---
title: "Cookie Policy"
description: "This Cookie Policy lists every cookie and browser storage key used on caveman.so, docs.caveman.so and the Caveman Cloud dashboard, what each one does and how long it lasts. The website sets no cookies"
canonical: https://caveman.so/legal/cookies
last-updated: 2026-10-07
status: "draft, not yet in effect"
version: "2026-10-06"
publisher: "Caveman Labs, Inc."
contact: "contact@caveman.so"
---

# Cookie Policy

This Cookie Policy lists every cookie and browser storage key used on caveman.so, docs.caveman.so and the Caveman Cloud dashboard, what each one does and how long it lasts. The website sets no cookies; the dashboard sets only cookies that are strictly necessary for sign-in and security.

## Summary

This summary is for convenience. The full policy below governs.

- The Website (caveman.so and docs.caveman.so) sets no cookies.
- The Caveman Cloud dashboard (app.caveman.so) sets only cookies that are strictly necessary to sign you in and keep your account secure. Its sign-up page uses Cloudflare Turnstile to keep out bots.
- Both save a few preferences in your browser's local or session storage. These are not sent to us automatically.
- We use no advertising cookies and no cross-site tracking.
- caveman.so runs cookieless product analytics, including session replays with every form field masked. It stores nothing on your device. It is configured for the dashboard but not switched on there.

This policy is published by Caveman Labs, Inc. ("Caveman", "we", "us"). It forms part of our [Privacy Policy](/privacy), which explains how we handle personal data more generally.

## What cookies and similar technologies are

A cookie is a small text file that a website asks your browser to store and send back on later requests. A cookie set by the site you are visiting is a first-party cookie; one set by another domain is a third-party cookie. Session cookies are deleted when you close your browser; persistent cookies last until they expire or you delete them.

Similar technologies include your browser's local storage and session storage, which let a site save data on your device that is not sent to the server automatically, and scripts or requests that load content from another company's servers. This policy covers all of these. We refer to them together as "cookies and similar technologies".

## The Website

### Cookies on the Website

The Website sets no cookies. An earlier version of our site could leave sign-in cookies named `cave_access` and `cave_refresh` in your browser. If the Website finds either of them, it deletes them. It does not set any new ones.

### Local storage on the Website

The Website saves the following values in your browser's local storage. None of them identifies you, and none is sent to us.

| Key | What it does | How long it lasts |
|---|---|---|
| `cave-banner` | Remembers that you dismissed the announcement banner, so it stays hidden | Until you clear it |
| `cave.hero` | Remembers which homepage header design was last selected, so it stays the same when you come back | Until you clear it |
| `cave.stars.*` (one per repository) | Caches the GitHub star count for each of our repositories between visits | Until you clear it |
| `cave.onboarding`, `cave.onboarding.done` | Remember your progress through the interactive product demo on the homepage | Until you clear it |
| `cave.fleet.setup-complete` | Remembers that you dismissed the setup checklist in the homepage demo | Until you clear it |
| `cave.compression-caching-note.dismissed` | Remembers that you dismissed a note in the homepage demo | Until you clear it |

### Third-party requests from the Website

Some Website features load content from other companies. When they do, that company receives your IP address and browser details under its own privacy policy.

- **GitHub.** Pages that show star counts for our repositories fetch them from api.github.com directly from your browser. GitHub's [privacy statement](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement) applies.
- **Cal.com.** Booking buttons open a Cal.com scheduling window. The Cal.com script does not load when the page loads. It loads only when you hover over, focus or click a booking button. Once the booking window opens, Cal.com may set its own cookies or use local storage on its own domain to run the scheduler and remember your choices, and it processes the details you enter. We do not control those technologies. Cal.com's [privacy policy](https://cal.com/privacy) describes them.

The Website serves its fonts from our own domain, so your browser makes no request to Google Fonts. Site search runs against our own documents and sends nothing to an AI model.

