Cookies are small files a website stores in your browser; local storage does a similar job without being sent to the server. This policy lists what SuprHiro stores on supahiro.co, in the SuprHiro application, and on the careers pages and candidate portal. It sits alongside our Privacy Policy.
1. Strictly necessary cookies
These keep you signed in and protect forms from forged requests. The Service cannot work without them, so they cannot be switched off. They are HttpOnly (unreadable by scripts) and, on our live site, sent only over HTTPS.
| Name | Purpose | Lasts |
|---|---|---|
| hr_access_token | Keeps a staff user signed in | 8 hours |
| hr_candidate_token | Keeps a candidate signed in to the candidate portal | 8 hours |
| authjs.csrf-token | Protects sign-in and forms against cross-site request forgery | Browser session |
| hr_oauth_state | Secures sign-in with Google or LinkedIn and calendar connections | 10 minutes |
On our live site some names carry a __Host- or __Secure- prefix, which tells the browser to apply stricter rules.
2. Analytics cookies
These help us understand how SuprHiro is used — which pages are visited, where people click and scroll, and what device and browser they use — so we can find problems and improve the product. We do not use them for advertising.
| Provider | Cookies | Purpose | Lasts |
|---|---|---|---|
| Google Analytics 4 | _ga, _ga_* | Counts visits and measures how pages are used | Up to 2 years |
| Contentsquare | _cs_* | Shows how pages are used — clicks, scrolling and navigation | Up to 13 months |
| PostHog (when enabled) | ph_*_posthog | Product usage analytics; session recording is switched off | Up to 1 year |
Lifetimes are the providers’ defaults and may change; your browser shows the exact expiry.
3. Security checks
Our signup and job application forms use hCaptcha to tell people from bots. hCaptcha runs in its own frame and may set its own cookies there; see hCaptcha’s privacy policy.
4. Local and session storage
The application remembers a few display preferences in your browser. They never leave your device and are not used to track you.
| Key | Purpose |
|---|---|
| theme | Light or dark mode |
| sidebar-collapsed, suprhiro.nav.open-groups | Navigation layout |
| feed-panel-collapsed, feed-panel-position | Position of the live activity panel |
| candidateViewMode, candidate-ranking-weights | How you prefer to view and rank candidates |
| hrdash.gettingStarted.dismissed | Hides the getting-started guide once dismissed |
| hr.assistant.conversationId | Continues your conversation with the staff assistant |
| careers.referralSource (session storage) | Remembers where a candidate came from (for example a job board) until they submit an application; cleared when the tab closes |
5. Other third-party requests
Some pages load fonts from Google Fonts, which means your browser sends your IP address to Google to fetch them. Interview booking pages may show Google Meet, Microsoft Teams or Calendly links; those services apply their own cookies once you open them.
6. How to control cookies
- Every browser lets you see, block and delete cookies — usually under Settings → Privacy. Blocking analytics cookies does not affect how SuprHiro works; blocking strictly necessary cookies will stop you signing in.
- You can opt out of Google Analytics on every site with Google’s opt-out browser add-on.
- You can opt out of Contentsquare with its privacy centre tools.
- Most tracker- and ad-blocking browser extensions also stop these analytics scripts from loading.
7. Changes and contact
We update this page when we add or remove a cookie. Questions: hiring@supahiro.co.