LinkMesh

Search docs, blog and changelog

ENDE

Cookies & tracking

Cookies & Tracking

Plain-English summary of what linkmesh.io stores in your browser. There isn't much.

Last reviewed: 2026-09-23.

What we set

linkmesh-consent-v2 — localStorage, always

A single localStorage entry storing your cookie-banner decision (granted or denied). Not a cookie — never sent over the network. Stays in your browser until you clear site data. Clearing it re-shows the banner on your next visit.

linkmesh-consent-record — localStorage, after you choose

A second localStorage entry recording when you chose, which version of this page you were shown, and whether the choice came from the banner, from withdrawing, or from your browser's Global Privacy Control signal. We keep it so we can show that consent was actually given, as data-protection law requires. It contains no identifier and is never sent over the network — it stays in your browser, and you can delete it with your site data.

Global Privacy Control — we answer it for you

If your browser sends the Global Privacy Control signal, we treat it as a Decline and the banner never appears — you have already told us, so we do not ask again. The signal also overrides an earlier Accept, on the grounds that it is the more recent instruction. While it is switched on, accepting is not possible; switch it off if you want to change that.

Google Analytics cookies — only after Accept

If you click Accept on the banner, Google's tag sets the following first-party cookies:

CookiePurposeExpiry
_gaDistinguishes browser sessions for Analytics2 years
_ga_F97CQD8TV5GA4 container session state2 years

These cookies are first-party (set on linkmesh.io itself), not third-party trackers. They contain a randomly-generated client ID, not your identity.

If you click Decline, none of these cookies are set and the Google Analytics tag stays under Consent Mode v2 in denied state: no analytics event is sent to Google at all — not page views, not downloads, not install clicks. The only measurement that continues is PostHog's cookieless count, described below.

PostHog storage — cookies only after Accept

We also use PostHog (EU Cloud, hosted in the EU) for product analytics and session replay. If you click Accept, PostHog sets the following first-party cookie. If you click Decline, PostHog may use cookieless aggregate measurement and does not set this cookie:

CookiePurposeExpiry
ph_<project>_posthogStores a randomly-generated device ID and session state for PostHog analytics1 year

First-party (set on linkmesh.io), containing a random device ID, not your identity. Until you choose, PostHog stores nothing in your browser — no cookie, no local or session storage. After Decline, the same is true.

What that cookieless measurement counts, before you choose and after a Decline: page views, and the actions you deliberately take — starting an install, copying the install command, downloading a binary or a document, submitting a form, and following a link to our documentation. Each is counted with the page address, the language and the button's label, and nothing else: no cookie, no stored identifier, no profile, and no campaign, referrer or first-touch information, which is added only after you accept. We also switch off PostHog's location lookup, so no country or city is derived from your IP address until you do. PostHog counts visitors with a daily server-side hash it deletes each day, so the same person is not recognisable from one day to the next.

Session replay — only after Accept

Accepting also turns on PostHog session replay: a reconstruction of your visit to this website — pages viewed, clicks, scrolling and mouse movement — that we watch back to find confusing or broken parts of the site. It is not a video of your screen, and it cannot see your camera, microphone, other tabs or other windows.

All form inputs are masked in the browser before the recording is sent, so a replay never contains what you typed. Replays live in PostHog's EU Cloud and are deleted after 30 days; visits shorter than two seconds are not recorded at all.

Nothing is recorded before you accept. Declining — or simply not answering the banner — means no replay is ever created, and if you accept and later decline, recording stops immediately.

What we don't set

  • No advertising or remarketing signals. ad_storage, ad_user_data, and ad_personalization are permanently denied in our Google Tag configuration — they are not conditional on the banner, they are off.
  • No third-party social trackers (no Facebook Pixel, LinkedIn Insight Tag, Twitter / X pixel, TikTok pixel).
  • No chat-widget tools and no third-party session-recording tools (no Hotjar, FullStory, Drift, Intercom, etc.). Session replay is done by PostHog only, after you accept — see above.
  • No A/B-testing platforms.

Change or revoke your consent

Withdrawing is as easy as giving consent: one click, no reload. It stops analytics and session replay immediately and brings the banner back so you can choose again.

If scripts are blocked in your browser, you can also delete the linkmesh-consent-v2 entry under Application → Local Storage → linkmesh.io in your developer tools and reload, or use your browser's standard cookie settings to block analytics cookies — the site continues to work either way.

Related

  • Privacy Policy — what we do with the data we collect
  • Trust — how the LinkMesh product handles telemetry on your own infrastructure (no cookies involved — it's a server binary)
  • Terms of Use

Campaign attribution after consent

After you accept analytics, linkmesh-first-touch stores the entry-page path, referring hostname and campaign parameters in localStorage. It expires from use after 90 days. linkmesh-entry stores the current tab’s entry information in sessionStorage until that browsing session ends. These entries help compare qualified enquiries by landing page; they do not contain your form responses. Withdrawing consent removes both entries.