1. Our current approach
Vague.no currently intends to use cookies and similar browser storage only for authentication, security, user-requested preferences and short-lived interface state. We do not currently use advertising cookies, cross-site behavioural tracking, session replay or audience analytics that identify you individually.
We use Vercel Web Analytics to see aggregate usage such as page views and approximate visitor country. It does not set cookies, does not use a persistent identifier, and cannot be used to single out or follow an individual visitor.
Strictly necessary technology, and analytics that does not identify individuals, is used without consent where the law permits. If we introduce technology that does require consent, it will remain disabled until you make a valid choice, and rejecting it will be as easy as accepting it.
2. Storage used by Vague.no
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
Supabase authentication cookies (normally named using an sb-…-auth-token pattern
and sometimes split into numbered chunks) | Vague.no / Supabase | Keep you signed in, refresh your authenticated session and protect account access. | Session credentials expire or are refreshed automatically; persistent authentication ends when you sign out, delete the account, clear storage or the credential expires. |
| Cloudflare Turnstile cookies, tokens and device signals | Cloudflare | Distinguish legitimate requests from automated abuse during guest access and login. | For the short period needed to complete and validate the security challenge, subject to Cloudflare’s security settings. |
atlas-sound-muted | Vague.no local storage | Remember the sound preference you choose. | Until you change it or clear browser storage. |
quiz-panel-pos | Vague.no local storage | Remember the quiz-panel position after you move it. | Until overwritten or browser storage is cleared. |
quiz-results-transition | Vague.no session storage | Coordinate a visual transition from a completed quiz to its results. | Removed after use or when the browser session ends. |
3. Third-party connections
Even when a service does not set a cookie, connecting to it can disclose technical information such as your IP address, browser information and the page requested. Vague.no currently connects to:
- Supabase for authentication, application data and avatar storage;
- Vercel for hosting, delivery and cookieless aggregate web analytics;
- Cloudflare Turnstile on guest-access and login flows;
- Sentry when the application reports a technical error; and
- Google or Apple when you actively choose that sign-in provider.
Fonts are self-hosted, so no font-related connection is made to Google or any other third party.
See the Privacy Notice for purposes, legal bases and recipients.
4. Your controls
You can delete or block storage using browser controls, but blocking authentication storage may prevent login and saved progress from working. You can change the sound preference from the Vague.no interface. If optional storage is introduced, a persistent privacy-settings control will be added to let you withdraw consent as easily as you gave it.
5. Contact
Questions about cookies or storage can be sent to hi@vague.no.