Cookie policy and tracking technologies
This page describes the cookies and similar technologies used by the DiagNow application. Google Tag Manager loads with analytics and advertising storage denied by default. PostHog, session replay and optional measurement tags are activated only after your explicit consent.
1. What is a cookie?
A cookie is a small text file placed on your device by a website. In particular, it can remember your session and preferences and help secure certain operations.
2. Cookies we use
DiagNow uses cookies required to operate the service, payment-related cookies when you access checkout or the billing portal and, only if you agree, PostHog and measurement tags managed through Google Tag Manager. No Google advertising storage is authorised.
| Cookie / storage | Purpose | Retention |
|---|---|---|
diagnow-session |
Keeps the signed-in user session active. | 2 hours (default) |
XSRF-TOKEN |
Protection against CSRF attacks (form security). | 2 hours |
remember_web_* |
“Remember me” option when signing in. | 5 years |
diagnow_analytics_consent (localStorage) |
Remembers whether you accepted or rejected PostHog product analytics. | Cookie: 180 days; local storage: until cleared manually or a new choice is made |
ph_*, posthog* or PostHog local storage |
Only after consent: product analytics; session replay limited to public presentation pages, with inputs masked and support and sensitive areas excluded. No replay in the authenticated application or administration. | Browser storage until consent is refused or manually cleared; session recordings for no more than 30 days |
diagnow_posthog_user_id (localStorage) |
Only after consent: stores the internal user identifier to prevent events from two different accounts being linked in the same browser. | Until sign-out, rejection of PostHog or manual deletion |
| Google Tag Manager / dataLayer | Loads and orchestrates tags. Analytics and advertising consent are denied by default; only analytics consent changes to “granted” after acceptance. | No Google Tag Manager-specific cookie; dataLayer lasts for the page. Activated tags may define their own retention periods. |
| Stripe payment cookies | Secures checkout, prevents fraud, processes payment and provides access to the billing portal. | According to the payment provider’s configuration |
3. Third-party cookies
With your consent, DiagNow uses PostHog as a product analytics tool. Session replay is limited to public presentation pages and is never started in the authenticated application or administration dashboard. Inputs are masked; support and sensitive areas are excluded. Administration pages load neither PostHog nor Google Tag Manager and send no analytics events. Users and organisations are represented by internal identifiers; no email address is transmitted. Stripe may use its own cookies when you open checkout or the billing portal on the website.
Google Tag Manager, provided by Google Ireland Limited and Google LLC, loads the tag container on DiagNow pages. Before you make a choice, analytics and advertising storage are signalled as denied. If you accept, only analytics storage is granted; advertising categories remain denied. Loading the container sends Google the technical data normally carried by a web request, such as the IP address, user agent, timestamp, site origin and consent state. Tags added to the container must honour these signals, and this policy must be updated before any new purpose is activated.
4. What does “Reject” mean?
By selecting “Reject”, you reject optional usage analytics. In practice:
- PostHog is not loaded and no new product analytics event is sent.
- No new session replay is recorded.
- Viewed pages or routes, clicks, forms, time spent, technical context and internal user or organisation identifiers are not sent to PostHog.
- If PostHog was previously accepted, DiagNow stops future capture and clears PostHog cookies and local storage accessible from the website.
- Google Tag Manager keeps analytics and advertising signals set to “denied”; no optional measurement tag is authorised to use analytics or advertising storage.
What remains active: cookies required for sign-in, the session, form security and preferences, payment-provider cookies when you open checkout or the billing portal, and the technical loading of Google Tag Manager with optional consent denied. Rejecting analytics does not limit any DiagNow feature and does not prevent the requested business data or security and audit logs from being recorded.
Remembering the rejection: DiagNow stores the value “denied” in the “diagnow_analytics_consent” cookie and local storage to respect your choice and stop asking again. The cookie expires after 180 days; local storage remains until it is cleared or a new choice is made.
Data already sent: rejection stops future optional collection. Events or replays sent while analytics was previously accepted are not deleted automatically; they remain subject to the applicable retention periods or a deletion request.
5. How to manage cookies
Essential cookies cannot be disabled without making the service inoperable, for example for sign-in and form security. You can accept or reject PostHog and optional measurement tags without affecting DiagNow features, then change your choice at any time:
You can also clear all cookies and local storage from your browser settings:
6. Contact
For any questions about this policy: info@diagnow.ch