Cookies and browser storage
Updated September 23, 2026
These websites use browser storage to support the application and sign-in features you request. Two optional measurement tools can also run: product analytics through PostHog, which counts page views and clicks on links and buttons, and the Meta pixel, which measures our Facebook and Instagram ads. Both are described below, and you can turn each one off. We do not use session-replay tools. Fonts are served from this website.
There is no “accept all” action. The settings below explain each entry and give you controls that actually work, including turning product analytics and ad measurement off.
What is stored
| Entry | Purpose | Duration |
|---|---|---|
| thalos.quote-draft | Answers to the Thalos questions you have not sent yet, so you can finish later on this device. No health information. Removed when you send your answers. | 30 days, or until you send or clear it. |
| ph_…_posthog (cookie and local storage) | Product analytics through PostHog: a random identifier so visits can be counted without knowing who you are, plus your analytics setting. It records page views and clicks on links and buttons, never what you type into a form, and it does not load on application or health pages. | Up to one year, or until you turn analytics off or clear site data. |
| thalos.analytics-off | Remembers that you turned product analytics off in this browser. | Until you turn analytics back on or clear site data. |
| _fbp (cookie) | Advertising measurement through the Meta pixel, when we run Facebook and Instagram ads: a random browser identifier that lets Meta match visits to our ads. Set only on our public pages and the quote questions, never on application, sign-in, waitlist, or agent account pages, and never when your browser sends Global Privacy Control or Do Not Track or you have opted out. | 90 days, renewed on each visit where the pixel runs. |
| _fbc (cookie) | Set by the Meta pixel only when you arrive from a Facebook or Instagram ad, to record which ad you clicked. | 90 days. |
| thalos.ads-off | Remembers that you opted out of ad measurement (Do Not Sell or Share) in this browser. | Until you turn ad measurement back on or clear site data. |
| d130.agent | Application reference used when returning from identity verification. | This tab’s session, or until cleared. |
| Supabase authentication entries | Verified email sign-in for approved applicants and agents. | Until sign-out, expiration, or removal. A signed-in session may refresh. |
| thalos_access | Essential, secure, HttpOnly cookie for checking approval before opening a protected page. | Up to one hour, renewed when approved access is checked. Sign-out clears it; revoked access is rejected even before it expires. |
| d130_application | Essential, HttpOnly cookie for resuming only the Direct 130 application started in this browser, including after identity verification. It does not grant dashboard access. | Up to seven days. Sign-out clears it. The server stores a hash and expiration, and invalidates it when the application is linked to its verified email account. |
Application references and authentication entries use session or local storage; page access uses the essential cookie listed above. Only the two Meta cookies above are used for advertising. The application also holds unsent answers in page memory while the page is open. Reloading the page clears those unsent answers. Your browser may restore a tab’s session when restoring a previous browsing session.
Providers and hosted pages
Hosting and authentication providers may use essential security mechanisms when serving a requested feature. Stripe’s hosted payment and identity pages operate on a separate website and may use their own cookies and storage. Their notices and controls apply there. An ordinary link to a carrier or to NIPR does not load that site’s tracking code on this website.
Your controls
Privacy choices (the Cookie settings and Do Not Sell or Share My Personal Information links at the bottom of every page) can turn product analytics or ad measurement off or back on, clear unsent answers and saved application references, or sign you out and clear this site’s authentication storage. You can also use your browser’s site-data settings. Blocking all storage may stop an application handoff or sign-in from working.
Clearing local information does not erase records you already submitted, and it does not cancel a policy or payment. To request access, correction, or deletion of service records, follow the Privacy Notice.
Global Privacy Control and Do Not Track are recognized when your browser supplies them: neither product analytics nor the Meta pixel loads at all, and we treat the signal as your request to opt out of sharing. Turning ad measurement off stops the pixel in this browser; it does not delete the cookies Meta already set, which your browser's site-data settings can clear. Meta's own controls are at facebook.com/adpreferences. If any other optional tracking is introduced, this inventory and the controls will be updated before it is enabled.