Legal

Cookies and tracking

Last updated 8 September 2026

In short

This website sets no cookies. It stores one thing, and only if you close the box telling you that Tripline is now Deline: a note that you have seen it, so you are not shown it again. It holds no identifier, and nobody but your own browser ever reads it.

The site does count visits, using analytics hosted in the EU that keeps nothing on your machine. Every visit is counted as a new anonymous one; you are not recognised on your way back. There is nothing here to consent to, which is why there is no banner asking you to.

Version 1.5. Effective 8 September 2026.

What this site stores on your device

One thing, and only if you dismiss one box. In full:

  • no cookies are set
  • one entry in local storage, named deline.rename-notice.dismissed and holding the word true. It is written at the moment you close the box that says Tripline is now Deline, and its only purpose is that the box does not come back. It contains no identifier, nothing about you and nothing about what you looked at; it is never sent anywhere, and no script on this site or anywhere else reads it except the one that decides whether to show that box. Clearing your browser's site data removes it, and the only consequence is that you may be told about the rename once more.
  • nothing else is written to local storage, and nothing at all to session storage
  • the analytics described below keeps its visitor identifier in memory only, for the life of the page, and writes nothing to your device
  • no advertising or conversion pixel runs
  • no tag manager runs
  • no session recording or heatmap software runs
  • no fingerprinting of any kind is attempted

Fonts are served from this site rather than from a font network, so loading a page does not tell anyone else that you visited.

Swedish law (lag om elektronisk kommunikation, 6 kap. 18 §) requires your consent before storing information on your device or reading information from it, unless doing so is strictly necessary to deliver the thing you asked for. The one entry described above falls inside that exception: it records a choice you made by pressing the button, it does nothing except carry out that choice, and there is no version of "do not show me this again" that can work without remembering that you said it.

Analytics does not change that on its own. What the law asks about is storage on your device, and the measurement below deliberately uses none - it holds its identifier in memory for the life of the page and forgets it when you leave. That choice costs us something real: we cannot tell a returning visitor from a new one, and we have accepted that rather than ask you to accept a cookie.

If that ever changes - if this site starts storing an identifier so that visits can be linked together - a consent banner will appear, it will default to declined, and declining will actually stop the thing rather than only recording that you said no.

What this site measures

We count how the site is used, so we can tell which pages people read and whether a link we shared brought anybody. This runs on PostHog, hosted in the European Union(eu.i.posthog.com), which is the same provider the app uses.

Three things are recorded, and nothing else:

  • A page view - which page, and the link parameters in the address bar if you arrived from a link we shared, so we can tell which post or channel sent you.
  • Leaving the page - so a page somebody reads can be told from one they close immediately. It records that you left, not where you went.
  • A tap on a Download button - which button, on which page.

What is deliberately not done, and is switched off in code rather than by policy:

  • No cookie or other storage, as above - so no identity persists between visits.
  • No session recording. Nothing records your screen.
  • No autocapture. Clicks, scrolls and gestures are not harvested; only the three events above are sent.
  • No location. Analytics providers normally infer a city and a country from the network address a request arrives from. That inference is switched off here, so no location is derived from your IP address or stored against your visit.
  • Nothing about you. You are not asked to identify yourself and nothing on this site does it for you. There is no account here.

Loading the site fetches this analytics code from PostHog's EU asset host, so your IP address reaches them in order to serve it, exactly as it reaches any host you request a file from. The legal basis for the measurement is legitimate interest. You can object by emailing support@deline.dev, and you can stop it outright with any content blocker or by turning on Do Not Track - and if you would rather not be counted, that is a perfectly reasonable thing to do.

The subprocessor list names PostHog and where it runs.

Requests your browser makes to anything else

A few pages on this site talk to our database host from your browser. They all go to the same place - Supabase, in Ireland - which means your IP address reaches it, the same way it reaches any host you request something from. None of them stores anything on your device, none sets a cookie, and none is used to identify or track you.

An invite link

When you open an invite link, the page needs the trip's name to show you what you have been invited to. That lookup normally happens on our server, before the page reaches you, so your browser never contacts anything else.

If our database does not answer within a fraction of a second, the page loads with a generic heading and your browser retries the same lookup itself. In that case the request comes from your machine instead of ours. It is the same lookup either way - the only difference is which machine makes it.

The password and email pages

Setting a new password happens on this website rather than in the app, because people ask for a reset on a phone and open the email on a laptop. So /forgot-password, /reset-password and /email-confirmed each send one request from your browser to Supabase: to ask for a reset link, to check the link and save the new password, or to confirm an email address.

A reset link carries a one-time code in its address. That code isremoved from the address bar the moment the page opens, so it does not sit in your browser history and is not passed on to anything you click next, and it is never included in what the analytics above records. Nothing about your password is stored on your device by these pages.

The Android waitlist

The Join the waitlist for Android button under every Download button opens a box asking for a first name and an email address. Submitting it sends one request from your browser to Supabase, carrying exactly what you typed and nothing more. Opening the box, or closing it again without submitting, sends nothing at all.

Nothing about it is stored on your device: the page does not remember that you signed up, and if you reload it the box will happily let you do it again. The privacy page says what happens to the address, how long it is kept and how to have it deleted.

Hosting

The site is served by Cloudflare. Like any web host, Cloudflare processes the technical details of a request - IP address, user agent, the page requested - to deliver the page and to protect against attacks. Cloudflare's own security features can in some configurations set a cookie; none that do are enabled for this site, and this page will change if that ever stops being true.

The app is different

The Deline app stores things on your phone in order to work - your login, your trips, and a marker recording that you have opened the app before. That is not cookie law's subject and it is covered in the Privacy Policy. The app does use product analytics, hosted in the EU, which the privacy policy describes in full; it carries no advertising software and asks for no tracking permission, because it has nothing to track you with.

Questions

support@deline.dev

Tripline is now