Cookies, local storage and analytics
Last updated October 2, 2026
Essential storage
Roost uses signed session and request-security cookies to keep you signed in and protect actions, plus an onboarding session mechanism to resume setup. Opening a Roost invite link stores its code in a 30-day cookie so signup can credit the person who invited you. Browser or app storage can keep onboarding progress and interface choices. Removing essential storage can sign you out or interrupt setup. Server-side sessions expire after 30 days unless renewed.
Product analytics
When configured, PostHog records page views and selected feature/onboarding events, with internal user or browser identifiers and device/browser metadata. The browser SDK uses local storage. Autocapture and session recording are disabled in the app configuration. Roost does not intentionally include private messages or photos in analytics events. Optional analytics can begin before sign-in; the account control is in Settings > Product analytics. Turning it off prevents future configured product-event capture; it does not erase prior provider records.
Third-party connections
When an interactive Google map loads, the browser connects to Google, which receives network/device information and map activity under its own policy. Crash diagnostics and hosting security logs are separate from product analytics. Roost does not use advertising cookies or cross-company advertising tracking.
Browser signals and requests
Roost does not currently change its analytics behavior in response to the legacy Do Not Track browser signal. We do not sell personal information or share it for cross-context behavioral advertising, so there is no such sale or sharing to opt out of. Browser storage controls can clear identifiers, but may also clear preferences. Contact info@roostmate.app about analytics data or other privacy choices. See /privacy for the full policy.