Legal

Cookie Policy

Every cookie and browser-storage entry Blank sets, what each one is for and how long it lasts. All of them are needed for something you asked for.

Last updated 23 September 2026

1.In short

Blank sets only cookies and browser-storage entries that are strictly necessary — to keep you signed in, protect the sign-in forms, finish connecting an integration, and remember your theme. There are no advertising, analytics or cross-site tracking cookies, and no third-party cookies on our pages. Product analytics are measured on our server; see the Privacy Policy.

2.What we set on this site

Over HTTPS, the sign-in cookies carry a __Secure- or __Host- prefix on their names; the list shows the base name.

  • authjs.session-token

    Type
    Cookie
    Purpose
    Keeps you signed in. A signed, encrypted token holding your account id and role — nothing else. May be split into numbered parts (.0, .1) if it grows.
    Lasts
    30 days, renewed while you use the product; removed when you sign out
    Category
    Strictly necessary
  • authjs.csrf-token

    Type
    Cookie
    Purpose
    Protects the sign-in and sign-out forms from being submitted by another site.
    Lasts
    Session (until the browser closes)
    Category
    Strictly necessary
  • authjs.callback-url

    Type
    Cookie
    Purpose
    Remembers which page to return you to after signing in.
    Lasts
    Session
    Category
    Strictly necessary
  • authjs.pkce.code_verifier, authjs.state

    Type
    Cookie
    Purpose
    Set only while you sign in with Google, to prove the reply from Google belongs to the sign-in you started.
    Lasts
    15 minutes, deleted when sign-in completes
    Category
    Strictly necessary
  • supabase_connect_next

    Type
    Cookie
    Purpose
    Set while you connect your Supabase account, to return you to the page you started from.
    Lasts
    10 minutes
    Category
    Strictly necessary
  • integration_connect

    Type
    Cookie
    Purpose
    Set while you connect an integration such as GitHub or Cloudflare, to remember which one and where to return you.
    Lasts
    10 minutes
    Category
    Strictly necessary
  • theme

    Type
    Browser storage
    Purpose
    Your light, dark or system theme choice. Stored in your browser and never sent to us.
    Lasts
    Until you change it or clear site data
    Category
    Strictly necessary
  • blank:chat-width

    Type
    Browser storage
    Purpose
    The width you dragged the builder's chat panel to. Stored in your browser only.
    Lasts
    Until you clear site data
    Category
    Strictly necessary

3.On sites people publish with Blank

Published sites run on their own domains and are their owners’. The hosting adds only this, and only to a site its owner has protected with a password:

  • blank_unlock

    Purpose
    Set on a visitor's browser by a password-protected published site after the right password is entered. It holds a signature, not the password.
    Lasts
    30 days, or until the owner changes the password

Anything else a published site stores — for example a Supabase sign-in session — is set by the site’s own code and described, if at all, by its owner.

4.Your choices

You can block or delete cookies in your browser settings. Blocking the sign-in cookies means you cannot stay signed in; clearing browser storage resets your theme and panel width. Because nothing here is used for tracking, there is nothing further to opt out of.

5.Questions

Write to [email protected]. If we ever add a cookie that is not strictly necessary, this page will change first and we will ask before setting it.