Effective date: September 8, 2026
Overview
This Cookie Policy explains how Haplotype Wallet ("we," "us," or "our") uses cookies, browser local storage, session storage, and similar technologies when you use our Services. It should be read with our Privacy Policy and Service Provider List.
We currently use essential technologies for authentication, saved preferences, security, error reporting, and performance diagnostics. With your consent, we also use one optional measurement tool, PostHog product analytics. We do not use advertising or marketing cookies or cross-site tracking.
The consent banner lets you accept or reject optional measurement. Rejecting it does not change the essential technologies described below. When we added PostHog, we updated this Policy and the notice and asked every visitor for a fresh choice; a preference recorded before that date was not used to activate it.
What are cookies and similar technologies?
Cookies are small text files stored by a website in your browser. Local storage and session storage are browser features that store information for an origin. Local storage generally remains until it is cleared; session storage generally lasts only for the browser tab or authentication flow. These technologies may remember a session or preference or help a service coordinate a secure request.
Categories we use
- Essential operations. Always active because they provide authentication, remember privacy and display preferences, protect the Services, and let us detect and diagnose errors and material performance problems. This category includes WorkOS AuthKit, the c15t preference manager, the theme preference, and our narrowly configured Sentry monitoring.
- Optional measurement. Off by default. Used only by PostHog product analytics, described below. Accepting it starts the PostHog browser library and lets our servers record product-usage events for your account; rejecting it stops both and clears PostHog's browser storage. A saved choice in this category will not authorize a different tool without an updated notice and fresh choice.
We treat Sentry as an essential operational service because we use it only for error reporting, incident investigation, and sampled performance diagnostics needed to keep the Services reliable and secure. We do not configure Sentry for advertising, marketing profiles, session replay, or general product-usage analytics. If we materially broaden those purposes, we will reassess the category and obtain any choice required before the broader use begins.
Current cookie and browser-storage inventory
This inventory describes the production web application as of the effective date. Provider-managed names can change as security software is updated; we will update this inventory when a material change affects your choices.
| Technology | Storage or recipient | Purpose and data | Duration |
|---|---|---|---|
| WorkOS AuthKit | WorkOS authentication cookies, including the workos-has-session session indicator, on Haplotype and WorkOS authentication origins (including auth.haplotype.ai in production) | Essential authentication, session restoration, token rotation, fraud prevention, and sign-out. Stores or processes session and security identifiers, not uploaded Genetic Data or Biomarker and Health Data. | Until sign-out, revocation, or the configured WorkOS session, access-token, or inactivity limit expires. |
| WorkOS AuthKit | workos:code-verifier and, when needed, organization-selection values in session storage | Essential PKCE login protection and completion of an authentication redirect. | Removed after the callback or sign-out, or when the browser tab/session ends. |
| c15t consent manager | c15t-2 first-party cookie on the current host and c15t-2 local-storage record (the key changed from c15t when PostHog was added so that every visitor was asked again; the old cookie is ignored and expires on its own) | Essential record of the categories selected, consent metadata, and timestamps. Offline mode sends no consent record to c15t. Our server stores only whether your account accepted optional measurement, so server-side analytics can follow your choice. | Cookie: 365 days from the latest save. Local storage: until replaced or cleared in the browser. |
| Theme preference | theme in local storage on the current origin | Essential display preference containing light, dark, or system. | Until changed or cleared in the browser. |
| PostHog browser library | ph_<project key>_posthog first-party cookie and local-storage record on the current host; events sent to PostHog Cloud (United States) | Optional product analytics, active only after you accept optional measurement. Records an anonymous or, after sign-in, opaque account identifier, page paths, environment, browser and device details, and an IP address processed in delivering the request. Our configuration disables autocapture, session recording, surveys, and heatmaps, so page contents are never captured, and we never send account email addresses or uploaded genetic or biomarker contents. While your consent is active, our servers also send PostHog product-usage events for your account (for example that an upload finished, or that a connected AI tool ran, with the tool's name and timing). | Cookie: 365 days from the latest activity. Local storage: until you reject optional measurement (which clears it) or clear your browser. Events are retained under our configured PostHog service period and deleted with your account. |
| Sentry browser SDK | Diagnostic requests to Sentry; our configuration sets no Sentry cookie or Sentry local-storage item | Essential error and performance monitoring. Events may include an opaque account identifier after sign-in, page or application context, error and stack information, browser and device details, release and environment, timing information, and an IP address processed in delivering the request. We do not send account email addresses, uploaded genetic or biomarker contents, biomarker query contents, credentials, cookies, authorization headers, or session replay. Error events are sent when relevant failures occur; performance traces are sampled at 10%. | No Sentry browser storage. Diagnostic events are retained under our configured Sentry service period and deleted under the retention principles in our Privacy Policy. |
Temporary browser-storage entries may also be created and promptly removed by WorkOS to coordinate token refreshes across tabs or to test whether storage is available. They serve the same essential authentication and security purpose and are not used for advertising or analytics.
Managing your optional preference
The first banner presents Accept optional and Reject optional with equal prominence. Customize opens the detailed preference dialog. You can reopen the dialog at any time using Manage cookies in the footer.
Clearing browser cookies or storage may sign you out, reset the theme, and erase the saved preference. Blocking essential storage may prevent authentication or other parts of the Services from working. Rejecting optional measurement stops the PostHog browser library, clears its storage, and stops server-side product-usage events for your account. It does not disable WorkOS, the preference manager, the theme setting, or the essential Sentry configuration described above.
Do Not Track and Global Privacy Control
We do not use advertising networks, sell or share Personal Data for cross-context behavioral advertising, or track visitors across unrelated services. We do not treat a browser Do Not Track (DNT) setting as a consent signal. Optional PostHog measurement runs only if you accept it in our cookie notice. You can change that choice at any time using Manage cookies in the footer.
We recognize a supported Global Privacy Control (GPC) signal as a request to opt out of sale, sharing for cross-context behavioral advertising, and targeted advertising where applicable law requires. We do not currently conduct those activities, so there is nothing additional to opt out of. GPC does not disable essential WorkOS or Sentry operations. If our practices change, we will honor GPC as required and update this Policy and our Privacy Policy.
Changes to this Policy
We may update this Cookie Policy to reflect changes in technology, law, or our practices. We will revise the "Last updated" date and provide additional notice when required. We will not rely on an old optional-measurement preference to activate a materially different tool without an updated disclosure and fresh choice.
User-requested support
When live support is enabled, the Chatwoot widget loads only when you select
Start chat under Help. Rejecting optional measurement does not prevent this
requested service. The widget uses first-party cw_conversation and
cw_user_<website-token> cookies for visitor and verified-account continuity.
The pinned SDK sets these cookies for up to one year; that cookie lifetime is
not the transcript retention period. Wallet clears support identity on sign-out
and account changes. Pre-login conversations remain separate from account
conversations. Closing the chat panel does not delete a conversation.
The widget also processes connection and page metadata. See the Privacy Policy for support recipients and deletion limitations.