WHOMA
Cookies Policy
This policy explains the cookies and similar browser storage WHOMA uses, who provides them, why they are used, and how long they last.
Your choice
Essential storage operates because it is necessary for secure sign-in, security, consent records or a feature you requested. Optional PostHog analytics, error capture and masked session replay stays off until you opt in.
Accept and reject are offered at the same level. You can change or withdraw your choice below at any time. Withdrawal stops future optional browser capture and resets the local PostHog identity; it does not make earlier consented processing unlawful.
Essential cookies
whoma_cookie_consent — WHOMA — stores the signed version, timestamp and analytics choice for 180 days so we can respect your decision.
Authentication cookies — authentication provider — maintain secure sign-in and refresh an authenticated session. Names vary by project and tokens last for the session or provider-configured authentication lifetime.
whoma_access_hint — WHOMA — is an HTTP-only signed routing hint, not an authorisation decision, and lasts up to 30 days.
whoma_agent_quiz_access — WHOMA — is a host-only HTTP-only bearer used to protect an in-progress quiz from unauthorised changes and lasts for up to 30 days.
whoma_agent_resume_suggestions — WHOMA — temporarily returns user-requested resume suggestions in an encrypted and signed HTTP-only cookie and expires after 15 minutes.
Essential and user-requested local storage
whoma.agentQuiz.sessionId — WHOMA — keeps only the opaque reference needed to resume an in-progress quiz in the same browser tab session; the bearer secret remains in an HTTP-only cookie.
whoma-agent-onboarding-step and whoma-agent-onboarding-draft — WHOMA — keep an in-progress onboarding step and draft in that browser until completion, explicit clearing or browser-storage clearing. This may contain the profile information entered into the draft.
whoma-sidebar-collapsed — WHOMA — remembers the signed-in user's requested sidebar presentation until the choice is changed or browser storage is cleared.
You can clear these items in browser settings, but doing so may sign you out, remove an unfinished draft or reset the interface.
Optional PostHog analytics
PostHog EU is the named provider. After consent, its ph_* browser storage may hold a pseudonymous analytics identity, session and consented usage state for up to 12 months, subject to earlier withdrawal or browser clearing.
Purposes are product analytics, navigation and feature-adoption measurement, error diagnosis, and fully masked session replay. WHOMA masks page text, element attributes and form values. We do not use this category for advertising, cross-site tracking or solely automated significant decisions.
WHOMA does not rely on the aggregate-statistics exception for this PostHog configuration because it can involve individual event histories and session replay; consent is required.
Browser controls and questions
Most browsers let you block or delete cookies and local storage. Blocking essential storage can prevent sign-in or requested features from working. For assistance or a request concerning earlier analytics data, contact the address below.
For cookie or consent questions, email support@whoma.co.uk.
Manage cookie preferences
Essential cookies are always enabled. Non-essential categories stay off until you choose otherwise.