Sign in ↗

Legal

Cookie Policy

Phases currently uses only cookies and similar browser storage that are necessary to authenticate users, protect the Service, remember interface choices, and reconnect active work.

Effective
15 September 2026
Last updated
15 September 2026

1. About this policy

This Cookie Policy explains how Aerobase Innovations AB uses cookies and similar storage technologies in the Phases web application. It should be read with our Privacy Policy.

A cookie is a small text value a website asks your browser to store and return with later requests. Local storage is kept by your browser for the same site but is not automatically sent with every request.

2. Our necessary-only approach

Phases does not currently load advertising cookies, cross-site tracking pixels, or optional behavioural-analytics cookies. The storage listed below supports a service you request or a necessary security, preference, or continuity function. Because there is no optional cookie category to enable, our short notice is informational and its Got it button records only that you have seen the notice—it is not used as consent.

If we introduce non-essential cookies in the future, we will update this policy and provide a choice before they are set where required by law.

3. Cookies Phases uses

Name or patternProviderPurposeTypical duration
sb-<project-ref>-auth-token (may be split into numbered chunks)Supabase, first-party contextKeeps guest or registered users signed in, refreshes the session, and authenticates protected requests.Up to about 400 days in the browser; refreshed or replaced during the session and removed on sign-out.
sb-<project-ref>-auth-token-code-verifier, ...-flows-code-verifier, and ...-flow-<flow-id>-code-verifierSupabase, first-party contextProtects and completes a pending PKCE sign-in or account-recovery flow; the flow index lets the authentication library find and clean up pending verifier slots.Normally removed when the flow completes, is evicted, or you sign out. A stale verifier can remain until the configured browser expiry, up to about 400 days.

Cookie names can include deployment-specific identifiers, and a large authentication value can be divided into chunks by the authentication library. Those chunks have the same purpose as the main auth cookie.

4. Similar browser storage

Key or patternPurposeDuration
themeRemembers your light, dark, or system appearance preference.Until you change it or clear site data.
durable-workflow-cursor:<workflow-id>Stores the workflow identifier, schema version, and last applied event sequence so the browser can safely reconnect a long-running workflow without skipping events.Until you clear site data; the server still verifies ownership and remains the source of truth.
phases:cookie-notice:v1Remembers that this informational cookie notice was dismissed.Until the notice version changes or you clear site data.

These values do not contain chat text, simulation inputs, material chemistry, uploaded files, passwords, or result artifacts.

5. Authentication-provider cookies

If you choose Google or GitHub sign-in, that provider may set or read cookies on its own domain to authenticate you, prevent fraud, and remember its own settings. Aerobase does not control those third-party cookies. Review the provider's cookie and privacy information and use email-and-password sign-in if you do not want to use a social provider.

6. Your browser controls

You can inspect, delete, or block site data in your browser settings. Blocking or deleting authentication storage will sign you out and can prevent guest chat and protected features from working. Clearing preference storage resets the theme, reconnect cursor, and cookie notice. Server-side chats, runs, and artifacts are not deleted when browser storage is cleared; use the product's deletion controls or contact us for those requests.

7. Changes and contact

We will update this policy and the date above when our use of cookies or similar storage changes materially. Questions can be sent to support@aerobase.se.