Cookie Notice

Every cookie we set, what it does, and how long it lasts. There are only a few, and they all exist to keep you logged in.

Last updated August 12, 2026 · Effective August 12, 2026

The short version: Studio Visibility uses strictly necessary cookies only. They keep you signed in and keep the site secure. We run no advertising and no cross-site tracking, and we do not sell or share your information. We do measure aggregate site traffic (which pages get visited, roughly how many people), but that measurement sets no cookie and stores no persistent identifier — see Aggregate traffic analytics below. What follows is the full list, cookie by cookie.

1. What cookies are

A cookie is a small text file that a website asks your browser to store and send back on later visits. Related technologies — local storage, session storage — do a similar job using space in your browser instead of a file sent with each request. This notice covers all of them.

Cookies are usually described in two ways:

  • First-party cookies are set by the site you are visiting (studiovisibility.com). Third-party cookies are set by another company's domain.
  • Session cookies are deleted when you close your browser. Persistent cookies stay until they expire or you delete them.

2. Our approach: strictly necessary only

Studio Visibility sets strictly necessary cookies only. We do not use advertising, profiling, or social-media cookies, and we do not allow third parties to track you across other websites through our site. We do measure aggregate site traffic, but that measurement is cookieless — see Aggregate traffic analytics.

"Strictly necessary" has a specific meaning: the cookie is required to deliver a service you actively asked for. Ours exist to sign you in and keep you signed in securely, and to keep the site working and safe. Without them you could not log in or stay logged in, and pages behind the login would not work at all.

Because these cookies are strictly necessary, EU and UK law (the ePrivacy Directive as implemented, including the UK's PECR) does not require us to ask for your consent before setting them — but it does require us to tell you clearly what they are, which is what this page does. The small banner at the bottom of our site is an informational notice, not a consent request: dismissing it accepts nothing, and there is no "reject" button because there is nothing optional to reject. If we ever add a cookie-based analytics or advertising tool, that changes — see If we add cookie-based analytics or advertising.

3. The cookies we use

First-party cookies (set by studiovisibility.com)

CookiePurposeTypeExpires
sb-<project>-auth-tokenYour signed-in session. Holds the encoded access and refresh tokens issued by our authentication provider (Supabase) so that each page you open knows you are logged in and shows only your account's data. Set only after you sign up or log in. On some browsers this is split across numbered cookies (…auth-token.0, …auth-token.1) purely because of the 4 KB per-cookie size limit.First-party, strictly necessaryUp to 400 days, refreshed as you use the app. Deleted when you log out.
sb-<project>-auth-token-code-verifierSecurity check for a sign-in step in progress. Holds the one-time PKCE verifier that proves the login, email-confirmation, or Google authorization you finish is the same one you started, which prevents an attacker from hijacking that exchange.First-party, strictly necessaryMinutes — deleted as soon as the sign-in completes
Hosting and security cookiesOur hosting and content-delivery provider may set a short-lived cookie to route your requests to a healthy server and to block automated abuse. These carry no information about you beyond a routing or request identifier.First-party, strictly necessarySession, or up to 24 hours

<project> is the identifier of our Supabase project, so the real cookie name you will see in your browser is a fixed string such as sb-abcdefgh-auth-token.

Local storage (not a cookie, same idea)

KeyPurposeTypeExpires
sv-cookie-notice-dismissedRemembers that you closed the cookie banner, so we do not show it on every page. It stores the value 1 and nothing else — no identifier, nothing that could recognize you.First-party, strictly necessaryUntil you clear your browser storage

Third-party cookies

We do not embed third-party trackers, advertising pixels, social buttons, chat widgets, or session-recording tools in our pages. Two third parties do set their own cookies, but only on their own websites, when you choose to go there:

WhenWhoWhat happens
Checking outStripePayment is handled on Stripe's own hosted checkout page. Stripe sets cookies there (for example __stripe_mid and __stripe_sid) for payment processing and fraud prevention, governed by Stripe's cookie policy. We do not load Stripe's scripts on our own pages.
Connecting Google Search ConsoleGoogleYou are sent to Google's own sign-in and consent screen, where Google applies its own cookies under the Google cookie policy. This only happens if you choose to connect an account.

