Cookie Policy
This page lists every cookie the Flushia website can set, by name, together with who sets it, what it does, and how long it lasts. There are five in total, only one of which is optional — and most visitors only ever receive two. Nothing on this site is used for advertising.
Last updated 23 August 2026 · Version 1.0
01What this covers
This policy covers the Flushia website at flushia.com. It sits alongside our Privacy Policy, which explains what we do with personal data generally; this page is only about storage on your device. Where the two overlap, the Privacy Policy is the fuller statement of your rights.
The Flushia applications for iOS and Android do not use cookies at all. Section 9 explains what they do instead.
02What cookies and similar technologies are
A cookie is a small text file a website asks your browser to keep and hand back on your next visit. It is how a site recognises that two page loads came from the same person without asking you again.
Websites can also store data in your browser without using a cookie — local storage is the common one, and it behaves much the same except that it is not automatically sent back to the server. Our analytics provider uses both.
The distinction matters technically and not at all legally. European law is written around storing or reading information on your device, whatever the mechanism, so anything in the analytics category below needs your consent regardless of which technology it happens to use. We treat local storage exactly as we treat cookies.
03Your choice, and how to change it
The first time you visit, we ask. Until you answer, nothing optional runs: no analytics cookie is written, no local storage key is created, and no request is made to our analytics provider. Declining is a single click, in the same position and the same weight as accepting.
You can change your mind at any moment, in either direction, and it takes effect immediately:
The same control sits in the footer of every page. If you switch analytics off, the cookies in section 5 are deleted from your browser there and then.
Your answer is remembered for six months, after which we ask again. We will also ask again if we add a category or materially change what an existing one does.
04Strictly necessary cookies
These are set because the site cannot do its job without them. They carry no advertising identifier and are readable only by us. Under European law strictly necessary cookies do not require consent, which is why they have no switch — but they are listed here in full anyway.
| Cookie | Set by | Purpose | Expires |
|---|---|---|---|
cc_cookie | flushia.com | Records the choice you made about analytics, so we do not ask on every page. | 6 months |
authjs.session-token | flushia.com | Keeps an administrator signed in to the internal admin panel. | 30 days |
authjs.csrf-token | flushia.com | Protects the admin sign-in form against cross-site request forgery. | Session |
authjs.callback-url | flushia.com | Remembers which admin page to return to after signing in. | Session |
Only the first of these is set for ordinary visitors. The three authjs. cookies belong to the internal admin panel, which is not part of the public site and which you cannot sign in to without an administrator account. If you are reading this as a listener rather than as someone who runs Flushia, your browser holds cc_cookie and nothing else from this table.
Over an encrypted connection your browser will show those three names with a security prefix — __Secure-authjs.session-token, __Host-authjs.csrf-token and __Secure-authjs.callback-url. It is the same cookie; the prefix is an instruction to the browser to refuse it over plain HTTP.
05Analytics cookies
Set only if you accept analytics, and deleted as soon as you withdraw. There is exactly one, and it is listed below. Our analytics provider is PostHog, which we use to count visits and a small number of product events — a story started, a story finished — so we can tell what is worth making more of.
| Cookie or key | Set by | Purpose | Expires |
|---|---|---|---|
ph_<project>_posthog | PostHog | Distinguishes one visitor and one session from another so that visits are not double-counted. Stored both as a cookie and as a local storage key of the same name. | 1 year |
<project> stands for our PostHog project identifier, which is a fixed string; it does not identify you.
That is the whole list — one cookie and one local storage key of the same name. In particular, withdrawing consent does not leave an opt-out marker behind: we configure the analytics library so that switching off removes what it stored rather than replacing it with a record of your refusal. If a future version of that library writes such a marker anyway, we delete it at the same moment.
These are first-party cookies — they are readable on flushia.com and nowhere else, and they cannot be used to follow you to another site. What we send to PostHog, where PostHog stores it and how long it keeps it are set out in sections 7 to 9 of the Privacy Policy.
06What we do not use
This list is as much a part of the policy as the tables above, and it is exhaustive rather than reassuring:
- No advertising cookies, and no advertising network is present on this site.
- No third-party tracking pixels. No Meta pixel, no Google Ads tag, no TikTok pixel, no LinkedIn Insight tag.
- No cross-site or cross-device tracking, and no data broker or advertising identity graph receives anything from us.
- No device fingerprinting — we do not attempt to recognise you from your screen size, fonts, canvas rendering or similar signals.
- No social media plugins. Links to any social account are ordinary links; they load nothing until you click.
- No session replay — we do not record your screen, your mouse movements or your keystrokes.
- No blanket capture of what you click. Analytics libraries commonly offer a mode that records every click and every form interaction on the page automatically. It is on by default in ours and we have turned it off. We send a short, named list of events and nothing else.
- Nothing is sold or shared for advertising, in the sense those words carry under California and other US state privacy laws.
07What happens if you refuse
Nothing. Every page works exactly as it does for someone who accepted, you are not asked again for six months, and you are not shown a different site. We have no interest in making a refusal inconvenient — consent obtained by wearing someone down is not consent.
08Controlling cookies in your browser
The control in section 3 is the direct way, but your browser can also block or clear cookies for a site, and that setting overrides everything here. Look for “Cookies and site data”, “Privacy and security” or “Manage website data”, depending on the browser.
Two consequences worth knowing. Clearing cookies deletes cc_cookie along with the rest, so we lose the record of your choice and will ask again on your next visit. And blocking all cookies signs an administrator out immediately.
09The mobile applications
The iOS and Android applications use no cookies, no web view for the main experience, and no advertising or attribution SDK of any kind. They keep a sign-in token in the operating system’s secure storage — the iOS Keychain or the Android Keystore — so you do not have to sign in every time. That token is strictly necessary in the same sense as the cookies in section 4, and it is deleted when you sign out.
Product analytics in the apps follow the same rule as on the web: they are sent only where consent has been given. Until an app version ships its own consent prompt, it sends no analytics at all.
10Global Privacy Control and Do Not Track
Global Privacy Control. Some browsers and extensions send a GPC signal, which several US state laws treat as a binding opt-out of sale and sharing. We do not sell or share personal data for advertising in the first place, so there is nothing for the signal to switch off here.
Do Not Track. We do not act on the older DNT header, and we would rather say so than imply otherwise. It was never given an agreed meaning and most sites ignore it silently. The control in section 3 is the one that actually governs what we do, and it is a real switch rather than a request.
11Changes to this policy
If we add a cookie, change what one does, or add a category, this page is updated first and the version number and date at the top change with it. Where the change means the consent you gave no longer covers what we do, the banner reappears and asks again rather than assuming the old answer still holds.
12Contact
Questions about anything on this page: . If you think we have set a cookie that is not listed here, tell us — that is a bug in the document or in the site, and either way we want to know.