The short version
- We set no cookies of our own and load no advertising or social tracking scripts. Optional first-party analytics is sent directly to Petrichor only after consent.
- The site keeps a handful of items in your browser's local storage so that sign-in, your theme, the demo chat and your consent choice work. These are strictly necessary or simple preferences.
- Two third parties can set their own cookies, but only when you use them: Google when you click "Sign in with Google", and Stripe when you open checkout or the billing portal.
- You can review or change your choice at any time via Cookie settings in the footer of every public page.
Cookies and similar technologies
Cookies are small files a website stores in your browser and reads back on later visits. Local storage, session storage and IndexedDB are similar browser features that keep data on your device without sending it automatically with every request. European ePrivacy rules treat all of them the same way: storage that is strictly necessary to provide a service you asked for needs no consent; anything else does.
Petrichor uses browser storage rather than cookies because our session credential is sent explicitly by the app, not attached automatically by the browser. That also means it is never sent to any third party.
What we store in your browser
This is the complete list of items Petrichor itself writes. Keys are shown as they appear in your browser's developer tools.
| Key | Type | Category | Purpose | Lifetime |
|---|---|---|---|---|
| petrichor-consent | localStorage | Necessary | Remembers the choices you made in the cookie banner so we do not ask again. | 12 months, then we ask again |
| petrichor-analytics-session | localStorage | Analytics | Opaque first-party session token for consented page and product activity; it contains no email or form content. | Until consent is withdrawn, site data is cleared, or the server retention window ends |
| petrichor-theme | localStorage | Preference | Light or dark theme you picked with the toggle. | Until cleared |
| petrichor.token | localStorage | Necessary | Your signed-in session credential. Sent with each request to prove it is you. | Until you sign out or the token expires |
| petrichor.impersonation.token | localStorage | Necessary | Only present while Petrichor staff assist inside your account with your permission. | Until the support session ends |
| petrichor.guestToken | localStorage | Necessary | Keeps your demo conversation on the landing page attached to the same temporary guest session. | Until the guest session expires |
| petrichor.onboarding.companyProfileJobId | localStorage | Necessary | Lets onboarding resume the background crawl of your website if you reload. | Until onboarding finishes |
| petrichor:chat:new-draft:* | sessionStorage | Necessary | Holds an unsent chat draft so a reload does not lose it. | Until the tab closes |
| petrichor:*:filters:v1 and other petrichor.* preference keys | localStorage | Preference | Sidebar state, list filters, dismissed hints and read markers inside the app. | Until cleared |
| Pending chat attachments | IndexedDB | Necessary | Temporarily stores files you attach to a chat message before they upload. | Until the upload completes |
Fonts are bundled with the site and served from our own domain, so no request goes to a font provider. Images and video on the marketing pages are served from our domain as well.
Third parties that may set cookies
| Service | When | What it does | Their policy |
|---|---|---|---|
| Google (Sign in with Google) | Only when you click the Google sign-in button | Google's sign-in popup runs on Google's domains and may set Google cookies to keep you signed in to Google and to protect against abuse. We receive only your email, name and account identifier. | Google Privacy Policy |
| Stripe | Only when you open checkout or the billing portal | Stripe's hosted pages set cookies for fraud prevention and to complete payment. Card details are entered on Stripe, not on our site. | Stripe Privacy Policy |
Services you choose to connect inside the app (email, LinkedIn, CRM and sending tools) run on their own domains under their own cookie policies. Connecting them is your choice and can be reversed from Integrations.
Your choices
The banner
On your first visit a banner offers Accept all, Necessary only and Preferences. Both main buttons are equally available; nothing optional is switched on until you choose it. Your choice is recorded in the petrichor-consent key for 12 months, after which we ask again. We also ask again if the categories change.
Changing your mind
Click Cookie settings in the footer of any public page to reopen the preferences panel. Clearing your browser's site data for our domain removes the record as well and the banner returns.
Browser controls
Every major browser lets you block or delete storage for individual sites. Blocking necessary storage will sign you out and stop the demo chat from keeping its context, but the rest of the site will still load.
Do Not Track and Global Privacy Control
We do not track you across sites, so there is nothing for these signals to switch off. We treat a Global Privacy Control signal as a request not to sell or share personal information, which we do not do in any case.
First-party analytics
With Analytics on, Petrichor records first-party page paths (query strings removed), pricing views, demo-form milestones, signup and selected authenticated product actions. We do not record form contents, credentials, session replay or cross-site advertising identifiers. Anonymous events remain anonymous unless a verified login or confirmed demo supplies a signed identity association, and the CRM labels the association confidence. Anonymous events are retained for 30 days and identified events for 90 days. Turning Analytics off stops future capture and revokes the browser session token.

