Legal
Cookie Policy
Last updated: September 19, 2026
Effective date: September 19, 2026. Vemzio uses a minimal, functional-first cookie set. We do not run advertising networks, cross-site trackers, or behavioral analytics. This page lists every cookie family the Service can set and why.
1. Strictly Necessary Cookies
These are required for the Service to function and cannot be disabled without breaking features you explicitly use.
1.1 vemzio_session
- Purpose: keeps you signed in to the dashboard. Contains an HMAC-signed payload with your user id, username, and an opaque authentication token — not readable by scripts (httpOnly).
- Duration: 7 days, or until you sign out.
- Type: first-party, strictly necessary, httpOnly, SameSite=Lax, Secure.
1.2 sb-access-token / sb-refresh-token (conditional)
- Purpose: compatibility session cookies for legacy Supabase client flows (community Q&A, verification flows started before the unified session). Set only when those flows authenticate you.
- Duration: 1 hour (access) / up to 30 days (refresh, only if issued).
- Type: first-party, strictly necessary.
1.3 CSRF / anti-abuse tokens
- Purpose: request validation on authentication and verification endpoints (e.g., OAuth `state` parameters). Sometimes stored short-term in cookies or session storage.
- Duration: minutes — just long enough to complete the flow.
- Type: first-party, strictly necessary.
2. Preference Storage (localStorage)
Not cookies — browser-local preferences that never leave your device and contain no identifiers beyond your own choices:
vemzio-theme— dark or light mode.vemzio-lang— interface language (English/Spanish).vemzio-sidebar-collapsed— your dashboard sidebar preference.
You can clear these at any time from your browser's site-data settings.
3. Analytics
Vemzio ships no third-party analytics cookies today. If we later add privacy-respecting, aggregate analytics (e.g., Cloudflare Web Analytics, which is cookieless), this page will be updated first and, where consent is legally required, a consent prompt will precede any non-essential storage.
4. Third-Party Setters
During payment or OAuth flows you may briefly interact with domains like connect.stripe.com or polar.sh, which set their own strictly-necessary cookies under their policies. Vemzio does not control those cookies and receives no advertising data from them.
5. Managing Cookies
- Session cookies are removed when you sign out (the dashboard logout clears them) or by clearing site data in your browser.
- Blocking strictly-necessary cookies will prevent sign-in and escrow flows from working.
- Because we set no marketing/ad cookies, there is no consent banner to manage — non-essential storage simply isn't set.
6. Do Not Track
We honor the spirit of DNT by not tracking you across sites at all; there is nothing additional to honor.
7. Contact
Questions about this policy: reach us through the channels listed in the Privacy Policy (§12).
Questions about this document? Reach the Vemzio team through your dashboard. The English version of this document governs; translations are provided for convenience only.