InnerTables

Cookie Policy

Last updated: August 4, 2026

1. What Does This Policy Cover?

This Cookie Policy explains how InnerTables (“we”, “us”, “our”) uses cookies and similar technologies - browser local storage, device and app storage, and software development kits (SDKs) - and the choices you have about them. It applies to our web application, our iOS and Android apps, and any related websites and services that link to this policy (together, the “Service”). “Cookies” below means all of these technologies unless stated otherwise.

Our Privacy Policy explains how we handle personal information generally, including your rights; its section on cookies, SDKs, and analytics is a summary that points here, while this policy is the authoritative description of the specific technologies we use. Our Terms of Service govern your use of the Service.

2. What Are Cookies and Similar Technologies?

3. What Do We Use Today?

Today the Service uses strictly necessary, first-party storage (sign-in and security), a small functionality cache for things you specifically request, and product-analytics storage through PostHog, whose servers for our account are in the European Union (PostHog Cloud EU). The complete list:

Name / Key Category Purpose Type Duration
_it_s0, _it_rt Strictly necessary Holds a sign-in token that keeps you signed in between visits. First-party local storage (web); secure device storage (secure store / OS keychain) in the mobile apps Persistent
Security and rate-limiting state Strictly necessary Short-lived sign-in state and request-rate counters that protect the Service against excessive or abusive requests. First-party, held in app memory only (not written to disk) Current session only
Form and preference cache Functionality Temporarily remembers details you are entering or have chosen - a half-completed form, your filter settings - so you do not have to re-enter them. First-party local storage (web); temporary app memory in the mobile apps Expires automatically after a short time-to-live set when the entry is saved (typically about 5-60 minutes)
PostHog analytics (apps and web app) Analytics / performance Shows us how the Service is used - screens and pages viewed, features used, technical/crash context - so we can improve it. Signed-in users are identified to PostHog by a pseudonymous internal user ID only (never your name or email), and that analytics identity is reset when you sign out. PostHog SDK identifiers in first-party app/local storage; event data is sent to PostHog Cloud EU (servers in the European Union) Persistent
ph_* (landing page) Analytics / performance PostHog’s JavaScript snippet on our public landing page stores a random device identifier and session state (keys beginning with ph_) to count visits and understand how the page is used. Visitors are not identified by name. Cookies and local storage set for our PostHog account (EU-hosted) Persistent - typically up to about 12 months, or until you delete them
None Advertising / remarketing Not used. We serve no third-party or interest-based advertising, do not sell personal information. - -
None Social media Not used at the moment. - -

The sign-in, security, and functionality storage above is first-party - created and read by InnerTables itself. The analytics storage is set for our PostHog account; There might be additional analytics included out-of-the-box by the 3rd party hosting of the app and/or our web services or products or other services. PostHog, our product-analytics provider, processes that data solely on our instructions under a data-processing agreement and may not use it for its own purposes (see the Privacy Policy’s service-providers section). Those hosting-level records are generated on the server side rather than stored on your device; apart from them, no other third party places cookies or similar technologies through the Service. If we change technologies, providers, or categories, we will update this policy first - and, where required, ask for your consent before any new non-essential storage goes live.

The sign-in, security, and functionality storage in Section 3 is strictly necessary or used solely to carry out something you specifically request - categories that laws such as the EEA/UK ePrivacy rules exempt from consent. Analytics storage is not strictly necessary.

Our members are currently located in Israel, where the law does not mandate a cookie-consent banner, so you may not see one. Instead, this policy discloses everything we store, and you can block or remove analytics storage at any time through your browser or device settings (Section 5) without any effect on your access. Before we serve users in a jurisdiction that requires prior consent for analytics, we will introduce a consent mechanism meeting its requirements - a separate, un-ticked checkbox at sign-up, an in-app control, or a banner, as appropriate. Your choice will be recorded in a single strictly necessary entry, valid for roughly 6 to 12 months - sooner if we introduce a category your earlier choice did not cover - after which we will ask again.

You will be able to withdraw or change consent at any time through that mechanism (once one exists) or your browser or device settings. You can also ask us to stop analytics processing relating to you by writing to support@innertables.com. Withdrawal stops us from setting or reading the relevant storage going forward, but it does not delete items already on your device - remove those yourself (Section 5) - and it does not affect the lawfulness of processing before withdrawal.

5. How Can You Control Cookies and Storage?

5.1 In your web browser

Most browsers let you view, block, restrict, and delete cookies and site data, including local storage. Official instructions:

“Clear site data” (or the equivalent) for the InnerTables web app or landing page removes both cookies and local storage, including the sign-in entry and the ph_* analytics identifiers. Content-blocking features and extensions can also prevent analytics requests entirely; the Service works normally without them.

5.2 In the mobile apps

On both platforms, signing out also resets your pseudonymous analytics ID, and clearing or deleting the app’s data removes the analytics identifiers stored on the device.

5.3 An honest warning about breakage

The strictly necessary storage in Section 3 is what keeps you signed in. If you block or clear it, you will be signed out, and sign-in and other core features will not work until you allow it again. Refusing non-essential storage never affects your access.

6. Notes for Users in Israel and the United States

Israel. The transparency and consent principles of the Protection of Privacy Law, 5741-1981 apply to tracking technologies that collect identifying information. We meet them by disclosing everything we store in this policy, using pseudonymous analytics identifiers rather than your name or contact details, keeping analytics data in the European Union with a provider bound to act only on our instructions, and giving you effective ways to prevent or remove analytics storage at any time (Section 5).

United States. If a US state privacy law (such as the CCPA, as amended by the CPRA) applies to you, your rights over data collected through cookies are described in the “Your Rights and Choices” section of our Privacy Policy.

We may update this policy when our technologies, our providers, or the law change, revising the “Last updated” date at the top. For material changes - such as a new category of cookies or storage - we will give prominent advance notice (by email and/or within the Service) before they take effect and, where required, ask for your consent before any new non-essential category goes live.

8. How to Contact Us

Questions about this Cookie Policy or the technologies it describes:

For how to complain to a data protection or privacy authority, see the contact and complaints section of our Privacy Policy.