Cookie Policy
Last updated: May 2026
This page explains the cookies and similar technologies Quibo uses, why we use them, and how you can control them. We only set cookies that are strictly necessary to keep the app working — for analytics we use a cookieless solution, so there's nothing to opt out of.
1. What we set
Strictly necessary (always on)
sb-*: Supabase Auth session — keeps you signed in.__Host-*: CSRF protection on Server Actions.
These cookies are essential for the app to work. Under GDPR ePrivacy Directive, strictly necessary cookies don't require consent — without them you couldn't sign in.
Analytics (cookieless)
We use Litlyx, a privacy-first analytics provider that does not set any cookies and does not track users across sites. Aggregated pageview counts only — no IP storage, no fingerprinting, no third-party data sharing.
2. Third parties
- Stripe: the card-input iframe sets short-lived cookies during checkout (essential for payment processing — we never see them).
- hCaptcha: bot protection on signup; only loaded on those pages (essential for security).
3. Legacy cookie-consent cookie
Older versions of Quibo asked for cookie consent. If you visited before May 2026, your browser may still hold a cookie-consentcookie. It's harmless and ignored — you can delete it from your browser's site settings whenever you like.
4. Contact
Questions: dpo@quibo.cc.