Legal

Cookie Policy.

Short version: two strictly necessary cookies (login and form security), plus one that remembers whether you accepted analytics. Analytics is opt-in and runs on EU servers; decline and nothing is loaded. No advertising, no third-party trackers, and we self-host our fonts. Last updated 5 August 2026.

1. What cookies we set

Three first-party cookies, none of which tracks you. Two are strictly necessary; the third only records whether you agreed to analytics.

The two session cookies are HttpOnly (scripts cannot read them), Secure (HTTPS only) and SameSite=Lax. They contain no personal data beyond what is needed to recognise your session. dbapps_analytics stores a single character — 1 or 0 — and is set whichever way you answer, so that we stop asking.

2. Analytics, only if you say yes

We use PostHog to see how the store is used — which pages people read, where they give up, whether a download finished. It runs on PostHog's EU servers (Frankfurt); your data does not leave the EU. PostHog is our processor under a data-processing agreement.

It is strictly opt-in. Until you press Accept, no PostHog script is loaded, no request reaches PostHog, and no analytics cookie is set. Press Decline and none of that ever happens — the store behaves exactly the same either way. If you accept, PostHog sets its own cookies (typically ph_*) to recognise a returning browser, and if you are signed in we tell it your account id — never your e-mail address or your name.

3. Third-party requests

No ad trackers, no social widgets, no external CDNs — we self-host our fonts, so your browser never calls a font CDN. The site runs on OVH servers in the EU. Exactly two things reach outside our server, and only when you trigger them: PostHog, if you accepted analytics above, and Paddle's secure checkout, which loads when you click Buy and sets its own cookies under its own policy.

4. Managing cookies and changing your mind

You can withdraw or give analytics consent at any time, as easily as you gave it:

Your browser also lets you view, block or delete cookies at any time (usually under Settings, then Privacy). Deleting our cookies simply logs you out and makes us ask about analytics again. Blocking dbapps_session will break login entirely; blocking dbapps_csrf will break form submissions.

5. Changes and contact

If we ever add a cookie, we will update this page and the date above before it ships. For how we handle personal data generally, see our Privacy Policy. Questions: contact@dbapps.co.