Cookies, Analytics, and Session Replay
A full inventory of cookies and browser storage, including names, durations, and consent categories, is published in the Cookie Policy at /cookie-policy. In summary, the Platform uses cookies, local storage, and similar technologies for:
- authentication
- session management
- security
- preference storage
- analytics
- operational monitoring
- product improvement
On public marketing pages, optional analytics tools — PostHog, Google Analytics, and Google Tag Manager where configured — load only after you accept analytics cookies. If you reject optional analytics, public pages remain fully usable and only the consent preference is stored. You can change or withdraw that choice at any time from the Cookie Policy page or by clearing the consent cookie in your browser.
No advertising, remarketing, retargeting, or conversion tags are configured in the application code, and the public site does not perform cross-site tracking. If advertising tags are introduced to the tag-manager container in future, this policy and the Cookie Policy will be updated before they are enabled.
Inside the authenticated console, DataTether uses PostHog product analytics, autocapture, heatmaps, surveys, exception capture, and session replay to understand product usage, diagnose issues, improve reliability, analyze feature adoption, and support security or operational review. This processing is based on our legitimate interest in operating and improving the Platform. Login, signup, and OAuth consent routes are excluded from PostHog capture.
Session replay reconstructs what was displayed in the console during a session. Because the console renders data retrieved from your connected systems, a replay may include enterprise data that was on screen at the time. Replay is limited to the authenticated console, is not enabled on public marketing pages, and is subject to the retention period described in Retention and Deletion. Organizations with a requirement to disable session replay for their workspace can request it through the privacy contact.
Analytics data may include page visits, interaction events, browser and device information, session activity, approximate geographic region derived from IP address, feature usage metrics, error data, and replay or heatmap data where enabled. We configure capture to avoid collecting credentials and secrets, and sensitive values should not be intentionally entered into fields that are not required for the operation being performed.
The Platform does not currently respond to browser Do Not Track signals, because no consistent standard for them exists. Where the Global Privacy Control (GPC) signal is legally recognized for a visitor, we treat it as a valid opt-out of optional analytics for that browser.