg's staging site.
Visitor identification on xerg.ai
On production pages, Xerg may use Cardinal Website Visitors, powered by RB2B, to associate a visit with company or professional identity information for sales and marketing follow-up. Xerg classifies this as selling or sharing personal data. It loads by default in the United States unless you opt out, stays blocked everywhere else until you accept Advertisement, and is always blocked while Global Privacy Control is active. The script does not load in local development or on Xerg's staging site. It may use cookie and device identifiers, IP address, user agent, current and referring page URLs, visit time, and matched professional or business contact information.
RB2B documents ten first-party cookies used for location, session continuity,
attribution, and identity resolution: _reb2bgeo,
_reb2bloaded, _reb2bref, _reb2sessionID,
_reb2buid, _reb2bfxf, _reb2btd,
_reb2bli, _reb2bresolve, and _reb2butk.
Their documented lifetimes range from one second to one year. You can also use
Retention.com's database opt-out or
RB2B's GDPR opt-out.
Analytics on xerg.ai
The marketing site uses PostHog to understand traffic, page performance, and how visitors use the site. This includes automatic capture of page interactions such as clicks and form submissions. Ordinary analytics and autocapture load by default in the United States unless you opt out, and stay blocked everywhere else until you accept Analytics. Session recording is disabled by default everywhere and starts only after you explicitly accept Analytics; form inputs are masked by default. PostHog stores first-party cookie and browser state to recognize return visits. The PostHog browser script is omitted from local development and Xerg's staging site.
After analytics consent, Xerg also stores a first-touch attribution record in browser storage for up to 30 days. It contains only a normalized channel, strict UTM source/medium/campaign slugs, and an external referrer hostname. Email-like, URL-like, overlong, and free-form values are discarded, and Xerg never stores a full URL. On the signup page, a random one-time token may link PostHog's anonymous marketing identifier to a completed signup, workspace pairing, and first successful audit push. The token expires after 24 hours. Xerg clears the anonymous identifier after both applicable milestones are accepted and in all cases within 30 days. With no analytics consent, this storage and linkage do not run.
Signing in to the dashboard
The hosted dashboard uses Clerk for sign-in. Clerk sets strictly necessary session cookies to keep you signed in and to protect your session. These are required for the dashboard to work and are not used for tracking.
Optional review and demo scheduling
The free agent spend review form does not load Cal.com automatically. After Xerg has saved your request, Cal.com loads only if you select Choose a time. Cal.com may then use cookies or browser storage needed to display availability and complete the booking. You can instead wait for a personal email without loading Cal.com.
When demo scheduling is unavailable, the demo page shows an email link and makes no Cal.com request. When scheduling is enabled, the embedded Cal.com scheduler loads as the page opens and may use cookies or browser storage needed to display availability and complete a booking.
Server-side product analytics
The dashboard does not load an analytics SDK. After selected successful product actions, Xerg's servers may send PostHog a pseudonymous workspace identifier and a small, fixed set of product-usage properties. This does not set an analytics cookie or browser storage, and it does not include prompts, responses, findings, policy values, cost figures, user identity, audit-source metadata, URLs, or browser and device metadata. When a signup carried consented attribution, product events can include only the coarse channel, source, medium, and campaign fields. They never include the anonymous marketing identifier or one-time token. A workspace administrator may object for the whole workspace by contacting hello@xerg.ai.
The objection disables future product-project PostHog delivery. It does not disable Xerg's separate 365-day D1 operational ledger of successful hosted pairing and audit-storage metadata, which is used for aggregate activation reporting and repair. Local CLI commands make no analytics call; explicit hosted pairing and push requests carry a fixed, content-free execution-context envelope.
Security
Our hosting provider, Cloudflare, may set cookies needed for security features such as bot protection when it challenges a suspicious request.
What we do not set
The hosted dashboard carries no analytics, advertising, or visitor-identification scripts. Its server-side product analytics does not set cookies or use browser storage. The local CLI is not a web surface and sets no cookies. Marketing-site tracking is limited to the consent-managed services described above.
Managing cookies
Use the lower-left privacy icon to reopen CookieYes, or clear cookies in your browser
settings. Withdrawing Analytics stops PostHog, stops session recording, deletes
controllable first-party PostHog and first-touch attribution state, and prevents a
future anonymous signup link.
Withdrawing Advertisement stops new advertising-pixel and Cardinal/RB2B requests
after the consent-triggered reload and deletes controllable first-party
_reb2* state. Xerg cannot directly delete a cookie already set on X,
Meta, Reddit, or LinkedIn's own domain. Global Privacy Control is stored as a
persistent sale/share opt-out; you can explicitly accept Advertisement only after
GPC is no longer active. Blocking strictly necessary sign-in cookies will prevent the
dashboard from working. The workspace-level hosted-product analytics objection
process is described above and is separate from browser cookie controls.
Contact
Questions about cookies can be sent to hello@xerg.ai.