What we collect without a banner prompt
A first-party telemetry beacon records page views, interactions, engagement, and operational page signals for human visitors: the page path, a referrer reduced to its site and page (no query string), UTM parameters, viewport size, browser language and time zone, a random per-session identifier kept in session storage, and — when the browser reports them — field LCP, CLS, INP, and TTFB. Our edge may add a coarse location and a corporate-network hint derived from the IP address. Our servers also derive a daily hash from the IP address and browser user agent to count unique visitors; it rotates each UTC day. These signals go to an internal operational channel so the founding team can see interest and real-user performance. This beacon is not gated by the cookie notice and is not a Chrome UX Report. Choosing “Decline” stops optional visitor identification below; it does not stop this first-party beacon. Automation and known bots are excluded. To ask that operational logs be deleted, email privacy@valty.ai.
What the cookie banner controls
The small notice offers “Accept all” or “Decline.” Necessary cookies keep the site working and secure: they remember your cookie choice, support the lead form, and provide basic anti-abuse and rate-limiting. If you choose “Accept all,” third-party visitor identification (currently Apollo) may load. If you decline, Apollo stays off and stops capturing further events. Closing the notice or scrolling past it only hides it for this browser tab; neither action grants permission or changes a previous choice. Reopen it from “Privacy choices” in the footer. A Global Privacy Control browser signal keeps Apollo off even if you previously allowed identification. PostHog is not affected by this choice: it receives our own first-party measurement from our servers, never from your browser. Your choice is versioned and stored for up to 180 days, in both your browser storage and a first-party cookie so the same choice applies even if one storage mechanism is blocked; it is not remembered forever regardless of age. You can reopen your choice at any time from “Privacy choices” in the footer, and decline after a previous accept. Withdrawing consent after Apollo has already loaded triggers a one-time page reload so no previously loaded tracking code keeps running. Clearing this site’s storage, or letting your 180-day choice expire, brings the banner back on your next visit.
Third parties
With consent, we may use Apollo for website-visitor identification. Apollo shares identifiers with its provider LiveIntent, including a visitor identifier and hashed email addresses; that data is not anonymous. PostHog processes our first-party site measurement and is sent from our servers, so it loads no script in your browser and builds no profile of you. Our site is served by Google Cloud Platform (Cloud Run) behind Google’s global HTTPS load balancer, which may set essential cookies/headers for security and load balancing. We do not sell your personal information. Where these providers process personal data on our behalf, they do so as subprocessors under our data agreements. See the Security page for the current subprocessor list.
Do Not Track and regional rights
Choosing “Decline”, letting your choice expire, or sending Global Privacy Control keeps optional visitor identification off. It does not stop the first-party telemetry beacon described above. Depending on where you are (for example, under the GDPR or similar laws), you may have rights to access, correct, or delete personal data we hold. Contact us to exercise those rights, and see the Privacy Policy for details on the legal bases we rely on.
Contact
Questions about this policy or your data can be sent to hello@valty.ai, or to security@valty.ai for security-related questions. This policy may be updated as our tooling changes; the version in effect when you visit governs your choice.