Legal
Cookie Policy
Every cookie and browser-storage entry Blank sets, what each one is for and how long it lasts. All of them are needed for something you asked for.
Last updated 23 September 2026
1.In short
Blank sets only cookies and browser-storage entries that are strictly necessary — to keep you signed in, protect the sign-in forms, finish connecting an integration, and remember your theme. There are no advertising, analytics or cross-site tracking cookies, and no third-party cookies on our pages. Product analytics are measured on our server; see the Privacy Policy.
2.What we set on this site
Over HTTPS, the sign-in cookies carry a __Secure- or __Host- prefix on their names; the list shows the base name.
authjs.session-token- Type
- Cookie
- Purpose
- Keeps you signed in. A signed, encrypted token holding your account id and role — nothing else. May be split into numbered parts (.0, .1) if it grows.
- Lasts
- 30 days, renewed while you use the product; removed when you sign out
- Category
- Strictly necessary
authjs.csrf-token- Type
- Cookie
- Purpose
- Protects the sign-in and sign-out forms from being submitted by another site.
- Lasts
- Session (until the browser closes)
- Category
- Strictly necessary
authjs.callback-url- Type
- Cookie
- Purpose
- Remembers which page to return you to after signing in.
- Lasts
- Session
- Category
- Strictly necessary
authjs.pkce.code_verifier, authjs.state- Type
- Cookie
- Purpose
- Set only while you sign in with Google, to prove the reply from Google belongs to the sign-in you started.
- Lasts
- 15 minutes, deleted when sign-in completes
- Category
- Strictly necessary
supabase_connect_next- Type
- Cookie
- Purpose
- Set while you connect your Supabase account, to return you to the page you started from.
- Lasts
- 10 minutes
- Category
- Strictly necessary
integration_connect- Type
- Cookie
- Purpose
- Set while you connect an integration such as GitHub or Cloudflare, to remember which one and where to return you.
- Lasts
- 10 minutes
- Category
- Strictly necessary
theme- Type
- Browser storage
- Purpose
- Your light, dark or system theme choice. Stored in your browser and never sent to us.
- Lasts
- Until you change it or clear site data
- Category
- Strictly necessary
blank:chat-width- Type
- Browser storage
- Purpose
- The width you dragged the builder's chat panel to. Stored in your browser only.
- Lasts
- Until you clear site data
- Category
- Strictly necessary
3.On sites people publish with Blank
Published sites run on their own domains and are their owners’. The hosting adds only this, and only to a site its owner has protected with a password:
blank_unlock- Purpose
- Set on a visitor's browser by a password-protected published site after the right password is entered. It holds a signature, not the password.
- Lasts
- 30 days, or until the owner changes the password
Anything else a published site stores — for example a Supabase sign-in session — is set by the site’s own code and described, if at all, by its owner.
4.Your choices
You can block or delete cookies in your browser settings. Blocking the sign-in cookies means you cannot stay signed in; clearing browser storage resets your theme and panel width. Because nothing here is used for tracking, there is nothing further to opt out of.
5.Questions
Write to [email protected]. If we ever add a cookie that is not strictly necessary, this page will change first and we will ask before setting it.