Legal
Cookie Policy
Last updated: June 22, 2026
This policy explains the cookies and similar browser storage Variafy uses. The short version: we use only what is strictly necessary to run the Service. We do not use advertising cookies, and we run no third-party analytics or tracking pixels.
1. What are cookies?
Cookies are small text files a site stores in your browser. "Local storage" is a related browser feature that keeps small values on your device. Some are essential for a site to function; others (which we don't use) track behaviour across sites.
2. What we use
| Name / type | Purpose | Category |
|---|---|---|
| Supabase auth session | Keeps you signed in to the cabinet. | Strictly necessary |
| OAuth state token | Security (CSRF protection) during Google Drive connection. | Strictly necessary |
Integration tokens (re_meta_token, re_gdrive_rt) — local storage | If you connect Meta / Google Drive, your own access tokens are kept in your browser so you can push creatives. Never sent to our servers. | Functional |
Consent & UI state (variafy_cookie_consent, re_job) — local storage | Remembers your cookie choice and your last job for page reloads. | Functional |
Strictly-necessary cookies don't require consent because the Service cannot work without them. We do not currently set any cookie that legally requires opt-in.
3. Analytics — not today, and only with consent later
We don't use analytics right now. If we ever add privacy-friendly analytics, it will load only after you accept via the cookie banner, and this page will be updated first.
4. Your choices
You can review or change your choice any time: . You can also block or delete cookies in your browser settings, though blocking the essential ones will stop you from signing in.
5. Contact
Questions: privacy@variafy.com.