Cookie Policy

Last updated: August 19, 2026

What Are Cookies?

Cookies are small text files stored on your device when you visit a website. Some sites, including Kyvora, also use similar browser storage (like local storage) for related purposes. We use these technologies to make Kyvora work correctly, keep you signed in, and understand how our product is used so we can improve it.

Cookies and Storage We Use

Cookie / StoragePurposeTypeDuration
sb-*Supabase authentication session — keeps you logged inStrictly necessarySession / 1 hour
sb-auth-tokenStores your authentication token securelyStrictly necessarySession
kyvora_cookie_consent, kyvora_cookie_prefsRemembers your cookie preferences from the banner below (local storage, not a cookie)Strictly necessaryUntil cleared
ph_* (set by PostHog)Analytics — recognizes your browser across visits, including before you sign up, so page views and product-usage events can be grouped together. See "Analytics: PostHog" below.Performance & AnalyticsUp to 1 year
Sentry session/error storageError monitoring, used to diagnose technical issues, runs on every page load; masked session replay runs on a sample of pages but never on the signed-in dashboard. Not controlled by the cookie preferences banner. See "Error Monitoring: Sentry" below.Strictly necessary (platform reliability)Session

Strictly Necessary Cookies

The authentication and preference cookies/storage listed above are strictly necessary for Kyvora to function — they enable sign-in, session management, and remembering your cookie choice. You cannot opt out of strictly necessary cookies while using the Platform.

Analytics: PostHog

Kyvora uses PostHog, a third-party product analytics provider, across the Kyvora website and product — including public pages you can view before signing up (like this one), the demo-request form, and the signed-in dashboard used by customers and staff. This helps us understand how the site and product are used and prioritize what to build and fix next.

What PostHog receives from Kyvora:

  • Page views and standard technical data (such as browser/device type, IP-derived approximate location, and page URLs visited) for every visitor, signed in or not, unless you opt out using the cookie preferences banner
  • If you submit the “Request a demo” form before signing up, the information in that submission (e.g., company name, and whether you provided a phone number or message), associated with your IP address rather than a Kyvora account
  • Once you are signed in: your Kyvora internal account ID, your organization ID, and your role — not your name or email address — plus product usage events you generate while signed in (e.g., a campaign was created, a checkout was started) and their non-sensitive metadata

What PostHog does not receive:

  • Candidate names, phone numbers, email addresses, or message/screening content
  • Session recordings or screen replays (explicitly disabled in our configuration)
  • Automatic capture of what you click or the text on the page (explicitly disabled — only the specific product events and page views described above are ever sent)

Candidates who interact with Kyvora exclusively by SMS or email — the normal way a candidate experiences Kyvora — are never sent to PostHog and are never identified by it. PostHog collection is not limited to the authenticated dashboard: it also runs on Kyvora's public website and pre-signup forms, as described above, but it is never used to track or identify candidates.

Error Monitoring: Sentry

Kyvora uses Sentry, a third-party application monitoring provider, to detect, diagnose, and fix technical errors in the Platform. Sentry's error monitoring runs on every page load for every visitor and is separate from the PostHog analytics described above — it is used for platform reliability, not marketing or usage analytics, so it is not currently controlled by the “Performance & Analytics” toggle in the cookie preferences banner.

What Sentry collects:

  • Application error details, stack traces, and operational log context, including internal organization/user/conversation/campaign identifiers
  • A masked session replay of a small sample of sessions, and of sessions that encounter an error — text content and form inputs are masked by default so candidate and account details are not captured in the replay video. Session replay is never active on the signed-in dashboard (where candidate names, phone numbers, and message content are displayed); it only runs on Kyvora's public website and sign-in/account pages

Email addresses, phone numbers, and similar PII patterns are redacted from Sentry data before transmission where technically feasible. See our Subprocessors page for more detail on Sentry as a subprocessor.

Cookies We Do Not Use

  • We do not use advertising or retargeting cookies
  • We do not use social media tracking pixels
  • We do not share cookie or analytics data with data brokers
  • We do not sell cookie or analytics data

Managing Cookies

You can manage optional (analytics) cookies at any time using the “Manage preferences” link in the cookie banner, or by clearing your browser's local storage for this site. You can also manage cookies through your browser settings. Disabling the authentication cookies will prevent you from logging into Kyvora. For instructions on managing cookies in your browser, see your browser's help documentation.

Changes to Cookie Use

If Kyvora adds advertising, retargeting, or other cookie use beyond what is described in this policy, we will update this Cookie Policy and provide any consent or opt-out controls required by applicable law before using such technologies where required.

California CCPA Rights

California residents have the right to know what cookies and tracking technologies we use and to request deletion of information associated with those cookies. We use PostHog for product analytics across the Kyvora website and product, including before you sign up, as described above; we do not use advertising or cross-context behavioral advertising cookies, and we do not sell cookie or analytics data. To manage analytics cookies, use the cookie preferences banner. To request account data deletion, contact privacy@kyvoratech.com.

Do Not Track

Some browsers transmit Do Not Track (DNT) signals. Our site does not currently change its behavior based on DNT signals. You can still control analytics cookies directly using the cookie preferences banner described above.

Contact

Questions about our cookie use: privacy@kyvoratech.com

Kyvora Technologies LLC
San Francisco, CA 94114
United States