Cookie Policy
Last updated: 16 August 2026
In short: We use essential storage technologies to keep the website and app working properly, including login and preference storage. Analytics that stores something on your device waits for your agreement if you are in Europe, and elsewhere runs until you turn it off. Session Replay follows the same rule as analytics, and masks your own documents wherever it runs. Measurement of your account sent from our servers stores nothing there and is explained below. Session Replay, where available, is managed separately. We do not use advertising cookies, and we do not currently sell information to advertisers; if that changes we will say so here first.
What this policy covers
This policy covers the Tagishoti website at tagishoti.com and the app at app.tagishoti.com.
It sits alongside our Privacy Policy, which is where you will find who operates the service, what kinds of information we collect, why, who it may be shared with, and how long it is kept.
What we mean by cookies
For simplicity we use the word "cookies" to also cover the browser's other storage technologies, such as localStorage, sessionStorage and IndexedDB.
We treat them together throughout this policy, but every row in the tables below names which kind of storage is used, what it is for, and how long it lasts.
How you choose and change your preferences
On your first visit, a banner appears at the bottom of the page with three options:
- Accept all — turns on analytics and Session Replay.
- Essential only — leaves only the essential storage active. Analytics and Session Replay stay off.
- Close (×) — outside Europe only, where measurement runs unless you turn it off. Closing the banner is not consent and not a refusal: it records only that you have seen it, so we stop asking and the default keeps applying. You can still change your mind from the Cookie settings link at the bottom of every page.
- Settings — opens a panel where you decide on each category separately.
The settings panel has three rows: essential storage, shown as always on and not switchable; analytics; and Session Replay, with its own switch. Session Replay is carried by the same analytics setup, so the two are linked — turning recording on also turns analytics on, and turning analytics off turns recording off with it.
Your choice is stored for 180 days, after which we may ask you to choose again.
You can change it at any time from the Cookie settings link at the bottom of every page on the website, and on the settings screen in the app.
Changing your preference stops future collection according to the new choice and may remove information stored in your browser for that purpose. Information already sent to our service providers is not deleted automatically simply because you changed a preference; it is handled according to the Privacy Policy and the relevant retention periods.
If we add a new category, or materially change what an existing category is used for, we will ask you to choose again.
Essential storage and service preferences
Some storage is necessary to run the service — for secure sign-in, for keeping you signed in, and for remembering your cookie choice itself.
Other items exist to remember choices you asked us to keep, such as language, display mode, or notices you have already dismissed.
Blocking some of these in your browser may stop parts of the service working properly, or stop certain preferences being remembered.
| Name | Kind | Where | What it does | How long |
|---|---|---|---|---|
sb-<project>-auth-token |
Cookie | The app | Holds your session. Set by Supabase, our authentication provider. When the value is too long for one cookie it is split into two, suffixed .0 and .1. |
Up to 400 days, renewed on each visit; cleared when you sign out |
sb-<project>-auth-token-code-verifier |
Cookie | The app | Secures the sign-in exchange when you use a Google account, so it cannot be hijacked midway. | A few minutes, cleared once sign-in completes |
li_connect_intent |
Cookie | The app | Remembers what you were doing when you were sent off to connect your LinkedIn account, so you land back in the same place. Marked HttpOnly, so code running in the browser cannot read it. | 15 minutes |
NEXT_LOCALE |
Cookie | The app | Remembers whether you chose Hebrew or English. Written only when that choice differs from the language your browser already asks for. | Session cookie — cleared when you close the browser |
tagishoti_consent |
Cookie | Website and app, on .tagishoti.com |
Your choice under this policy. Kept on the shared domain so a choice made on the website also applies in the app, and stored even when you reject — otherwise we would ask again on every page. | 180 days |
theme · resumate:theme |
localStorage | Website and app | Remembers whether you chose light or dark display. | Until you clear browser storage |
resumate:… |
localStorage | The app | Which one-time notices and tips you have already dismissed, so they are not shown again — for example resumate:whats-new or resumate:tailor-nudge. Each key stores a timestamp and nothing else. |
Until you clear browser storage |
sid |
sessionStorage | The website | A random identifier created only at the moment you submit the contact form, used to recognise a duplicate submission of the same form. | Until the tab is closed |
Analytics
We use Mixpanel to understand how the website and app are used, which parts help, and where people run into difficulty. If you are in Europe, nothing is stored on your device for measurement until you agree to it. Elsewhere, measurement is already running when you arrive and the banner is how you turn it off. Either way your choice is honoured in both directions: refusing stops measurement and removes what was stored. Screen recording is never on until you switch it on, wherever you are. Measurement of your own account’s activity, sent from our servers rather than your browser, stores nothing on your device and runs on our legitimate interest in understanding and improving the service. You can object to it at any time by contacting us.
We keep what is sent to a minimum. Specifically, in our configuration:
- Data is sent to Mixpanel's EU ingestion endpoint.
- We ask Mixpanel not to derive your location from your IP address, so no location properties are collected. Your IP still reaches Mixpanel's servers as part of any network request, which is governed by their own policy.
- The addresses of pages you visit are neither sent nor stored. The channel and campaign named in a link you arrive through, and the domain of the referring site — the domain only, never the full address — are recorded once, so we can tell which of our own posts reach people.
- Automatic capture of clicks and page views is off; every event comes from code we wrote deliberately.
