Cookie Policy
Effective Date: September 9, 2026 Last Updated: September 9, 2026
Our Privacy Policy explains our principles when it comes to the collection, processing, and storage of your information. This policy specifically explains how we deploy cookies, as well as the options you have to control them.
The explanatory text in this policy is adapted from the Automattic Cookie Policy, published free to use under CC BY-SA 4.0. The inventory of cookies is Xantly's own, and it is complete rather than representative.
What are cookies
Cookies are small pieces of data, stored in text files, that are stored on your computer or other device when websites are loaded in a browser. They are widely used to "remember" you and your preferences, either for a single visit (through a "session cookie") or for multiple repeat visits (using a "persistent cookie"). They ensure a consistent and efficient experience for visitors, and perform essential functions such as allowing users to register and remain logged in. Cookies may be set by the site that you are visiting (known as "first party cookies"), or by third parties, such as those who serve content or provide analytics services on the website ("third party cookies").
How we use cookies
We use cookies for two purposes only. Some are necessary for technical reasons: without them you cannot sign in and stay signed in. The rest are analytics cookies, which we set only if you allow them.
We do not run advertising cookies and we have no advertising partners. We do not use cookies to build a profile of you, to follow you across other websites, or to sell anything about you to anyone.
Where we place cookies
- On the website at xantly.com.
- In the dashboard at app.xantly.com.
The API at api.xantly.com does not set cookies for programmatic clients. Requests authenticated with an API key set nothing.
Types of cookie
| Category | Why we use these cookies |
|---|---|
| Required | Essential for the website and dashboard to perform basic functions. These include cookies required to allow registered users to authenticate and perform account-related functions, to protect those actions against cross-site request forgery, and to ensure the Service is operating properly. These are set whether or not you accept analytics cookies, because without them you cannot sign in. |
| Analytics | These let us see how the website and dashboard are used, including which pages are visited, so we can improve them. They are set only after you accept them, and you can change your mind at any time. |
The cookies we set
Required
| Cookie | Purpose | Lifetime |
|---|---|---|
xantly_at | Your access token. Identifies your signed-in session to the API. HttpOnly, so no script can read it. | 15 minutes |
xantly_rt | Your refresh token. Lets your session continue without signing in again. HttpOnly, and sent only to the refresh endpoint. | Cleared when you close the browser, unless you ticked "Remember for 30 days", in which case 30 days |
xantly_csrf | A token the dashboard reads and echoes back on every write, so another site cannot make requests as you. Readable by the dashboard by design. | Matches your session |
Analytics, set only if you choose "Accept All"
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
ph_* | PostHog, Inc. | Distinguishes one browser from another so page views and feature usage can be counted. | Up to 12 months |
Our analytics starts switched off. If you choose "Essential Only", or dismiss the banner, PostHog is opted out and none of these cookies are set. PostHog is also configured for session replay with every form input masked, which means we can see the shape of a session, not what you typed into it. If you decline analytics, no replay is recorded either.
Storage that is not a cookie
Two things we keep in your browser are not cookies at all. They live in local storage, they never travel with a request, and no third party can read them.
| Key | Purpose |
|---|---|
xantly_cookie_consent | Records the cookie choice you made, so we do not ask again |
xantly_redirect_after_auth | Remembers the page you were heading to, so we can return you there after you sign in |
PostHog also keeps some of its own state in local storage alongside its cookies, and only after you accept analytics.
Controlling cookies
Visitors may wish to restrict the use of cookies or completely prevent them from being set. Most browsers provide for ways to control cookie behavior such as the length of time they are stored, either through built-in functionality or by utilizing third party plugins. If you disable cookies, please be aware that some of the features of our service may not function correctly, and in particular you will not be able to stay signed in. To find out more on how to manage and delete cookies, visit aboutcookies.org.
On a mobile device, you may also be able to adjust your settings to limit tracking.
Within Xantly, the cookie banner on your first visit records your choice, and you can change it at any time from the same banner or by clearing the xantly_cookie_consent entry from your browser's local storage.
Changes and questions
We may update this policy to reflect changes to the cookies we set. Whenever we do, we will refresh the date at the top of this page.
Questions about this policy go to privacy@xantly.com.
Attribution
The explanatory text in this policy is adapted from the Automattic Cookie Policy by Automattic Inc., used under CC BY-SA 4.0, and this page is therefore made available under the same licence. Automattic does not endorse Xantly. Changes were made: the advertising sections were removed because Xantly runs no advertising, and the cookie inventory is Xantly's own.