Two cookies, and they only sign you in.
Every piece of storage this site uses, what it does, how long it lasts, and why none of it needs a consent banner.
The short version
No tracking cookies. No advertising cookies. No third-party cookies. That is why there is no consent banner — everything below is either required to sign you in or stored only in your own browser.
1. What we actually store
Two cookies keep you signed in. Two browser-storage entries remember your preference and, in preview mode, your drafts. That is the whole list.
| Name | Type | What it does | Lifetime |
|---|---|---|---|
| sb-<project>-auth-token | Cookie (first-party) | Holds your Supabase session so you stay signed in between pages. Set only after you open a sign-in link. | Until you sign out or the session expires |
| sb-<project>-auth-token-code-verifier | Cookie (first-party) | A short-lived value used to complete the sign-in link securely (PKCE). | Minutes, during sign-in only |
| appshift:theme | localStorage | Remembers whether you chose Light, Dark or System. Never sent to the server. | Until you clear browser storage |
| appshift:preview:v1 | localStorage | Only in local preview mode: keeps your draft answers in this browser so the playbook works without an account. | Until you clear browser storage |
If you never sign in, the site sets no cookies at all.
2. Why we do not ask for consent
European and UK rules require consent for storing information on your device, with exceptions. Authentication cookies fall under the "strictly necessary" exception: you asked to sign in, and without them the sign-in would not hold. Remembering your light or dark choice falls under the "appearance" exception, which exists for exactly this.
Nothing here profiles you, follows you to other sites, or feeds an advertising network, so nothing here needs a banner. We would rather earn the absence of a banner than design one.
3. If analytics is added later
No analytics service runs on this site today. If one is added, we will take the cookieless, aggregate-only route wherever it is available — measuring which steps get finished, not who finished them.
If a setup ever requires storage that is not covered by an exception, a consent request appears before anything is stored, refusing is one click, and the playbook keeps working either way. This page is updated before any of that goes live.
4. How to remove them
- Sign out — the session cookies are cleared immediately.
- Clear site data in your browser settings — this removes the cookies and the stored theme and preview drafts.
- Block cookies for this site — you can still read the playbook; you just will not be able to stay signed in, and the local preview will forget your answers on reload.
Anything unclear, or something we missed? Write to legal@appshift.xyz.
Contact
Aleksandr Borisov · CUIT 27-96484697-4
Laprida 1283, Piso 2, Dpto C, C1425 Ciudad Autónoma de Buenos Aires, Argentina
legal@appshift.xyz