Cookies

Xerg Cookies

Xerg uses a small number of cookies. This page lists what they are, why they exist, and how to manage them.

Consent banner on xerg.ai

The marketing site loads the CookieYes consent banner on every page. CookieYes sets a first-party cookie (cookieyes-consent) that stores your consent choices so the banner does not ask again on every visit.

Advertising measurement on xerg.ai

The marketing site loads conversion tracking pixels from X, Meta, Reddit, and LinkedIn to measure whether visits from our ads on those platforms lead to sign-ups. Each platform may set cookies as part of this measurement; see the privacy policy of X, Meta, Reddit, or LinkedIn for how it handles that data. These pixels are managed through the consent banner: where prior consent is required (for example in the EEA and UK), they stay blocked until you accept the advertisement category.

Analytics on xerg.ai

The marketing site uses PostHog to understand traffic, page performance, and how visitors use the site. This includes automatic capture of page interactions such as clicks and form submissions, and session recordings of visits to the marketing site (form inputs are masked by default). PostHog stores a first-party cookie and browser storage to recognize return visits. It is managed through the consent banner under the analytics category, the same way as the advertising pixels above.

After analytics consent, Xerg also stores a first-touch attribution record in browser storage for up to 30 days. It contains only a normalized channel, strict UTM source/medium/campaign slugs, and an external referrer hostname. Email-like, URL-like, overlong, and free-form values are discarded, and Xerg never stores a full URL. On the signup page, a random one-time token may link PostHog's anonymous marketing identifier to a completed signup and first successful audit push. The token expires after 24 hours. Xerg clears the anonymous identifier after that activation and in all cases within 30 days. With no analytics consent, this storage and linkage do not run.

Signing in to the dashboard

The hosted dashboard uses Clerk for sign-in. Clerk sets strictly necessary session cookies to keep you signed in and to protect your session. These are required for the dashboard to work and are not used for tracking.

Optional review scheduling

The free agent spend review form does not load Cal.com automatically. After Xerg has saved your request, Cal.com loads only if you select Choose a time. Cal.com may then use cookies or browser storage needed to display availability and complete the booking. You can instead wait for a personal email without loading Cal.com.

Server-side product analytics

The dashboard does not load an analytics SDK. After selected successful product actions, Xerg's servers may send PostHog a pseudonymous workspace identifier and a small, fixed set of product-usage properties. This does not set an analytics cookie or browser storage, and it does not include prompts, responses, findings, policy values, cost figures, user identity, audit-source metadata, URLs, or browser and device metadata. When a signup carried consented attribution, product events can include only the coarse channel, source, medium, and campaign fields. They never include the anonymous marketing identifier or one-time token. A workspace administrator may object for the whole workspace by contacting query@xerg.ai.

Security

Our hosting provider, Cloudflare, may set cookies needed for security features such as bot protection when it challenges a suspicious request.

What we do not set

Beyond the ad platform pixels and PostHog analytics above, no advertising cookies and no cross-site tracking cookies. The hosted dashboard carries no analytics or advertising scripts at all. Its server-side product analytics does not set cookies or use browser storage. The local CLI is not a web surface and sets no cookies.

Managing cookies

Use the consent banner to review or change your choices at any time, or clear cookies in your browser settings. Withdrawing analytics consent also deletes Xerg's first-touch attribution record from browser storage and prevents a future anonymous signup link. Blocking the strictly necessary sign-in cookies will prevent the dashboard from working. The workspace-level hosted-product analytics objection process is described above and is separate from browser cookie controls.

Contact

Questions about cookies can be sent to query@xerg.ai.