Cookie Policy
Last updated 2026-05-14. Used by dink.one to keep you signed in, remember preferences, and understand how the product is used.
Categories we use
Strictly necessary - session cookie (auth) and CSRF token. We cannot run the product without these; they are not opt-outable.
Functional - your selected theme, locale, dismissed banners, soft-session id for not-yet-fully-registered people. These persist your in-app preferences.
Analytics - PostHog (product analytics and session replay - it records the pages you view, your clicks, and your scrolling so we can replay a visit to diagnose bugs) and Vercel Analytics (page-view RUM). These are loaded only after you accept the consent banner, so no recording happens until you do. You can opt out at any time via Settings → Privacy.
Sub-processors
Cookie-setting sub-processors as of this date: Vercel (hosting), Supabase (auth + data), PostHog (analytics, EU instance), Sentry (error tracking, no PII). The full sub-processor list with retention windows lives in the Privacy Policy.
Your choices
The first time you visit, a consent banner offers Accept-All / Reject-Optional. You can change your decision later in Settings → Privacy. Rejecting optional cookies does not affect access to the product.
Do Not Track
We honor Do Not Track headers as an implicit reject-optional signal. If your browser sends DNT, we treat that as if you had rejected analytics in the banner.