Cookie Policy
Effective Date: July 27, 2026 Last Updated: July 27, 2026
Short version: Marlo uses only the cookies required to keep you signed in. There are no advertising cookies, no third-party trackers, and no cross-site profiling — which is also why you are not greeted by a cookie consent banner.
What we use
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
sb-access-token |
Keeps you signed in | Strictly necessary | Session / refreshed |
sb-refresh-token |
Renews your session without making you log in again | Strictly necessary | Up to 30 days |
These are set by Supabase, our authentication provider, on our domain. They are sent only over HTTPS and are not readable by client-side scripts.
What we do not use
- No advertising or retargeting cookies
- No third-party analytics cookies
- No social media pixels
- No fingerprinting or cross-site tracking
Because we set only strictly necessary cookies, no consent banner is required under the EU ePrivacy Directive or the UK PECR. If we ever add optional analytics, we will ask for your consent first and update this page.
Local storage
The app stores a small amount of data in your browser's local storage — such as your theme preference and draft text you have not yet saved — so the app works the way you left it. This stays on your device and is not transmitted to us.
Managing cookies
You can clear or block cookies in your browser settings. Blocking the two cookies above will sign you out and prevent you from signing back in, since they are how the session works.
The iOS app
The native app uses the same session mechanism inside its embedded browser view. It does not use advertising identifiers and does not ask to track you across other companies' apps or websites.
Questions: privacy@marlojournal.com