Cookie Policy

Senest opdateret 8. august 2026 - Version 2.1

Dette dokument findes ikke på dit sprog. Den engelske version vises, og det er den, der er juridisk bindende.

This policy lists everything wallticker stores on your device, what each item is for, and how long it lasts. wallticker is operated by Luwall AB (org. nr 559359-5993), Sweden.

1. What Are Cookies

Cookies are small text files a website stores in your browser and sends back on later requests. Websites can also store data in your browser without cookies, using local storage and session storage. This policy covers both.

2. How We Use Them

Most of what we store is there to make the Service work: to keep you signed in, remember your language and the currency you asked to see prices in, protect against cross-site request forgery, and remember display preferences such as light or dark mode.

One thing is not necessary: product analytics, which counts how features are used and collects error reports so we can improve wallticker. We ask for it in the cookie banner, nothing is stored for it until you say yes, and you can change your answer at any time under Cookie settings. We use no advertising cookies and take part in no cross-site tracking - see "Legal basis" below.

3. Cookies We Use

All of the cookies below are set on our own domain. Every one of them except the analytics cookie is strictly necessary.

  • sb-*-auth-token (and numbered continuations such as sb-*-auth-token.0) - stores your authentication session after you sign in. The continuations are used when the session token exceeds the browser's per-cookie size limit. Lifetime: the session, refreshed while you stay active.
  • sb-*-auth-token-code-verifier - a one-time value that secures the sign-in exchange (PKCE) when you sign in with Google or GitHub. Set when the sign-in starts and cleared as soon as it completes. Lifetime: minutes.
  • NEXT_LOCALE - remembers the language you chose with the language switcher. Lifetime: session.
  • wallticker.currency - remembers whether you want prices shown in euro or Swedish kronor, so you are not quoted in the wrong currency on every visit. Set only when you choose a currency yourself. Lifetime: 1 year.
  • wallticker.cookie-consent - remembers your answer to the cookie consent banner: which version of the choices you answered, whether you allowed analytics, and when. Set only when you make a choice in the banner or under Cookie settings. Lifetime: 180 days, after which we ask again.
  • ph_* (in practice ph_phc_....._posthog) - set by PostHog, our analytics provider, to recognise this browser across visits so that feature usage is counted once rather than many times. It holds a random identifier while you are signed out, and your account identifier once you sign in - never your name or email address. Written only after you allow analytics, and deleted from this browser the moment you withdraw. Lifetime: 1 year.
  • wt-deletion-gate - briefly caches whether your account is scheduled for deletion, so we do not query the database on every page load. Contains your account identifier and a single yes/no flag. HTTP-only. Lifetime: 60 seconds.
  • gcal_oauth_state - a one-time random value that protects the Google Calendar connection flow against cross-site request forgery. Set only when you start connecting a calendar, and deleted immediately afterwards. HTTP-only. Lifetime: 10 minutes.

If you purchase a paid plan, our payment provider Stripe may set its own cookies on its checkout pages, governed by Stripe's cookie policy.

4. Local and Session Storage

We also keep a small amount of interface state on your device. The entries listed below are never sent to our servers and contain no personal data - only how you like the app arranged. They stay on the device you set them on. Analytics storage works differently and is described after the list.

  • wallticker.period-range, wallticker.list-mode, wallticker.view-settings - which period and view the home page opens on.
  • wallticker.reports-view, wallticker.reports-table-config, wallticker.report-export-config - your last-used report and export layout.
  • wallticker.default-preset-hidden - remembers that you removed the built-in Default export preset on this device.
  • wallticker.projects-sections - which sections of the clients, projects and tags page you left open.
  • wallticker.entry-sort - your chosen sort order for the current session.
  • wallticker.runaway-dismissed - remembers that you dismissed a forgotten-timer prompt, for the current session only.
  • theme - your light or dark mode choice.

Analytics is the exception to the paragraph above. If you allow it, PostHog stores its identifier in local storage under the same ph_* name as the cookie in section 3, so it survives if cookies are cleared, and it may use session storage the same way for the current visit. That identifier is sent to PostHog - that is what it is for. Withdrawing consent under Cookie settings removes every ph_* entry from cookies, local storage and session storage alike.

6. Third-Party Cookies

Our analytics provider PostHog sets no cookie on its own domain - the ph_* cookie in section 3 is set on ours - but PostHog does receive what it collects, which makes it a third-party recipient, and its script runs only after you allow analytics. We set no advertising cookies and take part in no cross-site tracking or advertising networks. If you sign in with Google or GitHub, or connect a Google Calendar, those providers may set cookies on their own domains during sign-in, governed by their own policies. Stripe does the same on its checkout pages if you buy a paid plan.

7. Managing Cookies

To turn analytics off, use Cookie settings - linked in the site footer and in your account settings. It withdraws your consent and deletes the ph_* identifiers from this browser straight away, which is simpler than hunting through browser settings. You can also delete or block cookies in your browser, and clear local storage the same way. Be aware that everything else we set is strictly necessary, so blocking it will break the Service: in particular, blocking the authentication cookie will prevent you from signing in.

8. Changes to This Policy

We update this policy whenever we add, remove, or change what we store on your device. The version and date at the top of this page always reflect the current version.