Cookie Policy
Last updated June 5, 2026
Plain English Summary
We use two Supabase authentication cookies (to keep you logged in) and a few localStorage keys (to remember your colour theme and timezone). No advertising cookies. No tracking. No third-party analytics. That's it.
Cookies & Storage Used
| Name | Type | Purpose | Duration | Third Party | Necessary |
|---|---|---|---|---|---|
| sb-access-token | Authentication | Supabase Auth session token - keeps you logged in between page loads. Strictly necessary. | Session (cleared on sign-out) | Supabase Inc. | Yes |
| sb-refresh-token | Authentication | Supabase Auth refresh token - silently renews your session so you stay logged in. | Up to 7 days (configurable) | Supabase Inc. | Yes |
| cashundo-accent | Preference (localStorage) | Stores your chosen accent colour (HSL value) to prevent a visual flash on page load. | Persistent (until cleared) | None - local only | Pref. |
| cashundo-accent-rgb | Preference (localStorage) | Stores the RGB equivalent of your accent colour for CSS custom property injection. | Persistent (until cleared) | None - local only | Pref. |
| cashundo-timezone | Preference (localStorage) | Stores your selected or detected timezone for consistent date/time display across sessions. | Persistent (until cleared) | None - local only | Pref. |
| cashundo-clock-store | Preference (localStorage) | Zustand-persisted store for pinned world-clock timezones. | Persistent (until cleared) | None - local only | Pref. |
1. What Are Cookies & Local Storage?
Cookies are small text files placed on your device by a website. They are used to remember information about you between sessions. localStorage is a browser-based storage mechanism (not a cookie) that websites use to persist data on your device. Unlike cookies, localStorage data is never automatically sent to a server - it stays on your device. Cashundo uses a minimal combination of authentication cookies (set by Supabase) and localStorage keys (set by Cashundo) to operate the service. We do NOT use advertising cookies, tracking pixels, or third-party analytics cookies.
2. How We Use Cookies & Local Storage
Cashundo uses only two categories of cookies/storage: 1. Strictly Necessary (Authentication) These are Supabase authentication cookies (sb-access-token and sb-refresh-token). They are essential for you to log in and stay logged in. Without them, the Service cannot function. These cannot be opted out of while using the Service. 2. Preference / Functional (localStorage) These are localStorage keys used to remember your display preferences - accent colour, timezone, and pinned clocks. They prevent visual flashes on page load and maintain your personalisation between sessions. They do not track you across websites and are never transmitted to any server. We do NOT use: • Advertising or targeting cookies • Third-party analytics cookies (e.g. Google Analytics, Facebook Pixel) • Cross-site tracking cookies • Fingerprinting techniques Telegram Mini App note: The Telegram Mini App (telegram.cashundo.in) runs inside Telegram's WebView and does NOT use Cashundo's session cookies for authentication. Instead, every request is authenticated server-side using Telegram's cryptographically signed initData (HMAC-SHA256). The Mini App does not set any cookies or read your cashundo-auth session. Telegram's own WebView storage is governed by Telegram's Cookie Policy, not by this one.
3. Consent & Legal Basis
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian law: • Strictly necessary cookies (Supabase Auth) are processed on the basis of legitimate interest and contractual necessity - they are required to provide the Service you have requested. • Preference localStorage keys are processed on the basis of your consent, given implicitly when you customise your display settings. No personal data is stored in localStorage. By creating a Cashundo account and using the Service, you acknowledge and agree to the use of cookies as described in this policy.
4. Third-Party Cookies
Cashundo does not embed third-party advertising networks, social media widgets, or analytics SDKs that would place third-party cookies on your device. The only third-party cookie-setting service is Supabase Inc. (for authentication). Supabase's use of this data is governed by their own Privacy Policy and their Data Processing Agreement with Cashundo. If you use "Continue with Google" to sign in, Google may set its own cookies on their domain as part of their OAuth flow. These are governed by Google's Cookie Policy and are separate from Cashundo's cookies. If you use the Telegram Mini App (telegram.cashundo.in), Telegram's WebView may apply its own storage policies within that context. The Mini App itself does not set any cookies - authentication is handled entirely via server-side HMAC verification of Telegram's signed initData. Any storage Telegram uses within its WebView is governed by Telegram's Cookie Policy.
5. How to Manage or Delete Cookies
You can manage cookies through your browser settings: • Chrome: Settings → Privacy and security → Cookies and other site data • Firefox: Settings → Privacy & Security → Cookies and Site Data • Safari: Preferences → Privacy → Manage Website Data • Edge: Settings → Cookies and site permissions To clear Cashundo localStorage: 1. Open your browser's Developer Tools (F12) 2. Navigate to Application → Local Storage → your site 3. Delete any keys starting with "cashundo-" Note: Deleting authentication cookies will sign you out. Deleting localStorage keys will reset your display preferences (accent colour, timezone) to defaults on your next visit. Blocking all cookies will prevent you from logging in and using the Service.
6. Changes to This Policy
If we change the types or purposes of cookies/storage we use, we will update this policy and notify you via an in-app banner. The "Last Updated" date above reflects the most recent revision. Your continued use of the Service after the effective date of a revised Cookie Policy constitutes your acceptance of the changes.
7. Contact
For questions about our use of cookies or to exercise your data rights, contact: Email: cashundo.in@gmail.com Subject line: "Cookie Policy Query" Response time: Within 48 hours on business days.
