Cookie Policy

Version 2026-07-30. All policies

DRAFT FOR ATTORNEY REVIEW. Not yet reviewed by a legal practitioner. Placeholders must be completed before publication.

Service: Ideas Central, https://www.ideas-central.com Last updated: [DATE OF PUBLICATION]

This policy is short because Ideas Central sets very few cookies. Everything we use is either needed to sign you in and keep the session safe, or remembers a preference you set yourself.

What we set

"Cookie" below covers browser cookies, localStorage and sessionStorage, because the ePrivacy rules on storing and accessing information on your device apply to all of them.

Name pattern Type Purpose Strictly necessary? Lifetime
sb-<project-ref>-auth-token Cookie or localStorage, set by Supabase Auth Keeps you signed in. Holds your session and refresh token so you do not have to log in on every page Yes Session token expires in about 1 hour and refreshes silently; the stored record persists until you sign out or it expires. [CONFIRM CONFIGURED REFRESH LIFETIME]
sb-<project-ref>-auth-token-code-verifier localStorage, set by Supabase Auth PKCE code verifier and OAuth state value. Ties a login redirect back to the browser that started it, which is what stops a CSRF or login-injection attack Yes Deleted as soon as the sign-in completes; minutes at most
ic-theme localStorage Remembers whether you chose light or dark No, but it is your own preference and holds no identifier Until you clear it
ic-units localStorage Remembers whether you work in millimetres or inches No, but it is your own preference and holds no identifier Until you clear it
__cf_bm Cookie, set by Cloudflare Bot management. Distinguishes automated traffic from a person so the service stays available Yes 30 minutes
cf_clearance Cookie, set by Cloudflare, only if you are shown a security challenge Records that you passed the challenge so you are not challenged again on every request Yes Up to 1 year, or as configured. [CONFIRM WHETHER CHALLENGES ARE ENABLED]

The two Cloudflare cookies appear only where Cloudflare's security features are active on a request. Neither is used for advertising or profiling, and Cloudflare states that neither corresponds to any user ID in a customer application.

What we do not set

Why there is no cookie banner

Under the ePrivacy Directive (2002/58/EC as amended), Article 5(3), and the equivalent UK rule in regulation 6 of PECR, consent is not required for storage that is strictly necessary to provide a service the user has expressly requested, or that is used for the sole purpose of transmitting a communication.

Every cookie we set is either strictly necessary for authentication and security, or is a preference you set yourself in the interface. We set nothing for analytics, advertising or measurement. On that basis a consent banner is not required, and we would rather not show you a dialogue that asks permission for nothing.

This must be re-checked if we ever add cookie-based analytics, an embedded video or map, a chat widget, a social embed, an A/B testing tool, or any advertising tag. Any of those would need a compliant consent mechanism with prior opt-in and a genuine reject option. The point is flagged in docs/legal-review-notes.md.

Under POPIA there is no separate cookie consent rule. Processing has to satisfy a section 11 justification, which the storage above does, as performance of a contract and as our legitimate interest in keeping the service secure. See the Privacy Policy.

Controlling cookies

You can block or delete cookies in your browser at any time:

Browser Where
Chrome Settings → Privacy and security → Third-party cookies / Site settings
Firefox Settings → Privacy & Security → Cookies and Site Data
Safari Settings → Privacy, and Develop → Empty Caches for stored data
Edge Settings → Cookies and site permissions

Most browsers also have a "clear site data" option that removes cookies and local storage for a single site.

What happens if you block them. If you block the Supabase auth cookie or clear local storage for ideas-central.com:

Blocking the preference keys (ic-theme, ic-units) is harmless. The interface will simply return to its defaults each visit.

You can still use the anonymous generator, subject to the free anonymous export limit, without signing in. That limit is enforced against a hash of your IP address rather than a cookie, so it survives clearing your browser data, and it is shared with anyone else on the same network.

Changes

We will update this page whenever we add or remove anything that stores information on your device, and change the date at the top.

Questions: privacy@ideas-central.com