Cookie Policy
Last updated: 2026-04-21 Effective: 2026-05-01
This Cookie Policy explains what cookies FlowLibs uses, why we use them, and your choices. It supplements our Privacy Policy.
What are cookies?
Cookies are small text files that a site stores in your browser. They let a site remember you between page loads, keep you signed in, and understand — in aggregate — how the site is used. "Cookies" in this document also covers similar technologies like localStorage and sessionStorage.
What we use cookies for
FlowLibs uses a small set of cookies. We do not use advertising cookies, and we do not allow third parties to track you across other websites from FlowLibs.
Strictly necessary
| Cookie / item | Set by | Purpose | Typical lifetime |
|---|---|---|---|
sb-<project>-auth-token | Supabase (via @supabase/ssr) | Keeps you signed in and authenticates requests on your behalf | Session / up to 1 year |
sb-<project>-auth-token-code-verifier | Supabase | PKCE code-verifier used during the OAuth sign-in flow | A few minutes |
| Google OAuth state cookies | Google (during sign-in redirect) | CSRF protection during the OAuth handshake with Google | Short-lived |
| CSRF / session cookies | FlowLibs | Protect form submissions and authenticated actions from cross-site attacks | Session |
Without these cookies, the Service cannot function — you wouldn't be able to sign in or stay signed in. They are set on the basis of our legitimate interest in delivering the Service you requested.
Analytics
| Cookie / item | Set by | Purpose | Typical lifetime |
|---|---|---|---|
_vercel_jwt, __vercel_toolbar, etc. (as applicable) | Vercel | Privacy-friendly, aggregate site analytics via Vercel Analytics. We do not see IP addresses, and Vercel Analytics does not track you across other sites | Up to 1 year |
Vercel Analytics is designed to operate without personal identifiers and does not require consent in most jurisdictions, but if you'd prefer to opt out of analytics entirely, see "Your choices" below.
Payment (Pro and Team subscribers only)
When you start a checkout, you are handed off to Stripe. Stripe sets its own cookies on its checkout domain for fraud prevention and session integrity. FlowLibs does not read those cookies. See Stripe's own cookie and privacy notices.
What we do not use
- No advertising cookies.
- No cross-site tracking pixels.
- No social-media "like" or "share" trackers that phone home.
Your choices
- Browser controls. All major browsers let you block or delete cookies. Blocking strictly necessary cookies will break sign-in.
- Opt out of analytics. If your browser sends the Global Privacy Control (GPC) signal or Do Not Track, we honor it by disabling analytics for your session.
- Delete your account. Deleting your account also invalidates the auth cookies tied to that account.
Changes to this Policy
We may update this Cookie Policy as the Service evolves. Material changes will be reflected in the "Last updated" date above, and significant changes will be announced in-app or by email.
Contact
Questions? Email hello@flowlibs.com.