Cookie Policy

Last updated: August 4, 2026

1. Introduction

This Cookie Policy explains how ExpenseMate ("we", "us", or "our") uses cookies and similar technologies — including your browser's local storage and session storage — on our marketing website at expensemate.app and in our web app at app.expensemate.app. It should be read alongside our Privacy Policy, which explains how we use personal information.

Nothing non-essential runs until you say so. On your first visit to either one you are asked, and analytics is loaded only if you accept. You can change your answer at any time — see section 7. Continuing to browse is not taken as consent.

The website and the web app are separate origins with separate storage, so your choice does not carry between them. Accepting analytics on expensemate.app does not accept it on app.expensemate.app, and you will be asked again there. That is deliberate: neither can read the other's answer.

We do not sell cookie data and we do not use it for advertising. The analytics providers listed in section 5 process it on our behalf and on our instructions.

2. What Are Cookies?

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to the website owners. Cookies can be "persistent" or "session" cookies. Persistent cookies remain on your device for a set period specified in the cookie, while session cookies are deleted when you close your browser.

3. Types of Cookies We Use

We use the following categories, across the website and the web app:

  • Essential: necessary for the site or the app to work at all. They cover security, network management, keeping you signed in, remembering the invite you arrived with, and remembering your cookie choice itself. You may block them through your browser settings, but the Services will not work properly without them.
  • Preferences (functional): remember a choice you made about how the product looks or behaves. In the web app this is your Light / Dark / System appearance setting. It is stored on your device, is never sent to us as an analytics event, and only affects what you see.
  • Analytics: let us count visits, understand product funnels, and see which features are used, so we can improve the product. Google Analytics and PostHog require your consent under the GDPR, and are only ever loaded after you give it.

We also use Vercel Analytics on the marketing website, a cookieless analytics tool that does not set any cookies or store personal identifiers. It collects only aggregated, anonymised data such as page views, referrer, device type, and country (derived transiently from your IP address, which is never stored). Because Vercel Analytics uses no cookies and retains no personal data, it does not require your consent and is always active.

Error monitoring is separate, and is not an analytics category. When the web app hits an error it sends a report to Sentry so we can fix it. This sets no cookie and stores nothing on your device, and it is not part of the analytics choice — it is how we find out that something is broken for someone who will never write to us about it. This is why the web app's banner tells you that errors are always reported. The reports carry no name, email address, expense description or amount; see our Privacy Policy.

4. Specific Cookies We Use

Below is a list of the main cookies and storage keys that we use and what we use them for. Where the row applies to the web app rather than the marketing website, it says so.

Cookie NamePurposeDurationType
cookieConsentWebsite and web app. Stores your consent choice — essential only, or analytics accepted — in browser localStorage, not as a cookie. Each origin keeps its ownUntil you clear site dataEssential (local storage)
cookieConsentTimestampWebsite and web app. Records when you made that choice, so we know how old it isUntil you clear site dataEssential (local storage)
colorSchemePreferenceWeb app. Remembers whether you chose System, Light or Dark appearanceUntil you clear site dataPreferences (local storage)
expensemate.pending-inviteWeb app. Holds the group ID from an invite link so that the invite survives signing in or signing up. Cleared once you joinUntil you close the browser tabEssential (session storage)
firebase:authUser:…Web app. Keeps you signed in, set by Firebase Authentication. If you untick "Keep me signed in" it moves to session storage instead, so the session ends when the tab is closedUntil you sign out or clear site data, or until the tab closesEssential (local or session storage)
_gaUsed by Google Analytics to distinguish users (only set with analytics consent)2 yearsAnalytics
_ga_[ID]Used by Google Analytics to persist session state (only set with analytics consent)2 yearsAnalytics
ph_*Website and web app. Used by PostHog to understand funnels and session continuity (only ever set after you accept analytics on that origin)According to PostHog project settingsAnalytics
Vercel AnalyticsCookieless analytics, collects aggregated page view data with no personal identifiersNo cookie setCookieless / Always active

5. Third-Party Analytics

We use the following third-party analytics services:

  • Google Analytics (GA4), cookie-based analytics active only with your consent. Google's privacy policy applies: policies.google.com/privacy
  • PostHog, product analytics on both the marketing website and the web app, active only with your consent on that origin. Session replay is optional and off by default on the marketing website, and is switched off entirely in the web app. PostHog's privacy policy applies: posthog.com/privacy
  • Vercel Analytics, on the marketing website only. Cookieless, privacy-first analytics that collects only aggregated, anonymised data. No cookies are set and no personal data is stored. Vercel's privacy policy applies: vercel.com/legal/privacy-policy

The web app also sends error reports to Sentry. It is not an analytics tool, it sets no cookie and stores nothing on your device, so it does not appear in the table above — see section 3 and our Privacy Policy. Sentry's privacy policy applies: sentry.io/privacy

6. Managing Cookies

Most web browsers allow you to manage your cookie preferences. You can set your browser to refuse cookies, or to alert you when cookies are being sent. The methods for doing so vary from browser to browser, and from version to version. Note that browser cookie settings do not govern local or session storage, which is what the web app mainly uses: to clear that, clear site data for app.expensemate.app in your browser's settings. You can however obtain up-to-date information about blocking and deleting cookies via these links:

Please note that restricting cookies may impact the functionality of our website. For example, you may not be able to access certain areas or features of the site, or your user experience may be diminished.

7. Your Consent

When you first visit either the marketing website or the web app, you are presented with a banner that lets you accept or decline non-essential cookies and analytics. Nothing non-essential runs until you answer it, and — because the two are separate origins — you are asked once on each.

You can change your mind at any time:

  • On this website: the "Cookie Settings" link in the footer.
  • In the web app: Settings → Privacy, where analytics can be turned off and back on. The banner itself only reappears if the question has never been answered on that browser, so Settings is the route once you have answered it.

8. Changes to this Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in technology, regulation, or our business practices. Any changes will be posted on this page with an updated revision date. Please check back periodically to stay informed about our use of cookies.

9. Contact Us

If you have any questions or concerns about our use of cookies, please contact us at:

Email: contact@tkmedia.lu