Last updated: June 2026

Cookie Policy

This Cookie Policy explains how FrictionIndex uses cookies and similar technologies on the Platform. It should be read alongside our Privacy Policy, which contains further information about how we process personal data. By continuing to use the Platform, you acknowledge this Cookie Policy.

1. What are cookies?
Cookies are small text files placed on your device by a website or web application when you visit it. They enable websites to recognise your device on subsequent visits, remember your preferences and settings, maintain your authenticated session, and collect information about how you use the site. Similar technologies include local storage, session storage and unique session identifiers, which may be used for equivalent purposes. References to "cookies" in this policy include all such similar technologies unless stated otherwise.
2. Categories of cookies we use
We use two categories of cookies on the Platform: (a) Essential cookies — strictly necessary for the Platform to function correctly. Without these cookies, core functionality including authentication and session management would not operate. Essential cookies cannot be disabled without preventing use of the Platform. (b) Analytics cookies — used to collect information about how the Platform is used, which we use to improve its performance, features and user experience. Analytics cookies are not strictly necessary for the Platform to function but help us maintain and develop the service.
3. Essential cookies
Essential cookies are placed on the basis of our legitimate interest in operating a secure and functional Platform. They do not require separate consent under applicable law, although we inform you of them here. The following essential cookies are used by FrictionIndex: Session authentication token — Purpose: identifies your authenticated session and keeps you logged in while using the Platform. Without this cookie you would be logged out on every page navigation. Expiry: session (deleted when you close your browser or after a period of inactivity). CSRF protection token — Purpose: protects against cross-site request forgery attacks by verifying that form submissions and API requests originate from the Platform. Expiry: session. NextAuth session cookie — Purpose: maintains your authentication state between visits, enabling persistent login where you have chosen to remain logged in. Expiry: up to 30 days. User preference cookie — Purpose: stores display preferences such as your most recently selected time period or feature toggle state. Expiry: up to 90 days.
4. Analytics cookies — PostHog
We use PostHog, a product analytics platform, to collect information about how users interact with the Platform. PostHog places cookies on your device to enable this data collection. PostHog processes analytics data on servers within the European Economic Area (EU Cloud) on our behalf as a data processor. The data collected by PostHog via cookies includes: pages and features visited; elements clicked or interacted with; time spent on each area of the Platform; navigation sequences; session identifiers used to aggregate activity within a session; and device, browser and approximate geographic location data. This information is used solely by FrictionIndex to understand usage patterns and improve the Platform. It is not used by PostHog for its own commercial purposes and is not shared with third-party advertising networks. PostHog cookies used on the Platform include: ph_[token]_posthog — Purpose: identifies a unique visitor and session for analytics purposes, enabling PostHog to associate interactions with a consistent session. Expiry: up to 12 months. ph_[token]_posthog_ses — Purpose: identifies the current browsing session for session-level analytics. Expiry: 30 minutes of inactivity. PostHog's privacy policy is available at posthog.com/privacy. You can limit PostHog analytics by managing your browser cookie settings as described in section 7 below.
5. Third-party cookies
Other than PostHog (described in section 4 above), FrictionIndex does not use third-party advertising networks, social media plugins, behavioural tracking tools or retargeting pixels on the Platform. We do not permit third parties to place advertising or tracking cookies on the Platform. Where the Platform contains links to third-party websites, those sites may set their own cookies governed by their own cookie and privacy policies. FrictionIndex accepts no responsibility for cookies placed by third-party websites accessed via links from the Platform.
6. Legal basis for cookies
Essential cookies are placed on the basis of our legitimate interest in providing a secure and functional Platform and in maintaining authenticated sessions for users who have registered for access. They do not require your consent. Analytics cookies (PostHog) are placed on the basis of our legitimate interest in understanding Platform usage and improving the service. We rely on the soft opt-in approach applicable to business-to-business platforms used by professional subscribers, where analytics for service improvement does not require explicit consent where personal data is processed in accordance with the UK GDPR. You may opt out of analytics cookies at any time as described in section 7.
7. Managing and disabling cookies
You can control cookies through your browser settings. Most browsers allow you to: — View cookies currently stored on your device — Block all or selected cookies — Delete existing cookies — Receive a notification before new cookies are placed Please note that blocking essential cookies will prevent you from logging in and using the Platform. Blocking analytics cookies will not affect your ability to access or use the Platform but will prevent us from collecting usage data that helps us improve it. To manage cookies in common browsers: Google Chrome — Settings > Privacy and security > Cookies and other site data Mozilla Firefox — Options > Privacy & Security > Cookies and Site Data Apple Safari — Preferences > Privacy > Manage Website Data Microsoft Edge — Settings > Cookies and site permissions > Manage and delete cookies For further information about managing cookies, including browser-specific instructions, see allaboutcookies.org. You can also opt out of PostHog analytics specifically by using a browser extension that blocks analytics scripts, or by disabling JavaScript in your browser (though this will prevent the Platform from functioning).
8. Retention periods
Cookie retention periods vary by cookie type and purpose. Essential session cookies are deleted when you close your browser or after a defined period of inactivity. Persistent essential cookies (such as authentication state cookies) are retained for up to 30 days or until you log out. Analytics cookies placed by PostHog are retained for up to 12 months from placement. You may delete any cookies stored on your device at any time via your browser settings.
9. Changes to this policy
We may update this Cookie Policy from time to time, for example where we introduce new technologies or analytics tools, or to comply with changes in applicable law. The date of the most recent revision is shown at the top of this page. We will use reasonable endeavours to notify registered subscribers of material changes. Continued use of the Platform following any update constitutes acknowledgement of the revised policy.
10. Further information
For further information about how we process personal data, please see our Privacy Policy. For any questions about our use of cookies or similar technologies, please contact us via the Contact page on the Platform.