Last updated: August 13, 2026
This document is published in English only. We do not maintain a translated version, because two versions of a contract eventually disagree and only one of them can control.
1. Who We Are and What This Policy Covers
1.1 WebberUI (the "Site", available at webberui.com) is a service operated by Teyra LLC ("we", "us", "our"), a limited liability company formed in Wyoming, United States, with its registered business address at 30 N Gould St Ste N, Sheridan, WY 82801, United States. This Cookie Policy explains which cookies and similar technologies the Site uses, why we use them, and how you can control them.
1.2 This policy covers the Site only. It does not — and cannot — cover components you install from our registry into your own projects, because installed components contain no cookies, no beacons, and no tracking of any kind. They never contact our servers, never report anything back, and can never be remotely disabled. That is a core promise of our License Agreement (/license) and Privacy Policy (/privacy), and we repeat it here.
1.3 Companion documents: Privacy Policy (/privacy), Terms of Service (/terms), License Agreement (/license), Refund & Billing Policy (/refunds), and our Subprocessors list (/subprocessors). This page lives at /cookies.
2. What Cookies and Similar Technologies Are
2.1 "Cookies" are small text files a website stores in your browser. A "session" cookie is deleted when you close your browser; a "persistent" cookie stays until it expires or you delete it.
2.2 "Local Storage" is a separate storage area in your browser. Unlike cookies, its contents are not automatically attached to requests sent to a server — a page's own code has to read it. We use Local Storage for one analytics identifier (Section 3) and for several purely local conveniences that never leave your browser (Section 4).
2.3 We keep the list deliberately short. If a technology is not listed on this page, we do not use it.
3. The Complete List of Cookies We Use
3.1 Our own application code sets no cookies at all. Every cookie on the Site comes from one of two systems: Clerk (our sign-in provider) and PostHog (our analytics tool). A third measurement service, Cloudflare Web Analytics, also runs on the Site but sets no cookies whatsoever — see Section 3.5.
| Name / pattern | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| Clerk session cookies (a small set of authentication cookies; exact names are set by the Clerk SDK) | Clerk, set in a first-party context on webberui.com | Establishes and maintains your signed-in session and keeps that session secure. Never used for advertising or analytics. | Strictly necessary (sign-in features only) | __client_uat and __client_uat_<suffix>, observed on webberui.com on 2026-08-13. Both are set before sign-in, on the first page load, because Clerk must be able to tell an unauthenticated visitor from an expired session. Clerk sets further session cookies (such as __session) only once you sign in. Clerk also stores __clerk_environment in localStorage. Lifetimes are set by Clerk; see Clerk's own cookie documentation |
| PostHog analytics cookie (one cookie holding a randomly generated anonymous ID) | PostHog (PostHog Cloud, hosted in the United States), set as a first-party cookie by our page | Recognizes a returning browser so visits are not double-counted, and links together the short, fixed list of usage events described in Section 3.3. | Analytics | ph_phc_n67JZqLui5gKCqVZoUyPcxP662Z2nQ2t4oYnUn3WwdLj_posthog, observed on webberui.com on 2026-08-13. The same key is used for a localStorage entry and for two sessionStorage entries (…_window_id, …_primary_window_exists). It is written on the first page load, before any consent interaction, unless a Do-Not-Track or Global Privacy Control signal is present. Lifetime is the posthog-js default |
| PostHog Local Storage entry (the same anonymous ID, mirrored in Local Storage) | PostHog | Same as above. PostHog is configured with "localStorage+cookie" persistence, so the identifier lives in both places. | Analytics | Until you clear your browser's site data |
3.2 Clerk sign-in cookies (strictly necessary). Clerk cookies exist only so that signing in works. Signing in is never required to browse the Site or to install the 274 free-tier components — the free tier needs no account, and therefore no sign-in cookies. When sign-in is enabled, the Clerk SDK manages its own cookies; some may be set when the sign-in system loads, before you actually sign in. They are used solely for authentication and session security.
3.3 PostHog analytics — exactly how it is configured.
- If our analytics key is not configured in a deployment, no analytics code runs at all: no requests, no cookie, no Local Storage entry.
- The identifier is random and anonymous. We never call PostHog's "identify" function anywhere in our code, so the analytics ID is never linked to your Clerk account, your name, or your email — not at sign-in, not ever.
- Session recording (replay) is disabled. Autocapture is disabled. In-app surveys are disabled. "Dead click" capture is disabled. Pageviews are sent manually by our own code; page-leave events are enabled.
- The events we capture are a fixed, named list: pageview; component viewed; install command copied; composer opened; pricing page viewed; pricing scope switched; checkout clicked; email subscribed (this event records only which page the form was on — never the email address itself); documentation scrolled to 75%; a Pro item returning a 401; and Web Vitals performance metrics.
- Event details are limited to things like component, template, or documentation slugs, page type, referrer, and performance numbers. They never include your email, name, or account identity.
- Analytics data is processed on PostHog's servers in the United States. See the Privacy Policy (/privacy) and Subprocessors (/subprocessors) for cross-border transfer details.