## The Caveman Cloud dashboard

### Dashboard cookies

The dashboard sets the cookies below. All of them are first-party and strictly necessary: they make sign-in work and protect it against attacks. Names that begin with `__Secure-` can only be set over HTTPS.

| Name | Purpose | Lifetime | Type |
|---|---|---|---|
| `__Secure-cave_identity.session_token` | Keeps you signed in. HttpOnly, Secure, SameSite=Lax, and sent only to the host that set it | 7 days, renewed while you use the dashboard | Strictly necessary |
| `__Secure-cave_identity.two_factor` | Holds your place in the multi-factor authentication step of sign-in | 10 minutes | Strictly necessary |
| `__Secure-cave_identity.better-auth-passkey` | Holds the security challenge while you register or sign in with a passkey | 5 minutes | Strictly necessary |
| `__Secure-cave_identity.state` | Protects Google and single sign-on logins against cross-site request forgery | 5 minutes | Strictly necessary |
| `cave_oidc_state` | Protects single sign-on (OpenID Connect) logins against cross-site request forgery | 10 minutes | Strictly necessary |
| `__Secure-cave_identity.saml_binding` | Ties a SAML single sign-on response to the browser that started the sign-in | 5 minutes | Strictly necessary |
| `__Secure-cave_identity.invite`, `__Secure-cave_identity.join` | Carry an invitation or a join link through sign-in, so you land in the right Workspace | 15 minutes | Strictly necessary |
| `__Secure-cave_identity.free_notice` | Records that you agreed to the Free plan's Product Data Sharing screen while your account is being created | 60 minutes | Strictly necessary |
| `cave_access`, `cave_refresh` | Carry your session to the control API after some single sign-on and CLI sign-ins. HttpOnly and Secure | `cave_access` 15 minutes; `cave_refresh` 30 days, sent only to paths under `/api/v1/auth` | Strictly necessary |
| `cave_github_connect` | Keeps track of the GitHub connection flow. Sent only to paths under `/api/v1/github/` | 30 minutes | Strictly necessary |

The dashboard sets no advertising, analytics or cross-site tracking cookies.

### Browser storage in the dashboard

The dashboard saves the following in your browser. These values are never sent to us automatically.

| Key | Storage | What it does | How long it lasts |
|---|---|---|---|
| `cave.project`, `cave.projects.v1` | Local storage | Remember the project you last selected and the list of your projects | Until you clear it |
| `cave.sidebar.collapsed`, `cave.sidebar.folds` | Local storage | Remember whether you collapsed the sidebar and which of its groups you folded | Until you clear it |
| `cave.onboarding`, `cave.onboarding.done` | Local storage | Remember your onboarding progress | Until you clear it |
| `cave.dashboards.pinned.v1` | Local storage | Remembers the dashboards you pinned | Until you clear it |
| `cave.minichat.v1` | Local storage | Remembers where you placed the Ask panel and whether it is expanded. It holds no conversation text | Until you clear it |
| `caveman.agent` | Local storage | Remembers which coding agent you picked in setup instructions | Until you clear it |
| `cave.roles.v1` | Local storage | Caches which actions each role may take, so buttons show correctly before the server answers | Until you clear it |
| `cave.lucy.threads.v2` | Local storage | Earlier versions kept Ask threads here. The dashboard now deletes this key when it finds it | Deleted on your next visit |
| `cave.session.seen`, `cave.session.epoch.v1` | Local storage | `cave.session.seen` holds your user ID, Workspace ID and role so the dashboard can skip its loading screen, and is removed when you sign out. `cave.session.epoch.v1` is an opaque signal that lets open tabs notice when you sign in or out; it holds no identity values | Until you clear it |
| `github-app-project:` followed by a random state value | Session storage | Remembers which project you are connecting while you set up the GitHub App | Until you close the tab |
| `cave.quick-actions.v1:` followed by your Workspace and user IDs | Session storage | Remembers your recent actions in the command menu | Until you close the tab |
| `cave_sample_data_project` | Session storage | Remembers that you are viewing sample data | Until you close the tab |
| `cave.nav.current`, `cave.nav.previous` | Session storage | Remember the page you came from, so Back returns you to the same filters and view | Until you close the tab |
| `cave_invite_token`, `cave_join_token`, `cave_join_link` | Session storage | Carry an invitation or join link through sign-in in this tab. Removed when the flow ends or you sign out | Until the flow ends or you close the tab |
| `cave-query-cache` | IndexedDB | Caches recent dashboard responses, such as project lists, settings and aggregate reports, so pages open quickly. It never caches traces, sessions, prompts, chat or other content that can hold captured request or response text | Entries expire after 7 days; you can clear it in your browser |

### Third-party requests from the dashboard

The dashboard's Content Security Policy allows two third-party sources:

- **Cal.com**, whose booking script from app.cal.com is used for booking calls with us. What Cal.com does once its booking window opens is described in the Website section above.
- **Cloudflare Turnstile**, from challenges.cloudflare.com, on the sign-up page. It checks that you are a person, not a bot. Cloudflare receives your IP address and browser signals under its own privacy policy, and Turnstile may use storage on Cloudflare's own domain to do this check.

