Most cookie pages are long because the site has a lot to admit. This one is short, and it names every item.
What we set, and why
| What | Kind | Set by | Why |
|---|---|---|---|
Sign-in session (__session, __client_uat and related) | Cookie | Clerk, our identity provider | Keeps you signed in between pages. Without it, every page would ask you to sign in again |
PostHog ph_* identifiers and account profile properties | Cookie, localStorage and sessionStorage | PostHog | Connect product events and keep signed-in profile labels current |
wp_uid (opaque account ID) | localStorage | Us | Keep analytics identity consistent when you sign in or out in another tab. We use your account ID, not your name, email or Instagram handle |
wp_event:* | localStorage for sign-in/sign-up; sessionStorage for scan outcomes | Us | Avoid counting the same authentication callback or finished scan repeatedly |
Meta Pixel _fbp, _fbc | Cookie | Meta | Measure whether our own ads on Facebook and Instagram led to a visit, a sign-up, a checkout or a subscription |
wp_meta (first and latest ad click) | Cookie | Us | Remember which ad or campaign link brought you here — the click ID, campaign labels, landing page path and referring site, never the full address — so a later subscription can be credited to it |
| Razorpay checkout cookies | Cookie | Razorpay, on their own checkout window | Runs the payment, and the recurring mandate if you are subscribing. Set only when you open checkout, only by Razorpay, and governed by their policy |
The sign-in cookie and Razorpay's checkout cookies are strictly necessary: the product cannot sign you in or take a payment without them. That is why there is no banner asking you to accept them — there is no version of the service that works without them, so there is nothing to opt into.
PostHog identifiers, wp_uid, wp_event:*, Meta's _fbp/_fbc and wp_meta are analytics and ad measurement, not necessary. Clearing them costs you nothing; see How to clear it.
What we do not do
- One advertising pixel, for our own ads only. The Meta Pixel measures whether our ads on Facebook and Instagram worked. It is sent page views, a view of the pricing section, and account sign-up, checkout and subscription events with the plan and amount. It is never sent your Instagram handle, pitches, report contents or anything you type. See About Meta ad measurement.
- No unmasked recording of private content. Session replay masks input values and private page content. Public landing-page and policy text and static images remain visible; sensitive elements are blocked. We do not collect keystrokes, console logs or network request contents.
- No fingerprinting. We do not build a device or browser fingerprint.
- No cross-site tracking by us. We cannot see, and do not try to see, what you do elsewhere. Meta can connect a visit here to your Meta account under its own policy; clearing
_fbpand_fbc, or blocking third-party scripts, stops that. - No sale or sharing of browsing data. We do not sell it and we do not hand it to data brokers.
About Meta ad measurement
We advertise on Facebook and Instagram and use Meta's Pixel and Conversions API to learn which ads lead to subscriptions. From your browser, the Pixel sends page views, a view of the pricing section, and the sign-up, checkout and subscription events. From our server we send the same sign-up, checkout and subscription events with the plan, the amount charged and our own order reference, together with the _fbp/_fbc values, your IP address and browser user agent, and a one-way hash of your email address and account ID so Meta can match the event to the ad you saw. Meta receives no card or UPI details, no Instagram handle, no pitch or report contents, and no unhashed email. We keep your IP address and user agent for this purpose only until Meta has received the event (at most 30 days).
About the analytics
Product analytics run through PostHog, on their US infrastructure. We send event names for steps such as signup, scanning, opening a report, unlocking a brand, copying a pitch and checkout. Events use a random visitor ID before sign-in and an opaque account ID afterwards. Page paths exclude query strings and fragments. Confirmed purchase events include the amount, currency, billing cycle and opaque payment references.
Masked session replay helps us troubleshoot navigation. Input values and private page content are masked before they leave your browser. Public landing-page and policy text, styling and static images remain visible. Other images, authentication components and embedded payment windows are blocked. Sign-in, sign-up, account and payment pages are excluded, and recordings stop before on-page checkout opens. Recordings are retained for 30 days.
Button/link interactions and mouse positions support click, rage-click, dead-click and heatmap analysis. Button text and arbitrary element attributes are excluded. Browser exceptions and web-server errors include error types and code locations, with free-form messages and request contents removed. Feature flags and experiments reuse the existing analytics identifiers.
We also measure page visits and exits, time on a page, scroll depth, and numeric page-performance measurements (Web Vitals). We do not collect the page elements or resource details behind those performance measurements.
After sign-in, we attach your Clerk account name (when available) and verified primary email address to your PostHog person profile so we can recognize your account when reviewing product usage and troubleshooting. Your stable account ID connects events; changing your name or email does not create another identity.
We do not send Instagram handles, pitch contents, passwords, session tokens, card details or UPI details. We do not track your activity on other sites.
How to clear it
Clear site data for creators.ostryaai.com and everything in the table above goes with it:
- Chrome (desktop): Settings → Privacy and security → Third-party cookies → See all site data and permissions → creators.ostryaai.com → Delete.
- Safari (Mac): Safari → Settings → Privacy → Manage Website Data → creators.ostryaai.com → Remove.
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data → creators.ostryaai.com → Remove.
- On a phone: Settings → clear browsing data. Most phone browsers clear all sites, not just ours.
A private or incognito window keeps nothing after you close it.
What breaks if you clear it
You are signed out, and you sign in again. That is the whole effect.
Your account, your credit balance, the brands you have unlocked and your past reports live on our servers, not in your browser. Clearing site data does not spend a credit, cancel a scan, cancel a subscription, lock a brand you unlocked, or lose a report — sign back in and everything is where you left it. A scan already running keeps running.
Clearing this is not the same as deleting your data
Clearing your browser removes local copies. It does not delete the account, the scans or the reports we hold — for that you have to ask us, via Data Removal. Deletion is done by hand by an operator; there is no self-serve delete button yet.
If this changes
If we add another tool that writes to your browser, this page is updated before that code ships, naming the tool and what it collects, and we will add a consent mechanism if one is required. We will not quietly start tracking you and update the page afterwards.
For everything else about the data we hold, see the Privacy Policy and Data Sources.
Contact
Questions about browser storage or anything on this page: Raghav Mandhana, Grievance Officer, at raghav@ostryaai.com. More on Contact.