Browser storage
Cookie Notice
Bothlo currently uses only storage needed to operate and protect the service. The audited code contains no advertising or audience-analytics tracker.
What is used
| Technology | Purpose | Duration/control |
|---|---|---|
| Supabase Auth browser storage | Keeps the signed-in session and securely refreshes it. | Essential; follows the Auth session and ends on logout, expiry or browser clearing. |
| Bothlo sessionStorage | Stores a safe post-login return page and prevents duplicate parental-consent resend during the same tab session. | Essential; normally cleared when the tab/session closes. |
| Optional Bothlo localStorage configuration | Developer-only public Supabase URL/key override. It contains no password or secret. | Until manually cleared; not required in correctly configured production. |
| PWA Cache Storage | Caches same-origin interface files and an offline page. | Replaced by versioned cache updates. Supabase API/Auth, user data and config.js are excluded. |
| Cloudflare Turnstile | Bot and abuse prevention on Auth and public illegal-report forms, using browser/device/network signals and necessary storage where required. | Security-only. Exact provider retention and widget settings: [POTWIERDZIĆ W KONCIE CLOUDFLARE]. |
| Google OAuth | Google may use its own cookies/storage when a user deliberately chooses Continue with Google. | Controlled by Google and the user's Google/browser settings. |
External resources
Google Fonts and jsDelivr currently receive ordinary network-request information when loading fonts and the Supabase browser library. They are not configured by Bothlo as advertising or analytics, but self-hosting should be considered before launch.
No “Accept all” banner
The audited version does not intentionally set non-essential analytics or advertising cookies. For that reason it does not show a misleading “Accept all” banner. If non-essential technology is added later, Bothlo must update this notice and collect consent before using it where required.
Your controls
You can clear site data in browser settings, but doing so signs you out and may remove offline files. Blocking Turnstile or required storage may stop protected forms from working. Contact contact@bothlo.com with questions.