Skip to content

Cookie Policy

Last updated: July 24, 2026

1. Your choice

Before you choose, PostHog counts visits and product interactions in cookieless mode without storing a PostHog identifier in your browser or associating activity with your account. Selecting Reject cookies keeps that mode active. Selecting Accept cookies enables persistent PostHog tracking, Tolt, Google Ads measurement, and Sentry error replay.

You can change your choice at any time. If you withdraw consent, OpenBudget removes known first-party optional tracking cookies and browser storage, then reloads the page so optional scripts are no longer active. PostHog continues in cookieless mode. Data already sent to a provider follows that provider's retention and deletion process. Your choice does not affect your account, bank connections, spreadsheets, or subscription.

2. Necessary storage

OpenBudget uses necessary cookies and browser storage for authentication, security, bank and spreadsheet connection flows, billing, interface preferences, and the consent choice recorded by this banner. These items support features you request and cannot be disabled through the analytics setting.

  • Authentication and security: Keeps you signed in and helps protect your account.
  • Connection and billing flows: Preserves the state needed to complete Plaid, Google, Microsoft, and Stripe requests you start.
  • Consent preference: Stores accepted or rejected for 180 days so we can respect your choice.

3. Product analytics

PostHog measures page views, product interactions, and device and browser details from your first visit. It starts in cookieless mode and stays there unless you accept optional tracking. In cookieless mode, PostHog uses the request's IP address and user agent to calculate a privacy-preserving hash on its servers, then strips the IP address before GeoIP enrichment. It does not store a PostHog identifier in browser cookies, local storage, or session storage, and OpenBudget does not identify signed-in users.

If you accept optional tracking, PostHog uses its persistent analytics pipeline and may associate signed-in activity with your account. PostHog can use the request's IP address to derive an approximate country or region and may also provide session replay when that feature is enabled in our analytics project. We use replay to investigate usability and technical problems. All page text and input values are masked in replay.

4. Referral and advertising measurement

If you accept, Tolt can record a referral identifier when you arrive through a partner link. We use it to attribute a later subscription to the referring partner.

On the production site, Google Ads can measure whether an ad leads to a subscription. We do not load the Google Ads tag when you reject analytics or when your browser sends a Global Privacy Control signal. Google Ads measurement may be treated as a sale or sharing of personal information under some U.S. state privacy laws.

5. Infrastructure and security

Our hosting and network providers, including Cloudflare, process IP addresses and request metadata to deliver the site, prevent abuse, and maintain security. This processing is necessary to operate the service and is separate from the optional analytics choice. The consent banner does not change crawler access or search indexing rules.

Sentry receives browser error details, device and browser data, and relevant request context when the site fails. We use these operational reports to diagnose errors. Sentry error replay loads only after you accept optional tracking, with page text, input values, and media masked or blocked.

6. Providers

7. Contact

For privacy questions, email support@openbudget.sh. You can also read our Privacy Policy.