Legal · Browser storage
Cookie and Local Storage Notice
Version prelaunch-cookies-rc3 · Updated 24 August 2026
Cookies are small values stored by the browser and sent with relevant web requests. Local storage stays in the browser and is not automatically sent with each request. Rafflux currently uses both only where needed for sign-in, security, fraud prevention and a preference you request.
Strictly necessary storage cannot be disabled through a marketing banner because the requested secure account flow would not work without it. You can block it in browser settings, but sign-in, verification and protected member pages may fail.
1. Authentication session cookies
Supabase Auth session cookies keep a verified user signed in and allow protected server pages to confirm the session. Their names can include a project-specific prefix and auth-token fragments. They contain signed session material rather than your readable password.
If Keep me signed in for 30 days is selected, Rafflux gives the authentication session cookie a maximum browser lifetime of 30 days, subject to earlier sign-out, expiry, revocation or provider security controls. If it is not selected, the session cookie is intended to end with the browser session. Private-browsing behavior is controlled by the browser and may end sooner.
- Purpose: authentication, session continuity and protected-route security.
- Legal/storage basis: necessary to provide the user-requested secure sign-in service.
- Recipient: Rafflux and Supabase as authentication provider.
2. Remember-device preference
The rafflux_remember_device cookie records whether the user chose a persistent session and an absolute expiry timestamp no later than 30 days after that choice. Authentication-cookie refreshes are capped to the remaining time and do not restart the 30-day period. A value of 0 or a session-only value means do not persist the authentication session for 30 days.
- Purpose: honor the user’s requested session duration.
- Maximum duration: 30 days when enabled; otherwise the browser session.
- Contains: a preference value, not an email, phone, password or OTP.
3. OTP security local storage
Rafflux uses two fixed local-storage records, one for email OTP protection and one for SMS OTP protection. They store cooldown timestamps, short request/verification leases, local attempt counts, opaque lease-owner and code-generation values, and whether a code was issued.
These records do not store an email address, phone number, account name or verification code. They support a visible 60-second resend cooldown, duplicate-request protection and a maximum of five local verification attempts per issued generation. Supabase, Resend and Twilio remain authoritative if the browser state is cleared or bypassed.
- Keys: rafflux-auth-email-otp-guard-v1 and rafflux-auth-sms-otp-guard-v1.
- Active timing: 60-second resend cooldown and 15-second request/verify leases; stale or implausible timestamps are discarded.
- Duration: the record can remain until browser data is cleared, but expired values no longer grant or block an action.
4. Temporary registration state
Rafflux does not intentionally persist names, Cyprus city or area, legal confirmations, marketing choice, email or phone in browser storage for the unfinished six-step registration draft. Closing or reloading before final completion clears those form answers. A legacy session-storage key may be removed defensively but is not used to restore personal registration answers.
5. Security and framework cookies
The hosting platform, browser and security providers may use short-lived technical values needed for request routing, bot protection, load balancing or abuse prevention. Rafflux must add any production value that is actually set to the maintained inventory before activation if it is not already covered here.
Cloudflare Turnstile is active on public account-creation, sign-in, password-recovery and phone-verification request surfaces. Its browser challenge processes technical signals such as the client IP address, TLS fingerprint, user-agent header, site key, associated origin and browser-environment signals to distinguish people from automated traffic. Cloudflare states that Turnstile does not access, store or transmit form entries, user communications or other page inputs.
Rafflux treats Turnstile's challenge and any necessary technical storage as strictly necessary security processing, not advertising or optional analytics. Turnstile pre-clearance is not enabled, so Rafflux does not use Turnstile to issue a first-party cf_clearance cookie. Cloudflare may change the technical operation of its service; the maintained inventory and this notice must be reviewed if Rafflux changes the widget configuration or Cloudflare introduces a new production storage value.
- Purpose: bot detection, credential-abuse prevention and protection of authentication requests.
- Provider: Cloudflare Turnstile; Supabase also validates Turnstile tokens on protected hosted-auth requests.
- Consent category: strictly necessary security; it is not controlled by the optional marketing preference.
6. Storage not currently used
The current launch scope does not intentionally set advertising, cross-site tracking, behavioural profiling, social-media advertising, heatmap, session-replay or non-essential analytics cookies. No banner should falsely claim those tools are active.
If Rafflux later adds non-essential analytics or advertising, it will identify the provider, exact purpose, data, duration and recipients and will obtain valid prior consent where required. The interface will make rejection and later withdrawal as clear as acceptance and will not use pre-ticked consent or a cookie wall for an unrelated service.
7. Browser controls and consequences
You can delete or block cookies and local storage in your browser. Doing so clears local cooldown state but does not override server/provider limits. Blocking authentication cookies can sign you out or prevent account verification and protected pages from working.
Signing out removes or expires the relevant authentication session. Clearing a remember-device preference does not necessarily revoke another active session; use sign out and contact support if you suspect unauthorized access.
8. Updates and contact
Rafflux reviews this inventory when providers or frontend storage change. Material additions are dated and, where consent is required, are not set before the corresponding choice is available.
Contact geobusiness05@outlook.com with a browser-storage, privacy or service question, or use the published Rafflux service telephone where appropriate.