What we keep in your browser
Sign-in session
Cookie
Named sb-…-auth-token. Keeps you signed in between visits. Set when you sign in and removed when you sign out; otherwise it lasts up to 400 days. A large session can be split across two or three cookies with the same name and a number on the end.
Sign-in check
Cookie
Named sb-…-auth-token-code-verifier. Set when you ask for a sign-in link, and used once, to prove that the link is being opened by the person who asked for it.
Theme
Local storage
Named feedara-theme. Remembers light or dark, only after you pick one with the switch in the header. It stays in your browser and is never sent to us.
Currency
Cookie
Named feedara_currency. Set only if you pick a currency yourself on the Billing page, so prices are shown in it from then on. It lasts one year, and is used for nothing else.
Help assistant
Local storage
Named feedara-helper. Set only if you tuck the help assistant away to the edge of the screen, so it stays tucked on your next visit. It stays in your browser and is never sent to us. What you type to the assistant is not stored at all.
All five are set by feedara.ai itself. They are what UK law calls strictly necessary: the site cannot keep you signed in, or remember a choice you made, without them.
What we do not use
No analytics cookies, no advertising or retargeting cookies, no tracking pixels, no social media widgets, and no scripts from other companies apart from the security check described next. Nothing on feedara.ai follows you to another website.
If we ever count visitors, it will be with a tool that uses no cookies at all, and this page will say so before it is switched on.
The sign-in and contact check
The sign-in page and the contact form run a quick check from Cloudflare, our security provider, that a request comes from a person and not a script. Without it, a script could use up the sign-in emails for the whole site or fill our inbox with spam. The check loads from Cloudflare’s own address (challenges.cloudflare.com) and only on those two pages, so a visitor who never signs in or writes to us never meets it.
We measured what it does on the live page: it sets no cookies. It keeps one small entry in your browser’s storage for Cloudflare’s own address (named cf.turnstile.u), which Cloudflare reads, not us. Cloudflare receives your IP address and some details of your browser, and its Turnstile privacy policy says it uses them only to detect and block bots. UK law treats security measures of this kind as strictly necessary.
When you pay
When you subscribe or manage your plan, you move to a page run by Stripe, our payment provider. Stripe sets its own cookies there to prevent fraud, and they are covered by Stripe’s cookie policy, not this one.
Controlling cookies
Your browser can show, block or delete cookies at any time, usually from its privacy or security settings. If you block the sign-in cookies you will not be able to sign in, but the audit and every public page work without them.
The privacy policy covers everything else we hold. Questions go to hello@feedara.ai.