Cookie Policy
This Cookie Policy (“Policy”) explains how Volcano Services, LLC (“Volcano”, “We”, “Us”, and “Our”) uses cookies and similar technologies when you (“You” or “Your”) visit or use the marketing and signed-out pages of the https://volcano.dev website (collectively, the “Service”), and how You can manage Your cookie preferences. For more information about how We process Personal Data and Personal Information, please see our Privacy Policy, available at https://volcano.dev/legal/privacy.
Types of Cookies
Cookies are small text files that may be stored on Your device when You interact with certain websites and services. Similar technologies include web beacons, pixels, and embedded scripts, and We use the term “cookies” in this Policy to encompass these technologies that help automatically collect certain usage information. Cookies are widely used to support key functions such as logging-in, authentication, remembering Your account preferences, and enhancing user experience.
Volcano uses the following types of cookies:
Necessary Cookies: These types of cookies are necessary for the Services to function properly. They help enable essential functions like secure login experience and session management. Because these types of cookies are required for use of certain Service features and functionalities, they are set to “always active” and cannot be disabled.
Analytics Cookies: These cookies help us understand how visitors interact with Our Service and enhance Service performance. For example, analytics cookies may tell Us the number of users and analyze website traffic, or which features are most used.
| Source | Cookie Name | Category | Duration | Purpose |
|---|---|---|---|---|
| localStorage (PostHog Inc., US cloud, is the processor) | ph_<project_token>_posthog | analytics | 365 days | Anonymous device ID, session ID, referrer/UTM attribution, feature-flag and person properties |
| First-party (Volcano) | volcano_cookie_consent | necessary | 365 days | Records the visitor's analytics-cookie choice and the Cookie Policy version it was made against. |
| First-party | __Host-volcano_refresh_<project_id> | necessary | Configured per project (30 days by default) | Refresh token for Volcano Auth. HttpOnly, Secure, SameSite=Lax, Path=/ |
| First-party | volcano_git_connect_binding | necessary | 10 minutes | CSRF/state binding for the GitHub-connect OAuth handshake. HttpOnly, Secure, SameSite=Lax, Path=/github/callback |
| First-party | volcano_import_connect_binding_<hash> | necessary | 10 minutes | CSRF/state binding for the project-import connect flow. HttpOnly, Secure, SameSite=Lax, scoped to the callback path |
| First-party cookie set by Stripe.js (Stripe, Inc.) | __stripe_mid | necessary | 1 year | Fraud prevention / payment-session integrity |
| First-party cookie set by Stripe.js (Stripe, Inc.) | __stripe_sid | necessary | 30 minutes | Fraud prevention / payment-session integrity |
| Third party (Stripe, Inc.) | Stripe's own cookies on checkout.stripe.com | necessary | Stripe-defined | Set only if a user is redirected into Stripe's hosted Checkout; governed by Stripe's cookie policy, not ours |
| localStorage | volcano_session, volcano_access_token, volcano_refresh_token | necessary | Until logout | Dashboard login session — this, not a cookie, is how volcano.dev itself keeps you logged in |
| sessionStorage | volcano_oauth_state, volcano_oauth_redirect_url, volcano_oauth_next | necessary | Tab close | CSRF state and return destination across a Google/GitHub redirect |
| localStorage | volcano:referral-code | functional/necessary | Until claimed/cleared | Holds a referral code from a referral link until the reward is claimed |
| sessionStorage (PostHog) | ph_<token>_window_id, ph_<token>_primary_window_exists | analytics | Tab close | Session and session-replay window tracking |
| localStorage / sessionStorage | Last-opened project, log-table column layout, AI-builder session, dismissed-toast flags | necessary | Varies | UI preferences |
Managing your Cookie Preferences
You can manage your cookie preferences at any time through the Cookie Preferences link in Our website footer. You can choose which types of cookies to allow or disable. Please note that necessary cookies cannot be disabled, as they are required for the Service to operate.
You may also be able to control or block cookies through Your browser settings. We also honor Global Privacy Control signals as valid opt-out requests. Blocking certain cookies may affect some features or functionality of the Service.
Changes to this Cookie Policy
We may update this Policy from time to time. When we make changes, the “Last Updated” date above will be updated. Any such changes will be effective as of such date.