## Analytics

We use PostHog, on its EU cloud, for product analytics on caveman.so. It is cookieless: it keeps its identifiers in memory only, so nothing is stored on your device and they disappear when you close the tab. Each visit therefore starts fresh.

On caveman.so it records:

- the pages you visit, as page paths without query strings, and how long and how far you read;
- the buttons and links you click, with their visible labels, and click and scroll heatmaps;
- page speed, script errors and browser console messages;
- campaign tags (utm_*) on the link that brought you here, with ad click IDs masked, and the referring site's domain and search engine, but never the full referring address or your search terms;
- your approximate location, derived from your IP address, which is then discarded;
- if you join a waitlist or book a call, a link between that visit and your email address or Cal.com booking, for that browser tab only; and
- session replays of how pages render and respond. Every form field is masked in your browser before anything is sent, request and response contents are not recorded, and demo areas that repeat text you typed are left out.

It does not collect what you type, form values, file paths or free text, apart from the waitlist or booking link above. If your browser sends a Do Not Track signal, nothing is sent at all. Session replays are deleted after 30 days; other events are kept for up to 7 years, the retention period of our PostHog plan.

PostHog is also configured for the dashboard (app.caveman.so) but is not switched on there. If we switch it on, it will be cookieless, will not capture interactions automatically or record sessions, will identify events by your user ID, Workspace ID and plan, and will be off for Enterprise Workspaces. We will update this policy and the Privacy Policy before we do.

## No advertising or cross-site tracking

We do not use advertising cookies, tracking pixels, fingerprinting or any other technology to follow you across websites. We do not let advertising networks collect data on the Website or in the dashboard.

## Legal basis

EU and UK law (the ePrivacy Directive and the UK Privacy and Electronic Communications Regulations) require consent before a site stores or reads information on your device, unless that storage is strictly necessary to provide a service you have asked for.

- The dashboard cookies listed above are strictly necessary for signing in and keeping your account secure, so they do not need consent.
- The local and session storage values on the Website and in the dashboard remember choices you made or support the page you are viewing. They are not used to track you, and the Website's values never leave your device. We rely on the same exemption for them.
- On the Website, Cal.com's script loads only when you interact with a booking button.
- Product analytics on the Website stores nothing on your device. It sends information your browser provides with every page load, such as screen size, language and browser type. Your browser's Do Not Track setting turns it off.

If we ever want to use a cookie or similar technology that is not strictly necessary, we will ask for your consent first where the law requires it, and you will be able to withdraw that consent at any time.

Where these technologies involve personal data, the [Privacy Policy](/privacy) explains our legal bases and your rights.

## How to control and clear cookies and storage

You can see, block and delete cookies, local storage and session storage in your browser settings. Most browsers let you clear data for a single site, block all cookies, or block third-party cookies only. Your browser's help pages explain how.

- Clearing the Website's local storage resets the banner, the homepage header, the cached star counts and the homepage demo. Nothing else changes.
- Blocking or deleting the dashboard's cookies signs you out, and you will not be able to sign in while they are blocked.
- Clearing the dashboard's browser storage resets your interface preferences.

The Website sets no cookies and its analytics stores nothing on your device, so we do not show a cookie consent banner. Your browser's Do Not Track signal turns analytics off. Global Privacy Control is honoured as an opt-out of sale and sharing, as the Privacy Policy describes, but it does not turn the analytics off; Do Not Track does.

## Changes to this policy

We will update this policy when we change the cookies or similar technologies we use. The version tag at the top of this page shows which version you are reading. If we add a technology that needs your consent, we will ask for it before we use it.

## Contact

Questions about this policy go to Caveman Labs, Inc. at [contact@caveman.so](mailto:contact@caveman.so).
