1. What this page covers
This page explains the cookies and similar browser storage used by soloop. It sits next to the Privacy Policy, which covers the larger data picture: account data, project context, files, connected accounts, agents, logs, and deletion.
Cookies and browser storage are small records stored by your browser. They can keep you signed in, remember product state, complete OAuth flows, protect the service, and help us debug failures.
2. Cookies we use today
The current product uses necessary cookies. These are needed for login, session refresh, account checks, and security. Turning them off can break sign-in or workspace access.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| sb-* auth cookies | Supabase and soloop | Keeps you signed in, refreshes sessions, and lets protected workspace routes check account access. | Session-based. Cleared by sign-out, expiry, or browser cleanup. |
| OAuth state records | soloop server | Finishes account connection flows for Twitter/X, Reddit, GitHub, Stripe, and similar integrations. | Short-lived. Used to complete or reject the connection attempt. |
| Request and security logs | soloop and infrastructure providers | Records IP address, user agent, path, timestamp, errors, and performance data for security, abuse checks, and debugging. | Kept only as long as needed for operation, security, billing, support, or legal reasons. |
3. Browser storage
soloop also uses local browser storage for lightweight interface state. This is not used to sell data or build ad profiles.
Clearing browser storage can reset UI state. It should not delete server-side projects, chats, tasks, files, connected-account records, or billing records.
Workspace state
Active thread, sent-task drawer state, inbox read markers, auto-mode preference, and column width.
Start and setup state
Landing-page project input and pending GitHub project setup state so a flow can resume after sign-in or authorization.
Debug or preview state
Local-only state used by development or preview surfaces, such as paid preview state in debug pages.
4. Third-party providers
soloop uses services such as Supabase, AI model providers, TokenRouter, Anthropic, Vercel Sandbox, Stripe, X/Twitter, Reddit, GitHub, Apify, hosting providers, and email providers.
Stripe processes subscription billing on Stripe-hosted Checkout and Billing Portal pages. We do not receive or store full card numbers or CVC. Stripe may set or read its own cookies on those pages under its policy.
When a feature needs one of those services, the provider may receive request data and may set or read cookies on its own site. Its own policy controls that provider-side behavior.
If you approve a connected-account action, the external service can also keep logs, tokens, account records, rate-limit data, or abuse-prevention records under its own rules.
5. Cookies we do not use today
We do not use marketing cookies, ad retargeting cookies, third-party interest-based ad cookies, or cookie-based sale of personal data in the product today.
If we add analytics cookies, marketing cookies, or a consent banner later, we will update this page before relying on those cookies where law requires notice or choice.
6. Your choices
You can block or clear cookies in your browser. Necessary cookies are tied to login and workspace access, so blocking them can sign you out or stop the app from working.
You can clear local browser storage to reset local UI state. You can revoke connected accounts in the external service, and you can ask soloop to disconnect or delete related records through the product's support channel.
We retain cookie-linked security and billing logs only as long as needed for operation, fraud prevention, accounting, disputes, or legal duties. When those records are no longer needed, we delete or anonymize them where feasible.
7. Changes
We update this Cookie Policy when the product, integrations, cookie use, browser storage, or legal requirements change.
If a change affects your choices, we will post the updated page or use an in-product notice.
8. Contact
For cookie, privacy, security, deletion, export, or account-access requests, use the email link below.
Soloop, Inc. is responsible for this policy. Postal address: 6357 Joaquin Murieta Ave, Newark, CA 94560, United States. Email: [email protected].
[email protected]