Skip to content
IntuitionBack to home

Cookie Policy

Effective date: August 20, 2026

This Cookie Policy explains how Intuition Systems, Inc. uses cookies, browser storage, and related network services in the Intuition web application. It describes current application behavior and should be read with our Privacy Policy.

On this page

  1. 1. What cookies and browser storage are
  2. 2. Cookies we set
  3. 3. Browser storage we use
  4. 4. Optional analytics
  5. 5. First-party product events
  6. 6. External services
  7. 7. Your choices
  8. 8. Browser and device controls
  9. 9. Changes to this policy
  10. 10. Contact

1. What cookies and browser storage are

A cookie is a small text file that a website asks your browser to save and send back with later requests. A session cookie is deleted when you close your browser. A persistent cookie stays until it expires or you delete it, and the tables below give the expiry for each one.

Browsers also provide local storage and session storage. These keep values on your device without attaching them to every request: local storage stays until it is cleared, and session storage is discarded when the browser tab closes. Where this policy says “storage” it means all three.

First-party storage is set by Intuition on the domain you are visiting. Third-party storage is set by another company’s code or domain, such as an analytics or video provider. Every table below names which applies.

2. Cookies we set

These cookies support sign-in, security, recording your privacy choice, and interface layout, plus optional analytics once you grant it. Blocking the necessary ones in your browser may prevent parts of the Service from working.

Swipe or scroll horizontally to view all columns.

Cookies set by the Intuition web application, with purpose, duration, and party
NamePurposeDurationParty
<prefix>.session_token and __Secure-<prefix>.session_tokenKeeps you signed in and lets the server recognise your session. Strictly necessary. The prefix is configured per environment; browsers on HTTPS receive the __Secure- name.7 days, renewed while you stay signed inFirst party
<prefix>.session_data and __Secure-<prefix>.session_dataHolds a cached copy of your session so the server does not have to query the database on every request. Strictly necessary. It is HttpOnly, so page scripts cannot read it.7 daysFirst party
<prefix>.stateTies your return from Google back to the sign-in you started, so another site cannot complete it for you. Written only while you sign in with Google. Strictly necessary.Deleted when sign-in finishes. If you abandon sign-in your browser keeps it until it expires, but the attempt it protects is only accepted for 10 minutes.First party
<prefix>.legal_signup_intentCarries the Terms and Privacy acceptance you gave before signing up across the redirect to your sign-in provider and back. Strictly necessary. It is HttpOnly, so page scripts cannot read it.10 minutesFirst party
intuition_cookie_consentRecords your Analytics choice together with the version of the notice you saw and when you decided, so we do not ask again and the server can check consent before forwarding any analytics request. Strictly necessary.180 days (about six months)First party
onboarding_route_hint_<user id>Remembers where you had reached in onboarding so a reload returns you to the same step. The name includes your account ID so progress stays separate per account on a shared device. Functional.7 daysFirst party
sidebar_state, sidebar_hidden, sidebar_secondary_stateRecords whether you collapsed or hid the sidebar. Written by the shared sidebar component; this app does not currently read it back. Functional.7 daysFirst party
ph_*, __ph_*PostHog analytics identifiers, set only if your browser blocks local storage; otherwise PostHog uses local storage (see section 3). Written only after you grant Analytics, and deleted when you withdraw it.Set by the PostHog SDK; removed on withdrawalThird party (PostHog), set on the Intuition domain

Cookie names carry an environment prefix; the table lists the cookies this app sets in normal operation.

The consent cookie uses SameSite=Lax, is marked Secure over HTTPS, and is scoped to .intuition.systems on Intuition hosts so one choice covers those subdomains. Anywhere else it is host-only.

3. Browser storage we use

The Service also keeps values in local storage and session storage. These are grouped below by purpose rather than listed one key at a time, with the key patterns you would see in your browser’s developer tools.

Swipe or scroll horizontally to view all columns.

Local storage and session storage keys, with purpose, duration, and party
KeyPurposeDurationParty
intuition_analytics_consent_revocation (local storage)Records that you refused or withdrew Analytics, so the refusal still applies if the consent cookie is lost. A companion intuition_analytics_consent_revocation_probe key is written and removed immediately to test whether storage is available. Strictly necessary.180 days (about six months)First party
ph_*, __ph_* (local storage)PostHog distinct ID and session ID. Written only after you grant Analytics.Until you withdraw Analytics or clear site data; withdrawal removes these keysThird party (PostHog), stored on your device
wagmi.* (local storage)Remembers which wallet you last connected so the interface can reconnect and hydrate connection state safely. The wallet library uses local storage for this — no wallet cookie is set. The wallet-connector libraries may also store their own keys, such as rk-* for the connection dialog and wc@2:* for WalletConnect sessions. Functional.Until you disconnect or clear site dataFirst party
Interface and product preferences (local storage), for example intuition-active-theme, intuition-scaled-mode, intuition.search.recent, feed.settings.v1, settings.defaultTrustAmount, trustCircles.view, kg-panel-width, intuition.collection.pinned-stacks.*Remember settings you have chosen: theme and density, recent searches, feed and roster views, default TRUST amount, panel widths, and pinned stacks. Functional.Until you clear site dataFirst party
Drafts (local storage): onboarding-draft:<user id>, form-draft:<form key>Hold text and choices you have entered but not yet submitted, so a reload or an interrupted flow does not lose them. These entries contain content you typed. Functional.Until the draft is submitted, discarded, or you clear site data. Onboarding drafts expire automatically 7 days after they were last saved.First party
Product tour (local storage): intuition:product-tour:v<version>:<encoded user id>, plus an earlier resume keyTracks which tour steps you have completed. The key includes an encoded form of your account ID so progress stays separate per account on a shared device. Functional.Until you clear site dataFirst party
intuition:feed-event-session-id (session storage)A random identifier for feed events in the current tab, created before sign-in. See section 5 — it is not controlled by the Analytics switch.Until the tab closesFirst party
Short-lived interface state (session storage), for example intuition:back-navigation:v1, intuition:dismissed-build-sha, and create-flow preview togglesRemember where a back button should return to, that you dismissed an update prompt, and preview options in the create flow. The product tour also falls back to session storage when local storage is unavailable. Functional.Until the tab closesFirst party

