Cookie Policy

Last updated: May 2026

This page explains the cookies and similar technologies Quibo uses, why we use them, and how you can control them. We only set cookies that are strictly necessary to keep the app working — for analytics we use a cookieless solution, so there's nothing to opt out of.

1. What we set

Strictly necessary (always on)

  • sb-*: Supabase Auth session — keeps you signed in.
  • __Host-*: CSRF protection on Server Actions.

These cookies are essential for the app to work. Under GDPR ePrivacy Directive, strictly necessary cookies don't require consent — without them you couldn't sign in.

Analytics (cookieless)

We use Litlyx, a privacy-first analytics provider that does not set any cookies and does not track users across sites. Aggregated pageview counts only — no IP storage, no fingerprinting, no third-party data sharing.

2. Third parties

  • Stripe: the card-input iframe sets short-lived cookies during checkout (essential for payment processing — we never see them).
  • hCaptcha: bot protection on signup; only loaded on those pages (essential for security).

3. Legacy cookie-consent cookie

Older versions of Quibo asked for cookie consent. If you visited before May 2026, your browser may still hold a cookie-consentcookie. It's harmless and ignored — you can delete it from your browser's site settings whenever you like.

4. Contact

Questions: dpo@quibo.cc.