Free-preview cookie policy
Cookie Policy
CertLuna currently uses only cookies and similar browser-storage technologies that are necessary to authenticate approved learners, protect accounts, and deliver a secure free-preview session.
Necessary storage inventory
| Exact name or pattern | Provider | Storage type | Purpose | Strictly necessary? | Retention or expiry | Context |
|---|---|---|---|---|---|---|
__cf_bm | Cloudflare | HTTP cookie | Bot detection and abuse protection | Yes | 30 minutes after continuous inactivity | First party on certluna.com, issued by Cloudflare |
sb-hrzhyfrtjatboeagesct-auth-token-flow-<flow-id>-code-verifier | Supabase Auth, set by CertLuna | HTTP cookie | PKCE verifier for one pending Google sign-in flow | Yes | Maximum 30 minutes; deleted when the flow completes, fails, or is cancelled | First party |
sb-hrzhyfrtjatboeagesct-auth-token-flows-code-verifier | Supabase Auth, set by CertLuna | HTTP cookie | Index of pending PKCE flow identifiers | Yes | Maximum 30 minutes; deleted when the flow completes, fails, or is cancelled | First party |
sb-hrzhyfrtjatboeagesct-auth-token-code-verifier | Supabase Auth, set by CertLuna | HTTP cookie | Compatibility PKCE verifier slot | Yes | Maximum 30 minutes; deleted when the flow completes, fails, or is cancelled | First party |
sb-hrzhyfrtjatboeagesct-auth-token and chunked .0, .1, and later parts | Supabase Auth, set by CertLuna | HTTP cookie | Access and refresh session material for server-rendered requests | Yes | Browser lifetime up to 400 days; the server session may end or be revoked earlier | First party |
| Names vary according to the learner's Google session | Google-domain cookies and potentially other Google-controlled storage | Account selection, authentication, and Google security | Necessary for Google sign-in, but not controlled by CertLuna | Controlled by Google and the learner's Google/browser settings | Third party relative to CertLuna |
CertLuna does not create application keys in Local Storage or Session Storage and does not register application IndexedDB, Cache Storage, or service-worker storage. Learning history is stored server-side, not in browser storage. CertLuna does not receive or store your Google password.
Google sign-in
Choosing Google sign-in takes you to Google and may display a Supabase authentication domain as the application destination. Google may use cookies on its own domains under Google's policies to authenticate or select an account. CertLuna cannot read or manage those Google-domain cookies.
Cookie-free audience measurement
CertLuna uses Cloudflare Web Analytics to obtain aggregated page-view and performance measurements. This service does not set analytics cookies or use Local Storage to identify visitors. CertLuna does not currently install advertising, behavioral-tracking, or session-replay cookies. The consent experience and this policy will be reviewed before any non-essential browser-storage technology is introduced.
Provider settings and duration
CertLuna applies application-level session controls that require a new sign-in no later than 30 days after the session was first observed by the application, or after 7 days without a verified request. Provider or browser cookies may remain stored for longer, but their presence does not override these CertLuna limits or guarantee that a server session remains valid. Supabase's underlying project session settings, provider-controlled behavior, and concurrent-session limits must still be verified before broad or commercial launch.
Managing cookies
You can remove CertLuna cookies through your browser settings or use the application's sign-out control. Removing a necessary authentication cookie signs you out or prevents the secure account area from working until you authenticate again.
Questions and requests
Cookie-related questions can be sent to certluna@gmail.com. For account-data rights, follow the Privacy Requests procedure. Further information appears in the Privacy Policy and Legal Notice.
