Cookie and Analytics Notice
Last updated September 7, 2026·Version 2.1
1. What This Notice Covers
This notice explains what Samva stores in your browser, what it measures on the Samva website and
in the Samva dashboard, and how to change what you allow. It covers cookies and equivalent browser
storage, including localStorage and sessionStorage.
Email engagement tracking is a different subject with a different controller. It is described in section 6 and in the Privacy Policy.
2. Strictly Necessary Technologies
Samva uses cookies and equivalent storage for authentication, session continuity, security, bot and abuse protection, routing, and interface preferences such as your theme. These cannot be turned off without breaking sign-in or core functionality, and they are not used to profile you.
Your cookie choice is itself stored in this category, under the key
samva:analytics-preference. It is stored so the banner does not have to ask again.
3. How The Site Is Measured Before You Choose
Samva measures the public website by default, without cookies and without any identifier stored in your browser.
Two processors receive that measurement. Samva sends PostHog a page view containing the page address
with query strings and fragments removed, the referring site, browser and device characteristics,
and campaign parameters such as utm_source. PostHog groups those events using a daily identifier
computed on its servers from a rotating secret. Samva cannot reverse that identifier, cannot
recognize you across days, and stores nothing in your browser to do it.
Google Analytics receives the same page views and the same interaction events. Its tag runs with every storage permission denied, so it writes no cookie and reads no identifier from your browser. The requests it sends Google carry the same page address, referring site, and browser characteristics, marked as having no permission to use storage, and Google uses them to estimate how many people visited rather than to recognize you.
Nothing in this mode identifies you, links to a Samva account, or records what you do on a page. Session replay is off.
4. What Changes When You Accept
Accepting analytics cookies adds two things.
A first-party identifier. PostHog stores an identifier and related measurement state in this
browser under keys beginning with ph_, and Google Analytics stores its own in the _ga and
_ga_ cookies, so a return visit is recognized as the same visit rather than a new one. This is
used to understand which pages and campaigns bring people back, not to advertise to you and not to
build a profile with anyone else.
Your single answer grants Google its advertising storage permissions alongside its analytics one, so the choice covers everything Google measures rather than asking you again later. Samva connects no advertising product to this measurement: Google Signals and ad-personalization signals are turned off in the tag, and no advertising or remarketing audience is built from your visit.
Session replay on the public website. PostHog records a reconstruction of your visit to marketing and documentation pages: the pages you open, where you click, how you scroll, and how the page changed as you used it. Text you type into any field is masked before it leaves your browser, network request and response bodies are not recorded, and console output is not recorded. Masking is a strong control but not a perfect one, so do not enter payment card numbers, passwords, health information, or other sensitive information into a field that does not ask for it.
Session replay does not run in the Samva dashboard or the mailbox, and it does not run on sign-in and sign-up pages.
5. Signed-In Measurement
Being signed in does not by itself connect your Samva account to analytics. Samva links product usage to a user account only under a separate product-analytics permission held in your account, and only ever using an opaque account identifier, never your email address or name. Where that permission is off, dashboard activity is not attributed to you as a person.
The Samva dashboard and mailbox do not send automatic page views and do not start session replay. Google Analytics measures the public website only: it receives nothing from the dashboard or the mailbox, and it is never told who you are.
6. Email Engagement Tracking
Samva may process open and click events for messages its customers send, including timestamps, IP addresses, user agents, clicked URLs, and link metadata, when engagement tracking is enabled. The customer organization controls that setting and is the party responsible for notices to recipients. A recipient's unsubscribe or suppression record is separate from any analytics preference.
7. Your Choices
The banner offers three actions. Accept all turns on analytics cookies and session replay. Reject all leaves them off; the cookieless measurement in section 3 continues, because it stores nothing in your browser. Manage cookies lets you set the analytics category directly.
You can reopen the panel at any time from the Cookie preferences link in the site footer or from Privacy in your dashboard profile settings. Withdrawing consent stops session replay immediately, discards the recording still buffered in your browser, clears the stored PostHog identifier, deletes the Google Analytics cookies from this browser, and returns both processors to the cookieless measurement in section 3. It does not undo processing already completed, and it does not remove data already held.
Your choice is stored per browser and per device. Clearing site data clears it, and the banner asks again.
Blocking all cookies and storage in your browser settings is also honored: Samva falls back to the cookieless mode and the product continues to work.
8. Who Processes This
PostHog, Inc. processes website analytics and session replay on Arya Labs' behalf, on infrastructure in the United States, under its own contractual and privacy terms. Google LLC processes website analytics on Arya Labs' behalf through Google Analytics, under its own contractual and privacy terms, on infrastructure whose location Google determines. The complete provider list is at /legal/subprocessors.
9. Contact
Privacy questions: privacy@samva.dev
Arya Labs, Inc.
1111B S Governors Ave #29161
Dover, DE 19904
Portions of this notice are adapted from the Basecamp open-source policies, used under CC BY 4.0.