Cookies & Local Storage
Incomplete policy — not final. Observed storage is documented below. Authenticated/payment browser journeys and the operator information remain incomplete. Reviewed 8 October 2026.
What the candidate application uses
This notice describes the V2.2 source audit, not an assurance that all hosting and third-party settings have been independently verified.
- Supabase authentication: the browser client persists session tokens in local storage under a project-specific auth key (normally sb-<project-ref>-auth-token). This keeps you signed in and supports token refresh. Treat it as sensitive. Logging out removes the local session; server-side session controls still apply.
- Appearance: qr-relay-appearance stores your requested Light, Dark or System setting in local storage until changed or browser data is cleared. New visitors use System. It is not used for tracking.
- Service worker: the application registers a worker; the current worker does not cache authenticated pages, QR payloads or network responses.
- Camera permission: your browser remembers its permission decision according to browser settings. QR Relay does not store camera video.
External requests and providers
The application loads Google Fonts, so your browser requests fonts from Google infrastructure. Supabase handles login and realtime connections. Stripe Checkout and the Customer Portal run on Stripe-hosted pages and may use their own security and payment technologies. Read-only visits to both the hosted site and qrrelay.bar observed the Cloudflare __cf_bm bot-protection cookie, with Secure, HttpOnly and SameSite=None attributes. Cloudflare documents a 30-minute inactivity lifetime. This security cookie is set by hosting infrastructure, not the QR Relay application.
No analytics, advertising or marketing tracking is imported by the audited product code. Unused component-library code is not evidence that its optional storage features run on this site.
Not yet confirmed: complete authenticated, recovery and Stripe Checkout/Portal browser journeys to identify any additional provider storage. A response-header audit alone cannot prove the complete browser inventory.
Consent assessment
The inspected app stores authentication state to deliver your requested login and your selected appearance preference. The observed hosting cookie serves bot protection. No optional advertising or analytics storage was found in the application code, so this update does not add a speculative consent banner. A full provider/browser journey audit is still required before concluding that every storage operation is exempt from consent. Any optional non-essential storage found must be blocked until the appropriate choice has been given.
Camera choices, zoom settings and diagnostic details are held in memory for the current page; the app does not persist or upload camera frames. No application sessionStorage use was found. Local storage has no built-in expiry: authentication data is refreshed or cleared by the auth client and appearance remains until changed or cleared. Browser-managed HTTP caches have their own controls.
Your controls
Change Appearance at any time using the page control. Log out before using a shared device. Browser settings let you clear site data or revoke camera permission; clearing site data may sign you out and reset preferences, but it does not delete your server account or cancel a subscription.
Technologies strictly necessary for a service you explicitly request can be exempt from prior cookie consent; other storage/access technologies normally require consent. If optional tracking is introduced, it must be assessed and an appropriate choice provided before activation. This update adds no marketing consent or tracking system. See the Privacy Policy for personal-data processing.