We also load our display font from Google Fonts at build time and serve it from our own domain, so no request goes to Google when you view a page and no font cookie is set.

4. Aggregate traffic analytics

We measure basic site traffic — which pages get visited, roughly how many people visit, and which sites send us referrals — so we know what's working. We built this to set no cookie and no persistent identifier, rather than adding a third-party analytics script, because a script like that typically means a new cookie and a new company receiving data about your visit.

Specifically, when you load a page, your browser reports:

  • the page path (for example /pricing), never the full URL with query parameters;
  • the referring site's domain, if you arrived by a link (not the specific page you came from);
  • campaign tags if your link included them (utm_source, utm_medium, utm_campaign);
  • a coarse device category (mobile, tablet, or desktop);
  • whether you were signed in at the time.

To count unique visitors without a cookie, our server computes a one-way hash of your IP address and browser type, combined with a secret value that changes every day at midnight UTC. That hash is what gets stored — never the IP address itself. Because the secret changes daily, the same visitor produces an unrelated, unrecoverable hash each day: there is no record linking one day's visit to the next, and nothing here can be reversed back to your IP address. This means "unique visitors" is really unique visitors per day — the closest we can get to a real count without tracking anyone.

We honor Global Privacy Control and the browser's Do Not Track setting: if either is present, no traffic data is sent or recorded for that visit, full stop. This measurement never runs on pages inside /admin, is never combined with advertising or profiling of any kind, is never sold or shared with anyone, and is visible only to us, internally, as aggregate counts — never as a list of individual visits or visitors.

5. What we do not use

To be explicit, Studio Visibility currently sets no:

  • cookies or persistent identifiers for analytics (our traffic measurement above sets none — see Aggregate traffic analytics) — and no third-party analytics like Google Analytics;
  • advertising, retargeting, or conversion-tracking cookies or pixels;
  • social-media cookies or embedded social widgets;
  • session-recording, heatmap, or A/B-testing cookies;
  • fingerprinting or cross-site tracking of any kind.

We do not sell personal information and we do not share it for cross-context behavioral advertising as those terms are defined under California law, and we do not process personal information for targeted advertising under other US state privacy laws.

6. If we add cookie-based analytics or advertising

Our aggregate traffic analytics (above) set no cookie today, and we intend to keep it that way. If we ever do add a cookie-based analytics, advertising, or tracking tool:

  • we will update this page first, with the specific provider, cookie names, purposes, and lifespans;
  • for visitors in the EEA, the UK, and Switzerland — and anywhere else consent is required — we will ask for your opt-in consent before any non-essential cookie is set, offer "reject all" as prominently as "accept all," and let you change or withdraw your choice at any time from this page;
  • for visitors in US states with opt-out rights, we will honor opt-out preference signals such as Global Privacy Control;
  • we will never make access to the Service conditional on accepting it.

Until that notice appears here, nothing but the strictly necessary cookies listed above is being set.

7. How to control cookies

You can see, block, and delete cookies in your browser settings. Every major browser also offers a private-browsing mode that discards cookies when you close the window:

One warning: because our only cookies are the ones that keep you signed in, blocking or deleting them will log you out and prevent you from logging back in. The public pages will still work.

Blocking cookies does not delete any information we already hold. To exercise your rights over that information, see the Privacy Policy.

8. Changes to this notice

We will update this page whenever the cookies we use change, and we will revise the "Last updated" date at the top. If we ever introduce non-essential cookies, we will tell you before they are set rather than after.

This notice supplements our Privacy Policy, which explains everything else we do with personal information.

9. Contact

Questions about cookies, or think you have spotted one we have not listed? Email support@studiovisibility.com and we will look into it.

Studio Lifesaver LLC (d/b/a Studio Visibility)
Georgia, United States

Questions about this document? Email support@studiovisibility.com.