Every cookie, every key, and exactly what runs when.
This page is the complete inventory: the six cookies we can set, the browser storage we use, the analytics that load only with your consent, the cookie-free service analytics on our own server, and the anonymous visit counts. Nothing is missing from this list.
The short version
If you read nothing else:
- No analytics load until you save “Analytics” in the cookie banner. Ticking without saving does nothing.
- Withdrawal is one click: “Reject all” in the reopened cookie manager (footer, or Settings → Privacy). It also deletes the analytics cookies and forgets the analytics id.
- We set six cookies in total, all listed below with name, purpose and lifetime. There are no hidden ones.
- Our own service analytics uses no cookies at all — it records server facts about signed-in accounts, and one switch stops it and deletes what was recorded.
- Anonymous visitors exist only as daily counts with no identifier of any kind — no cookie, no IP, no fingerprint. You can still opt out at /privacy/counting.
- We never use ad pixels, retargeting, cross-site tracking or fingerprinting, and we never sell data. No Google Analytics, no Meta pixel — fonts are self-hosted too.
1. How consent works here
The banner is our own (Klaro, self-hosted — no consent vendor sees your choices). It offers two things: essential service and Analytics. Essential is what makes the site work and cannot be refused; Analytics is off until you turn it on.
- Nothing analytic is even downloaded before you save an Analytics consent. A tick without Save does nothing.
- “Accept” and “Reject all” sit on the same layer with the same weight.
- You can reopen the manager any time from the footer of the marketing site or Settings → Privacy in the app.
- Your decision is logged for accountability on our own consent server in Thessaloniki (klaro.tzekos.eu), with a pseudonymous consent id and the page template — never raw paths, never tokens, never your e-mail. That record proves your choice; consent records are kept for the life of the choice plus three years.
- Public application, offer and interview pages carry no analytics at all, and the pages behind e-mail links (unsubscribe, preferences, confirmations) are untracked.
4. Level 1 — analytics with your consent (PostHog Cloud EU)
With your consent, PostHog (hosted in Frankfurt, Germany) helps us see how the site and app are used. It records: pages viewed, time on page, scroll depth, clicks on links, buttons and forms, rage clicks, heatmaps, page speed, browser errors, and masked session replays. Signed-in users are identified by account id only — never by e-mail. PostHog is set not to store IP addresses, so it keeps neither your address nor a location worked out from it.
- Session replays are masked at the source: every character of text and every input is masked in your browser before anything is sent, media is blocked, and nothing at all is recorded on the Teams and coach screens, where we hold data for someone else.
- Never sent: tokens from invite, interview, deal or unsubscribe links (those paths are templated first), e-mail addresses, the public application and offer pages, the admin console.
- Eleven account milestones (signup completed, checkout opened, payment succeeded and the like) are forwarded from our server to PostHog — only for accounts whose analytics consent is on.
- Retention: events 12 months, replays 30 days.
- Withdrawal: one click on Reject all (reopened manager, or Settings → Privacy). It stops capture, deletes the PostHog cookies and forgets the analytics id.
6. Anonymous visit counts
To know which pages get visits without tracking anyone, we keep daily counters: page template, entry flag, referrer host, country, device class, browser version, OS family — one number per day per combination. No visitor id, no session id, no IP address, no user agent, no campaign tags: there is nothing a row could be joined to a person with. The addresses in the page request are used at the door to derive the country and device columns, then dropped. Applicant pages and e-mail-link pages are never counted. Counters are kept 25 months. Because there is no identifier, these counts hold no personal data — but you still get a switch: /privacy/counting sets a small opt-out cookie (13 months) and your visits are not counted.
7. In-app surveys
Our short feedback questions store their state on your account, never in the browser — no cookie, no banner needed. At most one prompt every 30 days, never in your first week (except the onboarding question), never on an application, checkout or interview page, and answering is always voluntary. “Don't ask me again” on any prompt, or Settings → Privacy → Feedback prompts, turns them off. Answers are kept 24 months, then anonymised. The one exception that runs in the browser is the pricing-page exit survey, which is part of Level 1 and appears only with analytics consent.
8. What we never do
The list of absences matters as much as the inventory:
- No advertising pixels, no retargeting, no remarketing lists, no Google Analytics, no Meta or LinkedIn pixels.
- No cross-site or cross-device tracking, and no fingerprinting — refusing analytics is not worked around by other means.
- No selling or renting data, ever, to anyone.
- No analytics on the public application, offer or interview pages, and none in the admin console.
- No tracking pixels in our e-mail: we do not record opens or clicks.
- Fonts and badge images are self-hosted: no font provider, launch site or other third party sees your visits through them.
9. Changes to this document
When a cookie, a storage key or a tracking behaviour changes, this page changes first — the inventory above is kept true by tests against the code. We revise the date at the top on every change. Change log: 26 September 2026 — first version of this page: full cookie and storage inventory, both tracking levels, the anonymous counts and their opt-out. It replaces the cookie section formerly folded into other pages; /cookie-policy now redirects here.
10. Contact
Questions about cookies or tracking, or an objection you could not place through the switches: privacy@erioun.com. Everything else: support@erioun.com. You can also complain to the Hellenic Data Protection Authority (dpa.gr). Who we are: Loukas Tzekos – Sole Proprietorship, D. Papathanasiou Vas. 79, 54629 Thessaloniki, Greece.
Frequently asked
Do I have to accept cookies to use Erioun?
No. Essential cookies are the only requirement and they carry no analytics. Refusing Analytics changes nothing about your plan, prices or features.
How do I withdraw consent?
One click: reopen the cookie manager from the footer or Settings → Privacy and press Reject all. Capture stops, the analytics cookies are deleted, and the analytics id is forgotten.
Are session replays watching me type?
Replays exist only with your consent, and they are masked at the source: every character of text and every input is masked in your browser before anything is sent, media is blocked, and the Teams and coach screens are never recorded at all. Replays are deleted after 30 days.
What are the anonymous visit counts?
Daily counters per page template — country, device class, browser version, referrer host — with no identifier of any kind. No IP, no cookie, no user agent is stored, so no row can be joined to a person. You can still opt out at /privacy/counting.
Does Erioun track me across other sites?
No. There is no cross-site tracking, no ad network, no fingerprinting and no data purchase. What we measure is limited to erioun.com, and most of it only with your consent.
Keep exploring
Every cookie, every key, and exactly what runs when.
Start your free trial and keep your job search under control.
- EU-built
- GDPR-native
- export & delete anytime