Legal
Cookie Policy
Every cookie BeDeeper actually sets, and why.
Defined terms carry the meanings given in BeDeeper's shared legal definitions unless expressly redefined here.
In plain language
BeDeeper uses only the cookies it needs to sign you in and to keep the sanctuary secure. BeDeeper does not run advertising cookies or third-party tracking cookies. Every cookie set by BeDeeper is listed below.
Related documents:
- Privacy generally: Privacy Policy
- Security posture: Security & Data Protection
1. What is a cookie
A cookie is a small piece of information a website stores on your device so it can remember something between requests — most often the fact that you are signed in. When you use BeDeeper, cookies help the sanctuary hold your session, remember trusted devices for multi-factor authentication, and hold short-lived post-verification grants.
2. Categories
BeDeeper uses only strictly necessary cookies. It does not run advertising cookies, marketing cookies, cross-site tracking cookies, or third-party analytics cookies.
Because BeDeeper is a signed-in sanctuary and every cookie it sets is strictly necessary to deliver that service, BeDeeper does not present a general cookie consent banner. Where local law requires consent for a specific category BeDeeper does not currently use (for example, analytics), BeDeeper would introduce that category with a consent flow before enabling it. Section 5 describes how that would be handled.
3. Cookies actually set by BeDeeper
| Cookie | Set when | Purpose | Lifetime | Category |
|---|---|---|---|---|
sb-<project-ref>-auth-token and related session cookies |
You sign in | Supabase authentication session used to hold your BeDeeper sign-in. Managed by the @supabase/ssr middleware. Names may include chunk suffixes (for example, ...auth-token.0). |
Session, refreshed on activity | Strictly necessary |
bedeeper_admin_test_mode |
An administrator explicitly opts in to admin test mode (and only where the environment allows it — in production, this requires an additional server-side flag) | Marks the request as coming from an authenticated administrator running a test path. Never set for regular members. | Up to seven (7) days | Strictly necessary — administrative |
bedeeper_trusted_device |
You complete multi-factor authentication and choose to remember this device | Marks this device as trusted for MFA so BeDeeper does not challenge you again for a limited period. | Up to thirty (30) days | Strictly necessary — security |
bedeeper_mfa_grant |
You complete multi-factor authentication or a recovery-code flow | Short-lived signed grant that confirms you passed MFA in this session. Used to keep you moving through the sanctuary without repeated challenges. | Up to twelve (12) hours | Strictly necessary — security |
All of the cookies above are set with HttpOnly and SameSite=Lax, and with Secure in production. That is, they are readable only by the server, sent only with same-site requests except for top-level navigation, and never sent over unencrypted connections in production.
4. What BeDeeper does not use
BeDeeper does not set — inside the sanctuary — advertising cookies, cross-site tracking cookies, marketing cookies, or third-party analytics cookies. BeDeeper does not embed advertising networks or social-network trackers in the signed-in application.
Stripe may set cookies on Stripe-hosted pages (checkout, customer portal) when you interact with them directly. Those cookies are set by Stripe and governed by Stripe's own policies. BeDeeper does not read those cookies.
If you sign in with Google or Apple OAuth, the identity provider may set cookies on its own domain during the sign-in flow. BeDeeper does not read those cookies. OAuth is covered by the identity provider's own policies.
5. If BeDeeper ever adds a new category
If BeDeeper decides to add a cookie category that is not strictly necessary — for example, an operational analytics tool — BeDeeper will:
- Update this Policy and Privacy Policy first, with an explanation of the tool and its purpose.
- Update the subprocessor list in BeDeeper's Legal Foundation.
- Introduce a member choice at the point where the cookie would be set, where local law requires consent.
- Never enable a category retroactively for a session that took place before the change.
6. Managing cookies in your browser
You can control cookies through your browser's settings. Because BeDeeper's cookies are strictly necessary, disabling them will affect basic sign-in, multi-factor authentication, and the ability to use the sanctuary. BeDeeper does not encourage disabling them.
7. Changes
Substantive changes to this Policy follow the notification convention in Terms of Service and the effective-date convention in BeDeeper's Legal Foundation. Introducing a new cookie category is treated as substantive.
8. Contact
Questions about this Policy may be sent to privacy@bedeeper.com.
