Analytics privacy

Last updated

The public AMS website and documentation use Google Analytics only after you choose “Allow analytics”. That choice also enables PostHog on the marketing site, documentation and console, including the console inside AMS for Mac, to understand the journey from a visit to signup and workspace use. Both browser trackers stay off until you allow them.

If you opt in, Google Analytics receives the public page path and title, broad device and browser information, approximate location, and a sign_up_start event when a public create-account link is selected. Query strings and URL fragments are removed from the page location before it is sent. PostHog receives approved marketing, documentation and console page paths, navigation and signup actions, and the referring website’s domain. Its browser identifier is linked to your internal user ID after sign-in, and to the random ID of a workspace you create or select. This lets AMS relate opted-in visits to workspace activation and subsequent usage. Names and emails are not sent to PostHog.

Consented PostHog events distinguish use inside AMS for Mac from browser use and include the Mac app’s numeric version when recognized. Approved console pages include Messages and Network. AMS reads existing app-identification tokens locally to derive these two values; raw user agents, version labels, operating-system versions and hardware details are excluded from analytics event properties. These events measure observed console use, rather than installations, app launches or background menu-bar activity.

Google Analytics is excluded from the authenticated /app/ console. AMS does not send message contents, workspace names, account details, authentication codes, or other product activity to Google Analytics. Google Signals, advertising storage, advertising user data, and ad personalisation remain disabled. PostHog receives only explicit events: no message content, form values, names, emails, authentication codes, full referrer URLs, or URL queries. Automatic content capture, session replay, and GeoIP enrichment are disabled. Browser connections still disclose an IP address and normal HTTP request headers, including the user agent, to the provider in transit; PostHog is configured to discard the IP address.

Within the same browser, your choice is shared across the website, documentation and console in a first-party cookie for 180 days. AMS for Mac keeps separate cookies and storage, so a choice in your ordinary browser does not automatically apply inside the app. The same consent and identity controls apply there. If you withdraw consent, AMS sends a denied Google consent update, removes first-party Google Analytics cookies it can access, and stops PostHog while clearing its stored identity. PostHog uses first-party local storage to retain a signed-in identity on the main website, and a parent-domain cookie to share a random anonymous identity with documentation. Signing out resets that identity. You can at any time here or through “Analytics settings” in a public-page footer. Earlier choices are not automatically reused when this tracking scope expands. A ten-minute cookie on the main website distinguishes a newly created account from a returning login, only while the same consented browser identity remains current. Withdrawing browser consent does not delete earlier events or disable the separate, minimal server-side workspace metrics described in the Privacy Notice.

Google documents the default information Analytics collects and how consent mode behaves. You can also review Google’s privacy policy. PostHog events go to its US Cloud project; see PostHog’s privacy policy. AMS retains PostHog events for up to 13 months. The Privacy Notice explains access, deletion, objections, and international transfers.