Cookie Policy
Last updated: June 18, 2026
This Cookie Policy explains the cookies, browser local storage, and similar technologies that Boardwalk uses on boardwalk.sh and the Boardwalk web app. It is part of our Privacy Policy, which explains the broader picture of how we handle data.
Boardwalk sets the cookies and storage needed to sign you in and run the app, plus optional product-analytics storage that we set only with your consent where consent is required. We do not set advertising, retargeting, or fingerprinting cookies.
1. Categories
- Strictly necessary.Without these the Service won't work. They handle authentication, sessions, CSRF protection, and routing.
- Functional. They remember basic preferences such as your theme and your cookie choice. We treat these as necessary for a usable experience.
- Analytics. Optional. They help us understand which features people use and where they get stuck. In the EU, EEA, UK, and Switzerland we do not set them until you accept on the cookie banner. If we cannot determine your region, we also ask before enabling analytics storage. Elsewhere they are on by default and you can opt out at any time. Until you opt in, analytics runs in a cookieless mode that sets no analytics storage on your device.
2. What we set
Strictly necessary
- Clerk authentication and session cookies. Used to keep you signed in and to authenticate requests to the Service. Lifetime: until sign-out or session expiry, with short-lived access tokens refreshed during an active session.
- Vercel platform cookies for routing, deployment protection, and abuse mitigation. Set by our hosting provider; lifetime controlled by Vercel.
Functional
theme(browser local storage): your light/dark theme preference. Persists until you clear it.bw_analytics_consent(cookie): records whether you accepted or rejected analytics, so we don't ask again. Scoped to our domain so one choice covers the marketing site and the app. Lifetime: up to 12 months, or until you change it.
Analytics (PostHog, set only with consent where required)
- PostHog distinct-ID and related cookies, used to recognize a browser across visits and deduplicate events. Set by the PostHog SDK after you accept (or, outside the EU/EEA/UK/Switzerland, on first load unless you opt out). If your region is unknown, we wait for your choice before enabling analytics storage. Until then, PostHog runs in cookieless mode and sets no storage. Lifetime: typically up to 12 months, configured by PostHog. We do not enable session recordings, and analytics never captures your run inputs, prompts, or outputs.
3. What we don't set
We don't run advertising trackers, retargeting pixels, social plug-ins, or third-party fingerprinting on Boardwalk. We don't sell personal information and we don't share it for cross-context behavioral advertising.
4. Your choices
You can change your analytics choice at any time using the "Cookie preferences" link in the site footer. We honor the Global Privacy Control (GPC) browser signal as a binding opt-out of analytics where applicable U.S. state law treats it that way. Most browsers also let you block or delete cookies and clear local storage; note that disabling strictly necessary cookies will break sign-in and most of the Service.
5. Updates
We may update this policy as our integrations change. Material changes will be posted here with a revised "Last updated" date.