Updated Sep 26, 2026

Cookie notice

Cactus keeps a few small things in your browser: to keep you signed in, remember your theme, keep a visitor's questions together and see how Cactus is used. Each one is below, with what it holds and how long it lasts.

The short version

  • No advertising cookies, and nothing Cactus keeps in your browser is shared for advertising.

  • The only cookie that is not Cactus's own is PostHog's, which we use to see how Cactus is used.

  • Cactus Messenger, on your own site, sets no cookies. It keeps what it needs in the browser's storage, and keeps no visitor id or conversations there when the visitor's browser asks not to be tracked.

On heycactus.ai and every Help Center

CookieLastsWhat it holds
Theme1 yearCalled cactus-theme. Light or dark, once you pick one. Each address keeps its own.
Visitor1 yearCalled cactus_visitor, on a Help Center only. A random id, set the first time a visitor asks a question or asks for a person, so their questions and the answers stay together in that browser.
Signed link30 daysCalled cactus_end_user, on a Help Center only. Set when one of your customers arrives through a link your own product signed, so their conversations follow them to any device.
Analytics1 yearPostHog's, called ph_ then our PostHog project key then _posthog. A random id for the browser and the current visit. Every address under heycactus.ai shares one; a Help Center on your own domain sets its own, for that domain and every address under it.

In the app

The app, at app.heycactus.ai, sets these as well as the theme and analytics cookies above.

CookieLastsWhat it holds
Sign-in7 daysCalled __Secure-better-auth.session_token. Keeps you signed in. Each day you use the app, its seven days start again.
Session copy5 minutesCalled __Secure-better-auth.session_data. A signed copy of your session, so the app need not look you up on every page.
Signing in5 minutesCalled __Secure-better-auth.state. Set while Google or GitHub signs you in, to check that the answer comes back to the browser that asked.
Connecting10 minutesCalled cactus_slack_oauth_state, cactus_discord_oauth_state or intercom_oauth. Set while you connect Slack, Discord or Intercom, for the same check, and deleted when you come back.

In the browser's storage

Some things are kept in the browser's storage rather than in a cookie. Local storage stays until it is cleared; session storage goes when the tab closes.

  • PostHog keeps a copy of its id in local storage, beside its cookie, and a note of the open tab in session storage.

  • Cactus Messenger, on your site and on ours, keeps in local storage a random visitor id, the visitor's conversations, the email address they left if they asked for a person, their unread count, and whether they put the Cactus dot away. Every name starts with cactus_messenger_ or cactus-.

  • The Messenger notes in session storage what it has already shown in the tab, such as its greeting, so it does not show it twice.

  • When the visitor's browser sends Global Privacy Control or Do Not Track, the Messenger keeps no visitor id and no conversations in local storage: each visit starts with a new id and no past conversations.

What PostHog records

PostHog records which pages are opened, what is pressed, the errors a page hits, and a recording of each visit to heycactus.ai, the app and Help Centers. The privacy page says what else it receives and how long it is kept.

Your choices

Your browser's settings can delete or block cookies and storage, for every site or for ours alone. The app needs its sign-in cookies, so blocking them signs you out. Everything else works without them, though a Help Center then forgets a visitor's earlier questions, and the theme goes back to its default.

Contact

When Cactus starts or stops keeping something in your browser, this page changes with it, and so does its date.

Questions go to hello@heycactus.ai. We reply within two business days.


This page is a working draft. A lawyer has not reviewed it yet, and its words may change when one does. Questions about it go to hello@heycactus.ai.