- Screen-view events are sent only from the job board, a job card, and the welcome screen. Sensitive screens are not reported at all.
- When you are signed in, measurement is linked to your account, including the email address held on your Mixpanel profile.
| Name | Kind | Where | What it does | How long |
|---|---|---|---|---|
mp_<token>_mixpanel |
Cookie | Website and app, on .tagishoti.com |
A random device identifier and the measurement state. Set on the shared domain on purpose, so reading the landing page and then signing up count as one person rather than two. | One year (Mixpanel's default) |
mp_<token>_mixpanel |
localStorage | Environments other than tagishoti.com | Exactly the same information, where there is no shared domain to set a cookie on. | Until you clear browser storage |
tg_attr |
Cookie | Website and app, on .tagishoti.com |
How you first reached us: the channel and post named in the link you clicked, and the referring site's domain only — never the full address. Written once and never revised. If you sign up it is also stored against your account. It carries no personal identifier and is never shared with advertising networks. | 90 days |
Session Replay
In parts of the app we may use Mixpanel's Session Replay to understand faults and interface problems — an action that did not complete, or a screen that did not respond as expected. It is not a video: it records the structure of the page and what you did against it, then rebuilds that afterwards. It runs across the app, dialogs included — but the text is only legible on the job-hunting screens.
It is managed separately from ordinary analytics, has its own switch in the settings panel, and stays off even if you have accepted analytics. Turning it on also turns analytics on, because it is carried by the same setup. Choosing "Accept all" enables both.
Your own documents stay unreadable. All text is masked on the CV, settings and onboarding screens, and on any screen we have not classified, so a replay never reconstructs your résumé, your address or your employment history. Input fields are masked everywhere, whatever the screen — what you are part-way through typing is never rebuilt. Images, video, audio, embedded frames and canvas elements are blocked entirely, and console output and network requests are not collected. What stays legible is the job-hunting side of the product — job titles, company names, the buttons you pressed — which is the point: to see where the product confuses people, not to read what you wrote.
Before a recording is sent, it is held temporarily in your browser:
| Name | Kind | Where | What it does | How long |
|---|---|---|---|---|
mixpanelBrowserDb › mixpanelRecordingEvents |
IndexedDB | The app | Holds the recording in your browser until it is uploaded, so it is not lost if the connection drops or the tab closes. | A single recording is capped at 24 hours, and is cleared once uploaded |
mixpanelBrowserDb › mixpanelRecordingRegistry |
IndexedDB | The app | Tracks which recordings are still waiting to be uploaded, so none is sent twice. | Updated and cleared along with the recordings |
How long recordings are kept by Mixpanel is set in our account with them rather than in the service's code. If you want to know the current period, write to us and we will tell you.
Vercel Web Analytics
On the marketing website we also use Vercel Web Analytics, our hosting provider's measurement tool, for aggregate traffic figures.
It does not use cookies and does not keep a persistent identifier in your browser. Per Vercel's documentation, a visitor is identified by a hash derived server-side from the incoming request, which is discarded after 24 hours.
Each page view may record: the page address and its route pattern, the referrer you arrived from, filtered query parameters, location at country or region level, operating system, browser and device type. It is more than a page count.
Because there is no optional storage on your device here, it is not managed through our cookie switches. If you would still rather not be counted, write to us.
External services
For some actions we hand you over to a page run by another provider:
- Polar — the payment page, opened in a new tab when you choose to upgrade.
- Google — when you choose to sign in with a Google account.
- Unipile — the connection page used to link a LinkedIn account.
- Google Apps Script — the website's contact form is submitted to a Google service that passes it on to us.
Once you are on an external service, its use of cookies and storage is governed by that provider's own policy.
In two places your browser also loads content from a third-party domain inside one of our pages:
- LinkedIn profile pictures and company logos (
media.licdn.com) appear on the connections screen. Your browser fetches the image from LinkedIn directly, so LinkedIn sees that request. - DOCX previews are shown through Microsoft's document viewer (
view.officeapps.live.com) in a frame on the page. What is stored inside that frame is determined by Microsoft.
Apart from those two, no external provider runs code on our pages or sets cookies on them: the app's content security policy allows scripts from our own origin only.
What we do not do
- We do not use advertising cookies for targeted advertising.
- We do not embed advertising-network pixels; there are no Facebook, Google Ads or LinkedIn tracking tags, and no Google Tag Manager, on the website or in the app.
- We do not currently sell personal information to advertisers or data brokers. If that ever changes we will update this policy and tell you before it takes effect, and ask for your consent where the law requires it.
- We do not load fonts from external servers — all fonts are hosted by us.
- We do not require you to accept optional uses in order to use the service, and nothing is pre-ticked.
Browser controls
Beyond our own settings, your browser can block or delete cookies and storage technologies, usually under "Privacy and security".
Blocking everything may also delete or prevent the storage the service needs to run, which can affect your ability to sign in, save preferences, or use some features.
If you delete the cookie holding your consent choice, we may ask you to choose again on your next visit.
Changes to this policy
If we update this policy, we will update the date at the top of the page.
If the change introduces a new category, or materially changes how we use these technologies, we will ask you to choose again where that is required.
Questions about cookies and privacy
For questions about cookies, privacy or how information is used, write to us at info@yalabo.io.
Details of the entity operating the service are in the Privacy Policy.
This page is a translation. In case of any discrepancy, the Hebrew version prevails.