← BackRedFlag

Cookie Policy

Last updated: 15 July 2026

What cookies are

Cookies are small text files stored on your device when you visit a website, used to remember information about you or your visit. Similar technologies such as localStorage (which stores data in your browser rather than sending it with every request) work for a similar purpose. This policy explains which cookies and similar technologies RedFlag (redflagstatus.com, operated by Qern Pty Ltd) uses, why, and how to control them. It should be read together with our Privacy Policy.

Categories of cookies we use

Essential. Required for the Service to function — signing in, keeping your session active, and caching your plan so the dashboard doesn't hit the database on every page load. You cannot opt out of these through the Service; blocking them in your browser will prevent sign-in and core features from working.

Analytics. Used to understand which features are used and where people get stuck, so we can improve the product. Set by PostHog and Google Analytics on the website.

We do not use advertising, retargeting, or third-party marketing cookies, and we do not sell your data.

Cookies used on redflagstatus.com

NameSet byPurposeDurationCategory
sb-*-auth-tokenRedFlag (Supabase Auth), first-partyKeeps you signed in to the web dashboardUp to 400 days, or until you sign outEssential
rf_pcRedFlag, first-partyCaches your plan (Free/Pro) and onboarding status briefly, to avoid a database lookup on every pageUp to 5 minutesEssential
rf_consentRedFlag, first-partyRecords your cookie-consent choice (analytics accepted or declined) from the consent banner, so we don't ask again every visitUp to 12 months, or until you change your choiceEssential
ph_<project-key>_posthogPostHog, via our reverse proxy t.redflagstatus.comAssigns an identifier so we can measure feature usage and improve the productUp to 1 yearAnalytics
_ga, _ga_<container-id>Google Analytics (gtag.js), third-partyDistinguishes users and sessions for website traffic analyticsUp to 2 yearsAnalytics
Turnstile challenge cookieCloudflare, third-partyConfirms you passed the bot-detection challenge on the sign-in/sign-up pageSession, typically a few minutesEssential (security)

Not a cookie, but similar: your light/dark theme preference is stored in your browser's localStorage under the key rf-theme, not in a cookie. Stripe does not set cookies on redflagstatus.com — if you upgrade to Pro, you're redirected to a Stripe-hosted checkout or billing-portal page, and any cookies there are set on Stripe's own domain and governed by Stripe's privacy policy.

The Chrome extension

The RedFlag extension does not use cookies. It uses chrome.storage.local — a browser-extension storage area, not a cookie — to keep you signed in and remember in-progress scan state on your device. This is described in more detail in our Privacy Policy.

How consent works

The first time you visit redflagstatus.com, a cookie-consent banner appears at the bottom of the page. Analytics cookies (Google Analytics, PostHog) are off by default and stay off until you choose "Accept analytics" in the banner — we do not set them, and no analytics network requests are made, before you opt in. If you choose "Essential only", analytics stay off and the banner is dismissed. Essential cookies (see the table above) are not part of this choice — they're required for the Service to function and are set automatically.

Your choice is remembered in the rf_consent cookie (see the table above) for up to 12 months. You can change your mind at any time using the "Cookie preferences" link in the footer of every page, which reopens the banner and clears your previous choice.

Managing your choices

You can clear or block cookies at any time through your browser settings; blocking essential cookies will prevent sign-in and core features of RedFlag from working. Most browsers let you view, delete, and block cookies from their privacy/settings menu:

  • Chrome: Settings → Privacy and security → Cookies and other site data.
  • Firefox: Settings → Privacy & Security → Cookies and Site Data.
  • Safari: Settings → Privacy → Manage Website Data.
  • Edge: Settings → Cookies and site permissions.

You can opt out of PostHog analytics in your browser by calling posthog.opt_out_capturing() from the browser console, or block analytics scripts with a content/ad blocker. You can opt out of Google Analytics site-wide using Google's Google Analytics Opt-out Browser Add-on.

Do Not Track

There is no common industry standard for "Do Not Track" signals, and RedFlag does not currently change its cookie behaviour in response to them.

Changes to this policy

We may update this policy as the product evolves, for example if we add a new analytics/advertising provider or change how the consent banner works. We will revise the "Last updated" date above when we do.

Contact

Questions about cookies or your data? Email support@qern.com.au.

HomePrivacy PolicyTerms of Service

RedFlag legal

We use analytics cookies (Google Analytics, PostHog) to understand how RedFlag is used. Essential cookies are always on.Learn more in our Cookie Policy.