This Cookie Policy explains how CASSO SOFTWARE uses cookies and similar technologies when you use Casso at usecasso.app and related services. It supplements our Privacy Policy.
In short: We use strictly necessary cookies to keep you signed in, and PostHog analytics and session-recording cookies / localStorage on the website to measure product usage and review UX. Form inputs in recordings are masked. We do not use advertising or retargeting cookies. Desktop product telemetry is first-party event data (not browser cookies) and can be turned off.
1. What cookies are
Cookies are small text files stored on your device by websites you visit. Similar technologies include local storage, session storage, and (for the desktop app) secure system storage such as the macOS Keychain. Together we call these "cookies" in this policy for simplicity.
2. How we use cookies
Casso uses cookies and similar technologies that are strictly necessary for authentication and account features, and analytics cookies / storage for website product analytics (PostHog). Without session cookies you cannot stay signed in or complete desktop license checks tied to your account. Without analytics storage, the site still works; we simply lose continuous analytics identifiers.
We categorise cookies as follows:
- Strictly necessary - required for the Service to function (session authentication). We use these.
- Functional - remember optional preferences. We do not set product-wide preference cookies on the website today beyond what is needed for auth. The desktop app may store a local telemetry preference (not a browser cookie).
- Analytics - measure website usage and review UX. We use PostHog on usecasso.app (when configured) for page views, page leave, basic interaction events (autocapture), and session recordings (DOM snapshots of page use with form inputs masked in the browser). Events and replay data are typically sent via a same-origin proxy path such as
/ingestor a dedicated reverse proxy host we operate (for examplep.usecasso.app). We do not use Google Analytics or advertising analytics SDKs. - Marketing / advertising - track ads or retargeting. We do not use these on the core product today.
Separately, the desktop app may send first-party product telemetry events to our API (for example app launch and annotation lifecycle events). That is not a browser cookie; see the table below and the Privacy Policy.
3. Cookies and storage we use
| Name / storage | Type | Purpose | Duration | How to control |
|---|---|---|---|---|
| better-auth.session_token | Strictly necessary | Keeps you signed in on the website (local / HTTP) | Session / up to ~30 days (refreshed while active) | Sign out, or clear site cookies in your browser |
| __Secure-better-auth.session_token | Strictly necessary | Same session cookie under the secure prefix in production HTTPS | Session / up to ~30 days (refreshed while active) | Sign out, or clear site cookies in your browser |
| ph_*_posthog | Analytics | PostHog product analytics and session recordings - stores a distinct ID and limited session state so page views, interaction events, and replay continuity stay continuous | Typically up to ~365 days (PostHog library default) | Clear cookies and site data for usecasso.app, or block cookies / storage for this site in your browser |
| PostHog localStorage keys (ph_*) | Analytics (local storage) | Holds the bulk of PostHog analytics and session-recording state alongside the cookie (localStorage+cookie persistence) | Until cleared in the browser | Clear site data / local storage for usecasso.app in your browser |
| Desktop Keychain session token | Strictly necessary (local) | Authenticates the macOS app for license checks (not a browser cookie) | Until you sign out or the session is revoked | Sign out in the app, or remove Keychain items for Casso |
| casso.telemetry.enabled (UserDefaults) | Preference (local, desktop) | Desktop preference controlling whether product telemetry events are sent to our API (default: enabled) | Until you change it or reset app preferences | Set to false in UserDefaults to disable desktop telemetry |
Exact cookie and localStorage names may vary slightly by environment (development vs production), PostHog project key, or library version. Session cookie purpose remains authentication; ph_* names remain product analytics for Casso.
4. Third parties
PostHog processes website analytics events and session recordings on our behalf. Analytics and replay requests are typically proxied through our domain so the browser talks to us first; PostHog still processes the event and recording data under its role as our analytics provider. See PostHog's privacy policy.
When you complete a purchase, you may be redirected to Stripe Checkout. Stripe may set its own cookies on its domain under its privacy and cookie practices. See Stripe's privacy policy. We do not control cookies set solely on third-party domains.
Download and update traffic may pass through CDN infrastructure (for example Cloudflare). Those requests are not used by us for advertising profiling.
5. Notice vs consent
Notice means we disclose what we use (this page and the on-site banner). Consent means an interactive accept/reject choice before non-essential storage is set - typically required for advertising cookies and, in some places, for analytics cookies.
Strictly necessary session cookies are required for sign-in and account features. This page is the disclosure (notice) for those cookies; they are not optional if you want to stay signed in.
Analytics cookies and localStorage used by PostHog help us understand product usage and (when session recording is active) review how the site is used. When analytics is configured, PostHog may initialise on the website by default (an opt-out model). In regions where a cookie notice is typically required (for example the EEA, UK, and Switzerland), a banner offers Accept (keeps analytics on and records your preference) or Necessary only (opts out of PostHog analytics and session recordings). Visitors outside those regions do not see the banner; analytics still runs unless you have previously opted out. Your choice is stored in localStorage under casso_cookie_consent. You can also clear or block site cookies and storage in your browser, and contact us to request deletion of analytics-linked account data (see Privacy Policy).
We do not use marketing, advertising, or retargeting cookies on the core product today.
6. How to manage cookies
You can control browser cookies and site data through your browser settings. Blocking all cookies may prevent sign-in and account features from working. Clearing only analytics cookies / localStorage typically resets PostHog identifiers without signing you out (session cookies are separate).
For the desktop app, sign out from Settings / Account, or remove stored credentials for Casso in macOS Keychain Access. To stop product telemetry events from the desktop app, set UserDefaults key casso.telemetry.enabled to false.
7. Do Not Track
We do not currently respond to browser Do Not Track (DNT) signals in a specialised way beyond the practices described here. There is no uniform industry standard for DNT. We do not use advertising tracking cookies on the core product; website analytics is described above.
8. Changes
We may update this Cookie Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes to cookie categories (for example new marketing cookies or a consent flow) will be reflected here.
9. Contact
Questions about cookies: [email protected].
Related: Privacy Policy / Terms of Service
This policy is a product-specific disclosure for Casso. It is not legal advice. Have a qualified attorney review for your jurisdictions before relying on it.