Cactus Cookie Notice

Review the cookies and browser storage Cactus uses, what they hold, how long they last, and what changes when you block them.

Cookies

Cactus uses cookies for themes, Help Center conversations, sign-in, analytics, and temporary service connections. It uses no advertising cookies, and nothing it keeps in your browser is shared for advertising. PostHog's cookie is the only one that isn't Cactus's own. Messenger sets no cookies; its browser storage is covered below.

Website and Help Centers

CookieLastsWhat it holds
Theme, cactus-theme1 yearYour light or dark theme. Each address keeps its own.
Visitor, cactus_visitor1 yearA random ID set when a visitor first asks a question or asks for a person. It keeps that visitor's questions and answers together in the browser.
Signed link, cactus_end_user30 daysSet when a customer arrives through a link your product signed. Their conversations follow them across devices.
Analytics, ph_[PostHog project key]_posthog1 yearA random browser ID and the current visit. Addresses under Cactus's site domain share one; a Help Center on your own domain keeps a separate one for that domain and its subdomains.

App

The app also sets the Theme and Analytics cookies listed above.

CookieLastsWhat it holds
Sign-in, __Secure-better-auth.session_token7 days, renewed when you use the appKeeps you signed in. Each day you use the app, its seven days start again.
Session copy, __Secure-better-auth.session_data5 minutesA signed copy of your session, so the app doesn't need to look it up on every page.
Signing in, __Secure-better-auth.state5 minutesChecks that a Google or GitHub sign-in response returns to the browser that started it.

Service connections

CookieLastsWhat it holds
Slack, cactus_slack_oauth10 minutesTemporary connection state and return details.
Discord, cactus_discord_oauth10 minutesTemporary connection state and return details.
PostHog, cactus_posthog_oauth10 minutesTemporary connection state and return details, including a PKCE verifier.
Intercom, cactus_intercom_oauth10 minutesTemporary connection state and return details.

These connection cookies use Secure, HttpOnly, and SameSite=Lax. Cactus deletes them when the browser returns from the connection flow.

Analytics

PostHog records which pages you open, what you press, page errors, and a recording of each visit to heycactus.ai, the app, and Help Centers. For what else it receives and how long it is kept, read the Privacy Policy.

Messenger storage

Messenger keeps a random visitor ID, conversations, an email address left when someone asks for a person, an unread count, and whether the visitor put the Cactus dot away in local storage. Local storage stays until it's cleared; session storage goes when the tab closes. Messenger uses session storage to remember what it has already shown in the tab, such as a greeting. When the browser sends Global Privacy Control or Do Not Track, Messenger keeps no visitor ID or conversations in local storage. Each visit starts with a new ID and no past conversations. Messenger storage names start with cactus_messenger_ or cactus-.

Browser choices

Your browser settings can delete or block cookies and storage for every site or for Cactus alone. Blocking the app's sign-in cookies signs you out. Without other cookies and storage, a Help Center forgets a visitor's earlier questions and the theme returns to its default.

For other personal-information practices, read the Privacy Policy.

Related pages