Cookie Policy
Last updated: 2026-09-25
What cookies we use
We use the cookies needed to run the Service, plus optional analytics cookies and optional advertising cookies from X (formerly Twitter). Visitors in the EU, EEA, United Kingdom and Switzerland see a consent banner on their first visit, and the optional ones stay off until they agree. Elsewhere, X advertising cookies are on unless your browser sends a Global Privacy Control signal or you turn them off. You can review or change your choices at any time with Cookie preferences below, or in Settings → Privacy once you are signed in.
Essential cookies
| Name | Purpose | Expires |
|---|---|---|
| token | Auth session (signed JWT). Required to stay logged in. | 7 days |
| pending2FA | Holds a Google or Microsoft sign-in while you enter your two-step verification code. | 5 minutes |
| mfa_ | Confirms that you have just re-entered your password, or signed in again with Google or Microsoft, before you turn two-step verification on or off. | 5 minutes |
| google_ microsoft_ | Protects a sign-in with Google or Microsoft against forgery. Deleted when the sign-in completes. | 10 minutes |
| oauth_ | Keeps your workspace invitation while you sign in with Google or Microsoft, so it is accepted when you return. | 10 minutes |
| integration_ github_ github_ | Protects the connection of an integration (GitHub, GitLab, Jira or Slack) against forgery while you set it up. | 10 minutes |
| jira_ | Remembers which Jira sites you can choose from while you finish connecting Jira. | 10 minutes |
| nl_ | Remembers your cookie choices. | 12 months |
| NEXT_ | Remembers the language you use Stride in. | 12 months |
| newlight-theme (local storage) | Remembers light or dark mode on this device. Kept in local storage rather than a cookie. | Until you clear it |
| stride_ | Records which campaign or link brought you to the site, so we know what to keep spending on. First-party; set when you arrive from a tagged link or another website; cleared when you create an account. Stride never sends its contents to an ad network. | 30 days |
Analytics cookies (optional)
| Name | Purpose | Expires |
|---|---|---|
| ph_*_posthog | Product-analytics identifier, so we can recognise a repeat visit and follow a journey across pages. Set only if you opt in. | 12 months |
We use PostHog for product analytics, to understand which features are used so we can improve the product. By default it runs cookieless: no cookie, no local storage, and no identifier that survives your visit, so we can count what happened but not who did it. If you opt in to analytics cookies we store a random identifier so we can recognise a repeat visit and follow a journey across pages. Analytics requests are sent to our own domain (/ingest) and forwarded to PostHog from our servers. PostHog analytics never track you across other sites.
Advertising cookies (optional)
We use the X (formerly Twitter) pixel on our public website and at two moments in sign-up: when you create an account and when you start a paid plan. It tells X that a visit, a sign-up or a purchase happened, so we can see which of our ads on X work. X receives the page address and referring page (never pages inside the product), your IP address and browser details, the ad-click code X added to the link you clicked (if any), and, for a purchase, the amount, currency and an anonymous order reference. We don't send X your name, your email address or anything from your workspace. X may connect this to your X account and uses it under its own privacy policy.
| Name | Purpose | Expires |
|---|---|---|
| _ | Keeps the ad-click code X added to the link you clicked, so a later sign-up or purchase can be credited to that ad. | Up to 13 months |
| _ | An identifier X's pixel uses to recognise this browser. | Up to 13 months |
| _ | An identifier X's pixel uses for a browsing session. | Up to 13 months |
| stride. (local storage) | Remembers that a sign-up or purchase from this browser was already reported to X, so it is never reported twice. | Until you clear it |
X's own cookies on x.com and twitter.com (for example muc_ads, personalization_id, guest_id) | Set and controlled by X under its privacy policy. | Set by X |
In the EU, EEA, United Kingdom and Switzerland the pixel stays off unless you accept Marketing cookies in the cookie banner. Everywhere else it is on by default, and off if your browser sends a Global Privacy Control signal or you turn Marketing off. Turn it off at any time with Cookie preferences below.
Managing your choices
If you were shown the consent banner, you can decline there. Wherever you are, you can open the picker at any time with the button below, or via Settings → Privacy → Cookie preferences once you are signed in. Turning off Marketing stops the X pixel in this browser, and we treat a Global Privacy Control signal from your browser as turning it off. Browsers also offer their own controls to block or clear cookies.
Contact
Questions? info@newlightai.com.