This page lists every cookie and browser-storage key that Zavi Labs, Inc. sets on zaviagent.com, what each one is for, and how to change your choice. It is short because we use very little: what keeps you signed in, what remembers your settings, and two analytics tools you can switch off. We do not use advertising cookies, and we do not record your screen.
1. What we mean by “cookies”
A cookie is a small text file a website stores in your browser. Browsers also offer two other stores, local storage and session storage, which some of the tools below use instead of, or as well as, cookies. The law treats them the same way, and so does this page: “cookies” here means all three. Session storage is cleared when you close the tab; local storage and cookies persist until they expire or you clear them.
2. Necessary
Set without asking, because the site does not work without them. Each one stores something you did — a sign-in, a setting, a build you started — and none of them is used to recognise you across sessions for our own purposes. The one read by a third party is Cloudflare's bot check on public forms.
| Name | Provider | Type | Expiry | Purpose |
|---|---|---|---|---|
| sb-<project>-auth-token (and .0, .1 chunks) | Zavi / Supabase Auth | Cookie | Session, refreshed while you use Zavi | Keeps you signed in. |
| sb-<project>-auth-token-code-verifier | Zavi / Supabase Auth | Cookie | Minutes, during sign-in | Completes a sign-in securely (PKCE). |
| zavi_consent_v1 | Zavi | Cookie | 180 days | Stores your cookie choice so we do not ask again. |
| __epv_<run> | Zavi | Cookie | Session | Lets you open a preview of a site the engineer agent built for you. Only set when you open a preview. |
| zavi:dark | Zavi | Local storage | Until cleared | Remembers your light / dark theme choice. |
| zavi:*, zavi.*, zavi_* layout preferences | Zavi | Local storage | Until cleared | Remembers workspace layout you set: pane widths, column order, collapsed panels, dismissed notices, tool-detail view. |
| praxis.brain.view, brainTab_systemCore_collapsed | Zavi | Local storage | Until cleared | Remembers how you last viewed the company brain. |
| praxis_pending_build | Zavi | Local storage | Until sign-up completes | Carries the build you described on /start across the sign-up redirect, so you do not type it twice. |
| zavi.launch-video.job | Zavi | Local storage | 30 minutes | Lets the launch-video page find your video job again after a reload. |
| zavi:cookie-banner-dismissed, praxis:connect-return, praxis:refine-seed:*, composer seeds, reload guard | Zavi | Session storage | Until you close the tab | Remembers you closed the cookie banner without choosing (it stays closed for this tab only); brings you back to the right page after connecting an integration; hands a draft between panels; stops a reload loop after a deploy. |
| Cloudflare Turnstile | Cloudflare | Cookie / storage | Per Cloudflare's policy | Bot protection on the launch-video form. Loaded only on that page. |
3. Analytics
Analytics are on unless you turn them off. Choose “Reject” in the banner or switch analytics off in preferences, and the analytics tools stop straight away in that tab, the keys below are deleted from this browser, and no analytics request leaves your browser after that. Other Zavi tabs you already have open stop when you reload them.
| Name | Provider | Type | Expiry | Purpose |
|---|---|---|---|---|
| ph_<key>_posthog | PostHog | Cookie | 1 year | Anonymous visitor ID and session, so page views on our public pages can be counted. Shared across zaviagent.com subdomains. |
| ph_<key>_posthog and other ph_* keys | PostHog | Local storage | Until cleared or withdrawn | A second copy of the same data (posthog-js keeps both by default). |
| __ph_opt_in_out_<key>, __mp_opt_in_out_<token> | PostHog / Mixpanel | Cookie / storage | Until withdrawn | Records your analytics choice. |
| mp_<token>_mixpanel | Mixpanel | Local storage | Until cleared or withdrawn | Analytics identity and event queue. Once you are signed in, linked to your account ID and email. |
| ph_pv:<url>, mp_pv:<path>, mp_signup:<id>, mp_login:<id> | Zavi | Session storage | Until you close the tab | Stops one page view, sign-up or login being counted twice. |
4. Managing your preferences
Open the preferences panel here, from the “Cookie preferences” link in the footer of every marketing page, or from your account page once you are signed in.
- Your choice is stored in the
zavi_consent_v1cookie on this device and browser. It is not tied to your account, so a different browser or device will ask again. - We keep a choice — yes or no — for 180 days, then ask again. We also ask again if we add a category of cookie or change what a tool does.
- Closing the banner without choosing leaves analytics on. Choose “Reject” to turn them off.
- If your browser sends a Global Privacy Control signal, we treat it as “no” and do not show the banner. You can still turn analytics on in the preferences panel; a choice you make there is respected over the signal.
- You can also block or delete cookies in your browser's settings. Blocking the Necessary ones will sign you out.
5. The analytics tools, plainly
We use PostHog and Mixpanel, both listed on our sub-processors page. Two things worth saying out loud:
- PostHog requests are sent to a path on our own domain and forwarded to PostHog from there. This is a common setup; it does not change what is collected, and we mention it so that a request to zaviagent.com in your browser's network tab is not a surprise.
- PostHog receives anonymous page views on a short list of public pages. Once you are signed in, Mixpanel events are linked to your account ID and email address, so we can see that a sign-up or a login happened. Neither tool records your screen, and neither captures clicks automatically — we send a fixed list of named events.
- We do not ask Mixpanel to derive a location from your IP address.
6. Embedded services
A few pages embed another company's service in a frame. Anything set inside that frame is set by them, under their policy, and we cannot control it — so we name them and link their policy rather than guess at their cookies.
- Cal.com — The booking calendar on /talk-to-team and /about.
- Cloudflare Turnstile — bot protection on the launch-video form, loaded only on that page. Listed under Necessary above because it is a security measure on a form you are submitting.
7. Contact
Questions about this page, or a request to delete analytics data associated with you: support@zaviagent.com. We update this page when the list changes and move the date at the top when we do.
