This explains the cookies and similar storage Rople uses at rople.app.
1. Strictly necessary — always on
These cannot be turned off; without them you cannot sign in.
| Name | Purpose | Duration |
|---|---|---|
sb-access-token | Your signed-in session | Session / [1 hour] |
sb-refresh-token | Keeps you signed in without re-entering your password | [30] days |
rople-session | Application session state | Session |
| CSRF token | Prevents cross-site request forgery | Session |
We also use browser local storage to remember interface preferences — sidebar state, last-visited module, dismissed first-run cards. This never leaves your device.
2. Analytics — consent required
| Provider | Purpose | Duration |
|---|---|---|
| PostHog | Which features are used, where people get stuck | [12] months |
We configure PostHog to mask text input by default. We do not use it to build advertising profiles.
3. Error monitoring — legitimate interest
| Provider | Purpose | Duration |
|---|---|---|
| Sentry | Capture crashes and errors so we can fix them | [90] days |
Error reports can incidentally contain a user ID and the URL you were on. They do not intentionally capture workspace content.
4. What we do not use
No advertising cookies. No third-party tracking pixels for ad networks. No cross-site behavioural profiling. No selling of any of it.
5. Your choices
On first visit you are asked to accept or decline non-essential cookies. You can change this any time under Settings → Privacy. Declining leaves Rople fully functional. You may also block cookies in your browser, but blocking the strictly necessary ones will prevent sign-in.
6. Contact
[PRIVACY EMAIL]