Cookie Policy

Last updated: 2026-09-25

What cookies we use

We use the cookies needed to run the Service, plus optional analytics cookies and optional advertising cookies from X (formerly Twitter). Visitors in the EU, EEA, United Kingdom and Switzerland see a consent banner on their first visit, and the optional ones stay off until they agree. Elsewhere, X advertising cookies are on unless your browser sends a Global Privacy Control signal or you turn them off. You can review or change your choices at any time with Cookie preferences below, or in Settings → Privacy once you are signed in.

Essential cookies

NamePurposeExpires
tokenAuth session (signed JWT). Required to stay logged in.7 days
pending2FAHolds a Google or Microsoft sign-in while you enter your two-step verification code.5 minutes
mfa_recent_authConfirms that you have just re-entered your password, or signed in again with Google or Microsoft, before you turn two-step verification on or off.5 minutes
google_oauth_state
microsoft_oauth_state
Protects a sign-in with Google or Microsoft against forgery. Deleted when the sign-in completes.10 minutes
oauth_inviteKeeps your workspace invitation while you sign in with Google or Microsoft, so it is accepted when you return.10 minutes
integration_oauth_state
github_install_state
github_user_verification_state
Protects the connection of an integration (GitHub, GitLab, Jira or Slack) against forgery while you set it up.10 minutes
jira_connect_contextRemembers which Jira sites you can choose from while you finish connecting Jira.10 minutes
nl_consentRemembers your cookie choices.12 months
NEXT_LOCALERemembers the language you use Stride in.12 months
newlight-theme
(local storage)
Remembers light or dark mode on this device. Kept in local storage rather than a cookie.Until you clear it
stride_attrRecords which campaign or link brought you to the site, so we know what to keep spending on. First-party; set when you arrive from a tagged link or another website; cleared when you create an account. Stride never sends its contents to an ad network.30 days

Analytics cookies (optional)

NamePurposeExpires
ph_*_posthogProduct-analytics identifier, so we can recognise a repeat visit and follow a journey across pages. Set only if you opt in.12 months

We use PostHog for product analytics, to understand which features are used so we can improve the product. By default it runs cookieless: no cookie, no local storage, and no identifier that survives your visit, so we can count what happened but not who did it. If you opt in to analytics cookies we store a random identifier so we can recognise a repeat visit and follow a journey across pages. Analytics requests are sent to our own domain (/ingest) and forwarded to PostHog from our servers. PostHog analytics never track you across other sites.

Advertising cookies (optional)

We use the X (formerly Twitter) pixel on our public website and at two moments in sign-up: when you create an account and when you start a paid plan. It tells X that a visit, a sign-up or a purchase happened, so we can see which of our ads on X work. X receives the page address and referring page (never pages inside the product), your IP address and browser details, the ad-click code X added to the link you clicked (if any), and, for a purchase, the amount, currency and an anonymous order reference. We don't send X your name, your email address or anything from your workspace. X may connect this to your X account and uses it under its own privacy policy.

NamePurposeExpires
_twclidKeeps the ad-click code X added to the link you clicked, so a later sign-up or purchase can be credited to that ad.Up to 13 months
_twpidAn identifier X's pixel uses to recognise this browser.Up to 13 months
_twsidAn identifier X's pixel uses for a browsing session.Up to 13 months
stride.adconv.v1:*
(local storage)
Remembers that a sign-up or purchase from this browser was already reported to X, so it is never reported twice.Until you clear it
X's own cookies on x.com and twitter.com (for example muc_ads, personalization_id, guest_id)Set and controlled by X under its privacy policy.Set by X

In the EU, EEA, United Kingdom and Switzerland the pixel stays off unless you accept Marketing cookies in the cookie banner. Everywhere else it is on by default, and off if your browser sends a Global Privacy Control signal or you turn Marketing off. Turn it off at any time with Cookie preferences below.

Managing your choices

If you were shown the consent banner, you can decline there. Wherever you are, you can open the picker at any time with the button below, or via Settings → Privacy → Cookie preferences once you are signed in. Turning off Marketing stops the X pixel in this browser, and we treat a Global Privacy Control signal from your browser as turning it off. Browsers also offer their own controls to block or clear cookies.

Contact

Questions? info@newlightai.com.