Cookies

Version 1.1 · Last updated 29 September 2026

Analytics on this website is off until you say otherwise. If you refuse, no analytics code is downloaded at all — not loaded and disabled, not present.

Who sets these

HeraIQ is a trading name of HERA INTELLIGENCE LTD, a company registered in England and Wales (company number 17459930).

Registered office: as shown on the Companies House register

ICO registration reference: ZC250032

Contact: hello@heraiq.io

What we do with personal information more broadly — why we hold it, who receives it, how long we keep it and how to use your rights — is in the privacy notice.

Where analytics does not run

Only these public pages are measured by the analytics this banner asks about. The signed-in product — everything a care manager or carer uses — loads no third-party analytics, no session recording and no third-party tracking script of any kind, whatever you choose here. That is about measurement, not about everything the product sends: using Hera, or speaking to it, sends what you write or say to OpenAI, and the sub-processor list names every company involved.

That is not a policy we ask ourselves to remember. Those pages carry service-user names, medication and safeguarding notes about people who are not our users and have agreed to nothing, so third-party analytics is allowed by an explicit list of public page addresses. A page that is not on the list gets no third-party script, including a page nobody has written yet.

Needed either way

These keep you signed in, remember an answer you have already given, or make one page work. None of them measures you, and none goes to anyone else.

Cookies and storage we set whatever you choose
NameSet byWhat it is forHow long it lastsWhen it is set
hera-consentHeraIQRecords whether you accepted or refused analytics, so you are not asked again on every page. It holds your answer, which version of this notice you answered, and the date.6 months, then we ask again.The moment you answer the banner — including when you refuse, which is why refusing still stores one thing.
hera-prelaunchHeraIQWhile the product is in private preview, records that you hold an access link, so you are not challenged on every page. Nothing to do with analytics.30 days.When you open a link carrying a valid preview key.
hera-roleHeraIQRemembers which portal your account belongs to, so a link into the other one can be sent to the right place. It is a hint: it never grants access by itself.Until you close the browser. It is given no expiry date.When you sign in.
hera-browsingHeraIQRecords that you chose to carry on reading the public website while signed in, so you are not offered your portal again on every page.Until you close the browser.When you choose to carry on to the website after signing in.
sb-cmlaxvpklzfxmseeeznf-auth-token, the numbered parts of it (…-auth-token.0, …-auth-token.1), and …-auth-token-code-verifierHeraIQ, through SupabaseKeeps you signed in. The value is split across numbered cookies when it is too long for one. The code-verifier is a one-time value that proves a password reset or an email confirmation was opened in the same browser that asked for it.400 days for the sign-in cookie, the default in the Supabase library we use. Signing out removes it. The code-verifier is deleted the moment you use the link; if you never use it, it expires on the same 400-day default.When you sign in, and when you ask for a password reset or confirm your email address.
heraiq-intro (sessionStorage, not a cookie)HeraIQRecords that the home page's opening animation has played, so it plays once rather than every time you come back to that page.Until you close the tab.The first time you open the home page in a tab.
Keys beginning heraiq. or heraiq: (localStorage and sessionStorage, not cookies)HeraIQKeeps the signed-in product usable as you move between pages: your session details, the rota board you last opened, and your Hera conversation.Removed when you sign out, apart from one marker that records that you signed out on purpose. The sessionStorage ones also go when you close the tab.Only inside the signed-in product.

Only if you accept

PostHog is our analytics provider, and your data is stored on its servers in the European Union, in Frankfurt, Germany. PostHog, Inc. is a US company and can reach that data from outside the EU, under the EU-US Data Privacy Framework with its UK Extension and standard contractual clauses. PostHog counts the pages you read on this public website, and three things you can do here: clicking through to sign up, sending the contact form, and joining the waiting list. With each of those, the IP address and browser details your request carries reach PostHog as well.

It does not record your session, does not track clicks automatically, and collects nothing you type. The one click it does record is a sign-up button: we store which button it was and the words written on it. Care records are stored separately, in the United Kingdom — see the security page.

Cookies and storage set only after you accept
NameSet byWhat it is forHow long it lastsWhen it is set
ph_<project key>_posthogPostHog, which stores the data in the EU (Frankfurt, Germany)Gives your browser a random identifier and a session id, so that ten page views can be told apart from one person reading ten pages.365 days, or until you use Cookie settings below.Only if you accept. On this website's own address, not across every subdomain — we switch PostHog's default off.
ph_<project key>_posthog (localStorage, not a cookie)PostHogHolds the fuller version of the same record: the identifier, the current session, and the page you arrived from. PostHog stores in both places by default.Until you use Cookie settings below, or clear your browser's storage.Only if you accept.

Change your mind

This used to say "delete the cookie in your browser settings", which asked you to do our work and left PostHog's own cookie and storage behind anyway. Use this instead. It reopens the banner with your current answer shown, and it is in the footer of every page.

Choosing Reject stops analytics on this browser and deletes PostHog's cookie and the storage it keeps. If it was running on the page you are reading, we load that page again, because a script already on a page cannot be taken off it any other way.