Cookie Policy
findrix_locale to section 2.1 now that the site is available in several languages. It stores only the language you pick and is set only when you pick one. 2026-09-23: this page was checked line by line against what the product actually sets. Four cookies that were listed but never existed (sb-access-token, sb-refresh-token, __Host-csrf, findrix_locale) were removed; the sign-in cookie, the first-party attribution and analytics cookies, the support-session and Google Analytics connection cookies, and the analytics opt-out flag were added with their real durations. No new cookie was introduced by this update. 2026-08-26: your cookie choice is now stored in a first-party cookie (fx_consent) shared across findrix.ai and app.findrix.ai, so deciding once covers both. It records nothing but the choice itself. 2026-08-14: added fx_auth_return to section 2.1. It carries no information about you and only prevents a wrong record being written after you sign in with Google. 2026-08-12: added fx_first_touch to section 2.4 — a first-party record of which campaign or link brought you to us, gated by the same advertising consent as the rest of that section. 2026-07-22 (v2.0): aligned with the product-launch Privacy Policy and sub-processor list; no new cookies added. Strictly necessary cookies are unchanged; optional analytics and advertising remain consent-gated by region.1. What cookies are
Cookies are small text files placed in your browser. We also use related technologies (localStorage, sessionStorage) for the same purposes. This policy covers all of them as "cookies" for simplicity.
2. Categories we use
2.1 Strictly necessary (no consent required)
| Cookie | Purpose | Duration |
|---|---|---|
| sb-auth-auth-token (plus numbered parts .0, .1) | Keeps you signed in. Set by our own application, not by a third party, and shared across findrix.ai and app.findrix.ai so one sign-in covers both; a long value is split across numbered parts | Up to 400 days, rewritten every time the session refreshes; cleared when you sign out |
| findrix_locale | Remembers the site language you chose, on both findrix.ai and app.findrix.ai. Set only when you pick a language | 1 year |
| fx_region | Remembers which regional consent rules apply to you | 24 hours |
| fx_analytics_disabled (cookie and browser localStorage) | Switches analytics and advertising tags off in this browser on both findrix.ai and app.findrix.ai. It is set only if you open a Findrix link carrying ?fx_analytics_disabled=1, and removed by the same link with =0 | 400 days |
| fx_auth_return (browser sessionStorage) | Marks that this browser tab came back from a sign-in provider, so we do not mistake the page you land on for the campaign that brought you here. It holds no information about you and exists only to stop a record being written | Until you close the tab |
| ga4_oauth | Carries the one-time security values for connecting a Google Analytics property, and only while that connection flow is open | 10 minutes |
| fdx_impersonate | Set only when a member of our team opens a support session on an account. The session is read-only — it cannot change anything — and the account shows a banner while it is open | 60 minutes |
These are required for the Service to function. They cannot be declined while you are signed in.
2.2 Functional (remembering your choices)
| Cookie | Purpose | Duration |
|---|---|---|
| fx_consent | Records your cookie choice — whether you allowed the optional categories, and when. The banner offers one decision for all of them, so analytics, advertising and functional are recorded together. Set on findrix.ai so the same choice applies on app.findrix.ai and you are asked only once. It holds no identifier | 13 months |
| findrix_cookie_consent (browser localStorage) | The same choice, kept as a local copy so it survives browsers that expire cookies early | Until you delete it |
| fx_cd | Records that you have made a cookie decision at all, so that declining is not mistaken for never having been asked. It does not hold the decision itself | 13 months |
| findrix_last_site | Remembers which of your sites you were last looking at, so the app opens on it instead of the most recently added one | 90 days |
2.3 Analytics
| Service | Purpose | Duration |
|---|---|---|
| PostHog (served from findrix.ai/ingest) | Anonymized product analytics. Its requests go to our own domain rather than to the vendor directly; it stores one first-party cookie named ph_…_posthog on findrix.ai | 12 months |
| Google Analytics 4 (googletagmanager.com) | Traffic & usage analytics (_ga, _ga_* cookies; Google Consent Mode v2) | Up to 2 years |
| Google Tag Manager (googletagmanager.com) | Loads the measurement tags configured in our container. It loads only once you have allowed all optional cookies; any cookie it sets belongs to the tag it loads | Set by the tag it loads |
Whether these run by default depends on where you are: see the regional table in section 3. Until analytics is allowed for you, Google Analytics sets no _ga cookies (Consent Mode stays denied), the tag-manager container does not load, and no advertising pixel loads. The Google Analytics library itself is requested on every page load so that your decision can be applied without reloading the page; that request reaches Google with your IP address and browser user agent before it is allowed to store anything.
