Cookies
A short summary. The canonical version is in our Privacy Policy.
This page summarises the cookies section of our Privacy Policy, which is the canonical version. If the two ever disagree, the Privacy Policy is correct.
What cookies we set
- Signing you in: the dashboard sets an auth cookie, written by Supabase and named
sb-<project-ref>-auth-token(split across additional cookies with.0,.1suffixes when the session is too large for one), plus a short-lived mirror cookie our server reads to decide whether to let a dashboard page load. It lasts 30 days by default, or 90 days if you check “Keep me signed in”; signing out deletes it. - Device-only preferences: a few settings (keep-signed-in choice, light or dark theme, whether the sidebar is collapsed) live in your browser's local storage, not in a cookie, and are never sent to us.
There are no advertising, analytics, or cross-site tracking cookies. On the website only (never the desktop app or CLI), Vercel Analytics and Speed Insights collect page views, referrer, coarse country-level location, and load performance. Neither uses cookies or assigns you a cross-site identifier.
Why there's no cookie banner
The only cookies we set are strictly necessary: they exist to keep you signed in, nothing else. The website's analytics are cookieless. A consent banner exists to ask permission for non-essential cookies, and we don't have any, so there is nothing to ask consent for.