Version 1 — last updated 7 September 2026
Last updated 4 September 2026
This policy explains what 8 SIGNS LIMITED ("8 Signs", "we", "us") stores on your device when you use app.8signs.io, and why. It covers cookies and the similar browser storage the app uses.
The short version: we use the cookies needed to keep you signed in, and nothing else. We do not use analytics, advertising or tracking cookies, and we do not share anything with advertisers.
Under UK and EU rules, consent is required for cookies that are not strictly necessary - analytics, advertising, profiling. Cookies that are strictly necessary to deliver a service you asked for are exempt.
Every cookie we set is in that exempt category: they exist to keep you signed in and to keep your session secure. There is nothing to consent to, so we do not interrupt you to ask. If that ever changes - if we add analytics, for example - we will ask for consent before setting anything, and this policy will say so first.
All of these are first-party, set by our authentication provider, Supabase.
| Cookie | Purpose | Lifetime |
|---|---|---|
sb-<project>-auth-token (and numbered parts) | Holds your signed-in session so you are not asked to log in on every page. Split across several cookies when the token is long. | Until you sign out, or the session expires |
sb-<project>-auth-token-code-verifier | A short-lived value used during sign-in and email confirmation to complete the exchange securely. | Minutes; deleted once sign-in completes |
These cookies are set with Secure and SameSite=Lax, and are scoped to this
site alone. Secure means they are only ever sent over an encrypted HTTPS
connection. SameSite=Lax means they are not attached to requests that another
website makes on your behalf, so a third-party page cannot act as you.
They are not marked HttpOnly, because the app itself has to read the session
in your browser in order to attach it to each request it makes. That is how the
authentication library is designed to work.
Signing out deletes them. Clearing your browser's site data for app.8signs.io does the same.
These are not cookies - they are stored in your browser's local storage, are never transmitted to us, and never leave your device.
| What | Purpose |
|---|---|
| Journal notes | Your private notes are stored only in your browser. They are not uploaded to our servers, which also means they are not backed up and do not follow you to another device or browser. |
| Discover readings | A cached copy of a topic reading so reopening it does not regenerate it. |
| Guide state | Whether you have already seen a feature's introduction, so it is not shown again. |
| Theme | Whether you chose light, dark or system appearance. |
Clearing your browser's site data removes all of it, including your journal notes. We cannot recover them if you do.
Stripe. When you make a payment, Stripe processes it and may set its own cookies in the payment fields for fraud prevention. That is Stripe's processing, under Stripe's privacy policy, and it happens only when you are paying. We do not receive or read those cookies.
RevenueCat. We use RevenueCat to record which plan you are on. It is called from the app; it does not set advertising or tracking cookies.
We do not embed social media buttons, advertising pixels, session recorders or third-party analytics anywhere in the app.
You can block or delete cookies in your browser's settings. Blocking our authentication cookies will stop you being able to sign in - that is what "strictly necessary" means in practice.
Because we set no non-essential cookies, there is no preference centre to manage. If you want your account and its data deleted entirely, you can do that from More > Delete account in the app, or by emailing us.
If we start using any cookie that is not strictly necessary, we will update this policy and ask for your consent before setting it.
Questions: support@8signs.io
8 SIGNS LIMITED Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R.