Cookie Policy
Last updated: October 5, 2026
1. What Are Cookies
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently, provide a better user experience, and supply information to website operators. Cookies may be set by the website you are visiting ("first-party cookies") or by other websites that serve content on the page ("third-party cookies").
2. Cookies on Our Landing Page (filingiq.io)
Our landing page does not set any cookies. No first-party cookies, no third-party cookies, no sessionStorage, no fingerprinting. The one thing it may store is your colour theme: only if you switch between light and dark yourself, your choice is kept in your browser's localStorage (fiq-theme) so the next page opens the same way. That entry is strictly necessary for the function you asked for and needs no consent (§ 25(2) No. 2 TDDDG).
For traffic analytics we use Plausible Analytics, self-hosted on EU-based infrastructure we operate. Plausible is a privacy-friendly analytics tool that does not use cookies, does not generate persistent identifiers, and does not collect any personal data that can be used to identify individuals. Aggregate data such as page views, referrer, country, browser and device type is processed on our own server. Because Plausible stores nothing on your device, no consent under § 25 TDDDG (the German implementation of the ePrivacy Directive) is required.
The landing page's fonts, its analytics script, every portrait on our politician pages and every article-card image on our blog come from servers FilingIQ operates, so opening any page on filingiq.io does not reveal your IP address or your browser to any outside party. The blog images used to be fetched from UploadThing (United States); since September 2026 we download them when we build the site and serve them ourselves. Our API reference at docs.filingiq.io is the same: the renderer that draws it is served from that domain, not from a content delivery network. All of this is described in our privacy policy.
3. Cookies in Our Web Application (app.filingiq.io)
Our web application uses cookies and localStorage entries that are strictly necessary for its operation:
- Authentication: The session cookie of our sign-in system (
better-auth.session_token, over HTTPS with the prefix__Secure-) keeps you logged in so you do not need to re-enter credentials on each page. It lasts 7 days, is renewed once a day while you use the application, and is removed when you sign out. - Security: Protecting against cross-site request forgery (CSRF) and other security threats. If you sign in with Google, one of these short-lived cookies carries the state and verifier for that sign-in so the reply coming back can be checked as genuine. It is set by us, on our own domain, and is discarded once you land back here.
- Preferences, in localStorage: your answer to the cookie banner (
filingiq-consent,filingiq-consent-meta), your language (filingiq-language), your colour theme (theme), your table and score display settings (filingiq-table-preset,filingiq-show-cps-scores,filingiq-show-ifs-scores), whether you closed the getting-started checklist or the personalisation prompt, and your votes for planned features. They stay until you clear them in your browser.
Essential cookies and entries cannot be disabled as they are required for the Service to function correctly. They do not require consent (§ 25(2) No. 2 TDDDG). Only after you accept the cookie banner does PostHog keep an identifier for your browser in a cookie and in localStorage (names starting with ph_); that storage rests on your consent (§ 25(1) TDDDG).
4. Analytics in the Web Application
Our web application uses PostHog Cloud (EU) for product analytics, and only after you accept analytics cookies. When you are signed in, PostHog receives your account identifier, your email address, your name, your subscription tier and your beta cohort, alongside the pages you visit, the features you use, session duration, and the IP address your requests come from; our PostHog project is set to discard IP addresses, so they are not kept with your events. With the same consent, PostHog records your sessions: it reconstructs the pages you see, including their text, with your mouse movements, clicks and scrolling, plus the messages your browser writes to its developer console and the timings of network requests, without their content. What you type into form fields is masked and not recorded. PostHog also builds heatmaps from this, captures clicks automatically and measures page performance. Recordings are deleted after 30 days. All of it is processed on EU-based infrastructure. This processing is based on your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time in your cookie settings, which stops collection immediately. The same answer also decides whether our servers report events of your account to PostHog, as described in our Privacy Policy; that part touches nothing on your device, and declining stops it from the next event on.
PostHog receives product analytics only. Its browser SDK can also capture unhandled JavaScript errors, complete with the error message and a stack trace, and we have that feature switched off deliberately so that error data reaches one processor rather than two.
Our web application and API use Sentry (EU region) for error reporting, and Sentry is our only error-reporting processor. In the web application Sentry starts only after you accept the cookie banner, and it receives technical context (browser version, URL, stack trace) only when an unhandled error occurs; it stores nothing on your device. Our API also sends Sentry the timings of a 10 % sample of its requests, without your email address or IP address. Your email address, your username and your IP address are removed from the report before it is sent. Our API's application logs also carry error messages and go to Better Stack, which our privacy policy describes.
5. Legal Basis
In compliance with the ePrivacy Directive (2009/136/EC), the German Telecommunications Digital Services Data Protection Act (TDDDG), and the GDPR, FilingIQ applies the following framework:
- Landing page (filingiq.io): No cookies, no consent banner, and no device storage beyond the colour theme you choose yourself. Analytics is processed under legitimate interest (Art. 6(1)(f) GDPR) using self-hosted Plausible. You retain the right to object under Art. 21 GDPR by contacting legal@filingiq.io.
- Web application essential cookies are set without consent, as they are strictly necessary for the Service to function (Art. 6(1)(b) GDPR, contract performance).
- Web application analytics and session recordings (PostHog) and error reporting in the browser (Sentry) are processed on the basis of your consent, given through the cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
6. Managing Cookies
You can manage cookies through your web browser settings. Most browsers allow you to:
- View the cookies stored on your device.
- Delete individual cookies or all cookies.
- Block cookies from specific websites or all websites.
- Set preferences for first-party and third-party cookies separately.
- Receive notifications when cookies are being set.
For instructions on managing cookies in common browsers, please refer to your browser's help documentation or visit aboutcookies.org.
7. Impact of Disabling Cookies
Our landing page does not set cookies, so blocking them has no effect on your browsing experience there. In our web application, disabling essential cookies will prevent you from logging in and using authenticated features.
8. Changes
We may update this Cookie Policy from time to time to reflect changes in our practices or applicable laws. Updates will be communicated by posting the revised policy on the Service and updating the "Last updated" date. We encourage you to review this policy periodically.
If you have any questions about this Cookie Policy, please contact us at legal@filingiq.io.