Skip to content
loam

Privacy

Cookies and website analytics.

The exact boundary: optional PostHog analytics on the public website after consent, never inside the signed-in app.

Last updated: 4 August 2026 · Version: LEGAL-2026-08-04-R1

  1. 01

    The boundary

    Optional PostHog analytics and session replay run only on the public marketing website at loam.ink, and only after a visitor gives consent. They do not run in the signed-in Loam application at app.loam.ink. Session replay is also disabled entirely on the public How we prove it and local document-verifier route (/security/). We do not send account details, school or tenant identifiers, student information, writing, evidence records, form values, login details or support content to PostHog.

    The application makes a separate request to load its own feature settings, containing one fixed identifier and no user, school, tenant or document data. It is operational configuration, not visitor analytics, and does not set a browser cookie.

  2. 02

    Essential storage

    Signed-in session. The application uses an essential, first-party session cookie. It keeps a user signed in, is Secure, httpOnly and SameSite=Lax, and is not available to browser scripts or used for tracking.

    Consent choice. The public website stores loam_analytics_consent after a visitor chooses whether to allow analytics. This host-only, first-party preference cookie lasts up to 180 days and prevents the consent notice appearing on every page.

  3. 03

    Optional analytics storage

    Only after consent, the public website loads PostHog and may store:

    • a random anonymous browser identifier used to connect events in one visitor journey;
    • first-party PostHog cookies or local-storage values used for anonymous sessions and replay; and
    • a first-party attribution record containing the landing path, allowlisted UTM campaign fields when present, and the referring hostname.

    These analytics values are host-only to the public marketing site at loam.ink and are not shared with signed-in application subdomains. Older releases could create parent-domain copies; browser code loaded by either the public site or the signed-in application expires those legacy copies. Analytics reporting uses the attribution record only on consented public-site page views and calls to action, including contact and teacher or school signup entry points. It is never joined to a completed product signup or signed-in activity. We never connect these events to a named PostHog profile and never call PostHog's identify function.

  4. 04

    What a consented visit sends

    • page path and page title, with query strings and URL fragments removed;
    • first-touch attribution on public-site page views and calls to action: the landing-page category, the allowlisted utm_source, utm_medium, utm_campaign and utm_content values when present, and the registrable referring hostname;
    • sections viewed, including whether student, teacher or school material was viewed;
    • navigation, call-to-action and outbound-link categories;
    • scroll-depth milestones, motion preference, page dwell time and web-performance measurements; and
    • a session replay of the public site.
    • on /security/ only: one static page view; a consent-choice or cookie-settings event if the visitor uses those controls; and coarse verifier counts for a sample download, sample versus non-sample file selection, and successful sample versus author-export verification.

    Attribution safeguards. Loam does not send utm_term, search queries or other free-form search text, full referrer URLs, URL query strings or fragments. Unknown or identifying landing paths are reported only as an “other” page category. Attribution is not appended to links into the signed-in application and is not used to attribute completed signups.

    Local verifier safeguards. The verifier reads a selected PDF on the visitor's device. PDF bytes, filename, file type or size, author or account name, document title or content, proof and key identifiers, evidence, replay, disclosure level, verification result, failure or error details, and explicit verification timing are not sent to PostHog or any other processor. The /security/ route sends no scroll, section, dwell, generic click, navigation, client-error or Web Vitals events.

    Replay safeguards. On public pages where replay is enabled, every input and form value is masked. Replay does not capture request or response bodies, network headers, console logs, canvas content or cross-origin iframes. Elements marked private are masked or blocked. Replay is never enabled on /security/. PostHog autocapture, person profiles, advertising, surveys and heatmaps are disabled.

    Network information. PostHog necessarily receives the source IP address and browser request information when the browser connects to it. Consented events also carry an ordinary event timestamp and a random anonymous browser identifier so we can count unique visitors. These could make elapsed time between a file-selection event and a successful-verification event inferable to someone with raw-event access. We do not add an explicit verification duration, create a named person profile, identify the visitor, or expose a time-to-verify dashboard.

  5. 05

    Purpose and legal basis

    We use this information to understand which public pages and perspectives are useful, where visitors leave, whether calls to action work, and where the website performs poorly. We do not use it for advertising, retargeting, data brokerage or decisions about students or users.

    We rely on the visitor's consent for optional website analytics and replay. Rejecting analytics has no effect on access to the website or application.

  6. 06

    Provider, location and retention

    PostHog, Inc. provides the analytics service. Loam uses PostHog Cloud EU, with analytics and replay data hosted in Frankfurt, Germany. PostHog and its contracted infrastructure providers process the information to provide the service under PostHog's data-processing terms.

    Session replays are retained for no more than 30 days. Analytics events and associated metadata are retained for up to 7 years under Loam's current PostHog Cloud plan. Loam reviews access and usefulness after the first 30 days and may shorten the event-retention period in future; this notice will be updated to match the enforced setting. Access is limited to authorised Loam personnel who need it for website analysis.

  7. 07

    Your choice

    Before consent, the website does not initialise PostHog or send it a request. Rejecting means no visitor analytics or replay is sent to PostHog. A browser Global Privacy Control signal is treated as a rejection.

    You can change or withdraw your choice at any time through Cookie settings in the site footer. Withdrawal stops future collection and removes Loam's optional analytics storage from that browser; it does not retroactively remove events already received. To request deletion of existing analytics information, contact hello@loam.ink. Include the anonymous browser identifier if available so we can locate the records without asking you to identify yourself.

  8. 08

    Changes and contact

    We will update this notice before materially expanding the analytics data, purpose, provider, location or retention period. We will ask for consent again where the change is not compatible with the choice already made.

    Privacy Officer, Loam, Difinity Pty Ltd, New South Wales, Australia. hello@loam.ink

Optional website analytics

With your permission, Loam uses PostHog EU to understand which public pages help visitors and where they leave. Session replay masks every input and is disabled entirely on the document-verifier page. We do not run PostHog analytics inside the signed-in app.

Read the cookie and analytics notice