3.4 Hosting. The Site runs on Cloudflare. Nothing in our own code or configuration sets Cloudflare cookies. Whether Cloudflare's edge sets an operational cookie of its own (for example, a bot-management cookie) depends on account-level settings outside our codebase. As configured on 2026-08-13, Cloudflare Bot Fight Mode is turned off on webberui.com and we subscribe to no bot-management product, so no __cf_bm cookie is set. Should we enable such a feature later, any cookie it sets would serve security and abuse prevention only, would be set by Cloudflare rather than by our code, and we would not use it for tracking.
3.5 Cloudflare Web Analytics — cookieless, and listed here for completeness. Our Cloudflare zone serves a traffic and performance beacon (static.cloudflareinsights.com/beacon.min.js) that reports to a first-party endpoint on our own domain. It sets no cookie, writes nothing to Local Storage or Session Storage, and assigns you no identifier — it is cookieless by design and cannot recognize you across visits or across sites. It appears in this policy not because it stores anything on your device, but because you should know everything that runs on the page. Content blockers block it, and the Site works fully without it.
4. Local Storage That Never Leaves Your Browser
4.1 The Site keeps a few conveniences in Local Storage. These are stored only on your device. Our servers never receive them, and we keep no server-side copy:
| Key | What it stores |
|---|---|
webberui:saved |
Components you have marked as saved |
webberui:saved-templates |
Templates you have marked as saved |
webberui:theme-tokens |
Your custom theme built in Theme Studio |
| Theme preference | Your light/dark mode choice (managed by the Site's theming library) |
| One demo-only key | Remembers that you dismissed the "broadcast bar" demo on its demo page |
4.2 Playground parameters. Settings you adjust in component playgrounds are held in memory only. They are not written to cookies or Local Storage, and they disappear when you leave the page. Nothing is stored, locally or on our servers.
4.3 You can remove the saved-items keys with one click on the account settings page ("clear local saved items"), or clear everything through your browser's site-data settings. Doing so affects nothing except your own local lists and theme.
5. What We Do Not Do
5.1 To be explicit, on the Site there are:
- No advertising cookies, pixels, or tags of any kind.
- No cross-site tracking or cross-site profiling.
- No data exchange with advertising networks — we neither send them data nor receive data from them.
- No selling, renting, or trading of any data collected through cookies or Local Storage.
- No session recording or replay.
- No linking of the analytics identifier to your name, email, or account.
- No cookies, beacons, telemetry, or "phone home" mechanisms in installed components. Code you install from WebberUI runs entirely inside your own project and never reports back to us.
6. How to Control Cookies
6.1 Browser settings. Every major browser lets you block or delete cookies, per site or globally, and clear Local Storage under "site data".
6.2 Content blockers. Ad and tracker blockers typically stop the PostHog analytics cookie and requests entirely. This does not break the Site: every feature works with analytics blocked.
6.3 Do Not Track and Global Privacy Control. Consistent with our Privacy Policy, we treat your browser's "Do Not Track" (DNT) and Global Privacy Control (GPC) signals as an opt-out from analytics. verified in code: lib/analytics.ts sets respect_dnt: true and checks GPC before initialization
6.4 Clearing Local Storage. Use the "clear local saved items" button on the account settings page, or your browser's site-data controls.
6.5 What happens if you block things.
- Blocking the analytics cookie: nothing breaks. All features keep working.
- Blocking Clerk's cookies: you will not be able to sign in or stay signed in. Sign-in matters only for Pro access (including the current launch promotion); the 274 free-tier components require no account, no sign-in, and therefore no cookies at all. Command-line installs authenticated with a Pro license key send the key in an
Authorizationheader, not in a cookie, so they are unaffected by cookie settings. - Blocking Local Storage: saved items, your custom theme, and your light/dark preference will not persist between visits. Everything else works.
7. Consent and the EU/EEA Note
7.1 Being straight with you about the current state: the Site does not currently show a cookie-consent banner. Where our analytics key is configured, the PostHog anonymous-ID cookie and Local Storage entry are set when a page first loads, without a prior consent prompt.
7.2 In some jurisdictions — notably the EU/EEA and the United Kingdom under ePrivacy rules — non-essential cookies (which includes our analytics cookie) require prior consent. This is a pre-launch decision, and there are two compliant options on the table: (a) switch posthog-js to cookieless mode (persistence set to "memory" — no cookie and no Local Storage identifier), so that no consent banner is needed at all; or (b) add a consent banner (at minimum geo-gated to EU/UK visitors) that blocks PostHog from loading until you opt in. We have chosen (b): a consent banner, geo-gated to EU/UK visitors, which blocks PostHog from loading until you opt in. It will be in place before public launch; until then this Section describes the position accurately and analytics remains blockable by any content blocker.
7.3 Strictly necessary cookies (Clerk sign-in) are generally exempt from consent requirements, and in any case become relevant only if you choose to sign in.
8. Changes to This Policy
8.1 When our cookie usage changes, we update this page and the "Last updated" date at the top. Material changes — a new cookie category, a new provider, or a new purpose — will be flagged prominently on this page, and any new cookie-setting provider will also be added to the Subprocessors list (/subprocessors). We will not quietly weaken a promise made here.
9. Contact
9.1 Questions about this policy, or requests concerning your data: official@teyrallc.com. Your rights to access, correct, or delete personal data are described in the Privacy Policy (/privacy).
9.2 WebberUI is a service of Teyra LLC.