4. Optional analytics

During closed testing, optional analytics is enabled automatically unless you have already opted out or your browser sends Global Privacy Control. You can turn it off in Settings. When the testing policy requires explicit opt-in, analytics stays off until you allow it. Unavailable consent storage prevents automatic opt-in.

Once eligible, the application loads analytics asynchronously and sends selected product events directly to PostHog in the United States. Dev error tracking also sends sanitized errors and masked session replays where enabled. Replay masks text and inputs, blocks media, and excludes console messages and network payloads. Errors include safe route, environment, release, and code-location details, without request payloads or identity properties. Automatic click-event capture is disabled.

Events use an account identifier while signed in or a temporary random identifier otherwise. Replay session state is held in memory and changes when the account changes. Turning analytics off stops capture, queued delivery, and recording. Your choice is remembered by the consent manager. The application configuration does not define a PostHog retention period.

5. First-party product events

Feed surfaces may create a temporary random feed-event identifier in session storage, including before sign-in. When you are signed in, feed interactions may also be sent to Intuition’s own recommendation service and associated with the authenticated account. This first-party product pipeline is separate from PostHog and is not controlled by the Analytics switch.

6. External services

Normal application pages request the Archivo, Archivo Black, Inter, and JetBrains Mono stylesheets from Google Fonts. Those requests disclose ordinary connection data, such as an IP address and browser information, to the font provider.

When configured, Sentry receives application errors and sampled performance traces so we can diagnose faults. Sentry runs for reliability rather than analytics, so it is not controlled by the Analytics switch and operates whichever choice you make. The current integration does not configure session replay or advertising features.

A geolocation script from Geo Targetly runs on most pages so that we can tailor region-specific content and comply with regional requirements. It receives your IP address and the address of the page you are viewing. It is not controlled by the Analytics switch, and it is not loaded on /legal-acceptance, /restricted, or /sanctioned.

The wallet connection interface registers supported wallet software, including Rabby, MetaMask, Coinbase Wallet, injected wallets, and WalletConnect when configured. When you choose a wallet, that provider may use its own storage and network services under its policy.

Card surfaces may request images from external media URLs. If you choose to play a YouTube video, Intuition loads a privacy-enhanced player frame from YouTube’s youtube-nocookie.com domain. The provider then receives ordinary connection and device data and may use storage under its own policy. Opening other external links takes you to the provider’s site.

7. Your choices

You can accept, reject, or change Analytics at any time through Cookie settings in an Intuition footer or account settings. If your browser reports Global Privacy Control, Analytics is denied even if an earlier cookie recorded a grant. Do Not Track is not treated as Global Privacy Control. If cookies are unavailable, your choice can apply for the current page session but cannot be remembered after a reload.

When you refuse or withdraw Analytics we also keep a record of that refusal in local storage, so losing the consent cookie cannot quietly turn analytics back on.

8. Browser and device controls

Independently of the controls in the Service, most browsers let you view, block, and delete cookies and site storage from their settings, usually under a privacy or site-data menu, and offer a private or incognito mode that discards storage when you close the window. Mobile browsers and in-app browsers offer similar controls.

Blocking or clearing storage has consequences here. Blocking the cookies in section 2 will sign you out and can stop sign-in, consent recording, and layout from working. Clearing site data deletes the record of your Analytics choice and your saved preferences and drafts, so the Service will ask for your choice again.

9. Changes to this policy

We update this policy when the storage or services the Service uses change. The effective date at the top of this page shows when the current version took effect, and the current version always replaces earlier ones. If we begin using optional storage for a new purpose, we will ask for your choice again before that storage is used.

10. Contact

Questions about this inventory can be sent to [email protected] with the subject “Privacy request”.

Intuition

Own your knowledge.

A shared knowledge graph, shaped by what you know and who you trust.

Build

  • Documentation (opens in a new tab)
  • Intuition Protocol (opens in a new tab)
  • GitHub (opens in a new tab)

Connect

  • About Intuition (opens in a new tab)
  • Community (opens in a new tab)
  • Contact support
  • Terms
  • Privacy
  • Data
Built by Intuition · © 2026
Analytics: off.