First-party
| Cookie | Purpose | Duration |
|---|---|---|
| fx_aid | A random identifier our own servers use to count a visit once instead of many times. It is not readable by scripts in your browser, is never shared with a third party, and is set only where analytics is allowed for you — never before you accept in a region that asks first, and never after you decline | 13 months |
| fx_ads | Records that advertising measurement is allowed for you, so our servers apply the same decision as your browser does | 13 months |
2.4 Advertising
We use a small set of advertising pixels to measure our own ad campaigns and build retargeting audiences. We do not show third-party ads on Findrix.
| Service | Purpose | Duration |
|---|---|---|
| Meta Pixel | Measures our Meta ad campaigns; retargeting audiences | Up to 90 days |
| LinkedIn Insight Tag | Measures our LinkedIn ad campaigns; retargeting audiences | Up to 1 year |
| OpenAI Ads pixel | Measures conversions from our ads shown in ChatGPT | Set by OpenAI |
| FirstPromoter | Credits the affiliate or partner who referred you to us | 90 days |
These load only where and when permitted (see section 3). Each provider's own privacy policy is linked on our sub-processor page.
First-party
| Cookie | Purpose | Duration |
|---|---|---|
| fx_first_touch (browser localStorage) | Remembers which campaign or link brought you to us, so we can credit the right channel | 90 days |
| fx_ft | The same record as a cookie on findrix.ai, so the channel that brought you here is still known when you move to app.findrix.ai | 90 days |
| fx_signup | Marks that an account was just created through Google sign-in, so the sign-up is counted once. Cleared the first time it is read | 10 minutes |
3. How consent works in your region
Different places have different privacy laws (GDPR in Europe, CCPA/CPRA in the US, and similar), so the site behaves differently depending on where you visit from:
| Where you are | What happens by default | Your controls |
|---|---|---|
| European Economic Area, United Kingdom, Switzerland, Brazil, Japan, South Korea, Quebec (Canada) | Nothing is set. Analytics and ad measurement start only after you click "Accept all". | Cookie banner on your first visit. Change your mind anytime via "Cookie preferences" in the footer. |
| United States, Canada (outside Quebec), Australia | Analytics and ad measurement run unless you opt out. | Opt out anytime via the footer link (labelled "Do not sell or share my personal information" in the US). We also honor the Global Privacy Control browser signal automatically. |
| Everywhere else | Analytics and ad measurement run unless you opt out. | Opt out anytime via "Cookie preferences" in the footer. Global Privacy Control is honored here too. |
If we cannot determine your location, we err on the side of asking first: nothing runs until you accept, as if you were in the first row.
4. Manage your choice
Wherever you are, the "Cookie preferences" link in the footer lets you change your choice at any time (in the US it is labelled "Do not sell or share my personal information"). Withdrawing takes effect immediately.
Browser-level controls are also available. See your browser's help pages for "manage cookies".
5. Third-party cookies
The advertising and analytics providers listed in sections 2.3 and 2.4 above are the third parties that set cookies on this site. The cookies that keep you signed in are first-party: they are set by our own application, not by a third party. Separately, when you pay for a plan, the checkout and billing pages are hosted by Stripe and set their own cookies on Stripe's domain to process the payment and prevent fraud. The full list of providers is on our sub-processor page.
6. Global Privacy Control
We honor the Global Privacy Control (GPC) browser signal everywhere outside opt-in regions: it acts as an automatic opt-out, so no analytics or marketing cookies are set and no pixel loads. In opt-in regions your explicit banner choice governs. We no longer treat the legacy Do Not Track flag as a consent signal (it has no legal effect and browsers ship it inconsistently); use GPC or the "Cookie preferences" link instead.
7. Updates
When we add new cookies, we update this page and re-prompt for consent on next visit.
8. Contact
Cookie questions: privacy@findrix.ai. See also our Privacy Policy.
