Last updated: 31 July 2026
This policy explains every cookie and similar technology (local storage and session storage) used on replien.com and inside the Replien application, what each one is for, how long it lasts, and which ones you can refuse.
It sits alongside our Privacy Policy, which covers everything else we do with personal data. Where the two overlap, this page is the more detailed one.
Nothing optional runs before you choose. Analytics cookies are loaded only after you accept them — not merely “enabled” after acceptance, but genuinely absent from the page until then. Refusing is one click, in the same place and at the same size as accepting.
You can change your mind at any time, and withdrawing is as easy as granting. When you withdraw, we do not simply stop collecting: we tell each provider to stop and to delete the cookies already on your device. Use the button below, or the same control in section 10 of the Privacy Policy; either clears your choice and re-opens the consent banner.
If your browser blocks the storage we use to remember your choice, we treat that as “not consented” and ask again — never as consent.
Replien is three different surfaces with three different levels of exposure, and they are not treated the same. This is enforced in code, not by policy alone.
| Surface | What runs there | Why |
|---|---|---|
| Public marketing pageshome, pricing, legal | Product analytics and session replay, with your consent. | Anonymous visitors, no customer data on screen. |
| The application/app, /settings | Product analytics events only, with your consent. No session recording, ever. We also do not record the text of what you click. | Every screen here shows your clients’ names, addresses and email bodies. Recording it would put their personal data in a third party’s hands, which is not ours to give. |
| Your clients’ pagesquote, appointment and demo links | Nothing at all — no analytics, no replay, no cookie banner, with or without consent. | Those visitors never entered a relationship with Replien, so any consent we collected there would be the wrong person’s. The page address itself is also redacted before any measurement, because the link is the credential. |
These either keep you signed in or remember a preference you set yourself. They are all first-party, none are shared with anyone, and the service does not work without them.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
better-auth.session_token |
Cookie | Keeps you signed in. You cannot use the app without it. | Up to 30 days, or until you close the browser if you did not tick “remember me” |
replien_analytics_consent |
Local storage | Remembers whether you accepted or refused analytics, so you are not asked on every page. | Until you clear it |
replien.theme, replien.lang |
Local storage | Your light/dark choice and your language. | Until you clear it |
replien.landing.currency, replien_setup_return, replien_setup_exited, gmail_oauth_state |
Session storage | The currency shown on pricing, where to return to in the setup wizard, and a one-time security value that protects the mailbox-connection step against request forgery. | Until you close the tab |
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
ph_<id>_posthog |
PostHogEU, Frankfurt | A pseudonymous id that lets us count returning visitors and see which steps of signing up people abandon. Session recording is switched off for this provider on every page, including the marketing pages. | 12 months |
_clck |
Microsoft Clarityfirst-party | Persists a pseudonymous Clarity user id, so repeat visits to our marketing pages are recognised as the same person. | Set by Microsoft — see below |
_clsk |
Microsoft Clarityfirst-party | Joins several page views into a single session recording. | Set by Microsoft — see below |
On Clarity’s lifetimes, plainly: Microsoft publishes the list of cookies Clarity sets but does not publish an expiry for them, and they are set by Microsoft’s script rather than by us, so we cannot state a number we have verified. We would rather say that than print a figure we made up. What Microsoft does publish is how long the data lasts: recordings are kept for 30 days, with favourited recordings and a random sample kept up to 9 months. The current list is at the Microsoft Clarity cookie reference. You can delete these cookies at any time from your browser, or by withdrawing consent — which instructs Clarity to erase them.
Clarity’s advertising cookies are switched off. Clarity can also set cookies on Microsoft’s own domains (MUID, ANONCHK, MR, SM, CLID) which Microsoft describes as being used for advertising. We send Clarity an explicit advertising storage denied signal on every visit, so these are not set for you. We run no advertising and have no use for them.
Vercel Speed Insights and Vercel Web Analytics report page-load speed and traffic counts. They store nothing on your device and identify no one, so there is nothing to consent to. Vercel already hosts this website and therefore already handles every request to it — this adds no new recipient of your data. We keep it un-gated on purpose: it is the only measurement that includes people who refused consent, which is what lets us tell a real drop in traffic apart from a change in how many people accept cookies.
| Provider | Role | Where the data is processed |
|---|---|---|
| PostHog | Processor — acts only on our instructions | European Union (Frankfurt) |
| Microsoft (Clarity) | Independent controller — see below | United States, under the EU–US Data Privacy Framework and Microsoft’s Standard Contractual Clauses |
| Vercel | Processor (and our hosting provider) | No personal data — cookieless and anonymous |
The one thing worth reading twice. Microsoft receives Clarity data as an independent controller, not as a supplier acting for us. That means Microsoft may use it for its own purposes, including advertising, under its own privacy terms rather than ours — and we could not stop it if we wanted to. We disclose this here rather than in a footnote because it is the single respect in which this stack is not purely on our behalf, and it is the reason the advertising signal described in section 4.2 is switched off. See the Microsoft Privacy Statement. If you would rather Microsoft received nothing, refuse analytics cookies — everything else on this site works exactly the same.
The “Manage cookies” control on the Privacy Policy is the most direct route, but every major browser also lets you view, block and delete cookies for a single site: look under Settings → Privacy in Chrome, Firefox, Safari or Edge.
Blocking strictly necessary cookies will sign you out and prevent the application from working. Blocking the analytics cookies has no effect on anything you can see or do.
If we add, remove or change a cookie, we update this page and the date at the top. Where the change means new non-essential cookies, we ask for your consent again rather than relying on a choice you made about a different set of cookies.
Questions about this policy, or about anything on your device:
Bernardo Pereira
Email: privacy@replien.com
You also have the right to complain to the Portuguese supervisory authority, the CNPD.