# Cookie Policy

> Canonical: https://discry.ai/legal/cookies · Markdown mirror: https://discry.ai/legal/cookies.md

Effective 2026-09-22 · Version 1 · Version tag 2026-09-22.1

Operator: Discry LLC, a New York limited liability company. Legal contact: legal@discry.ai.

**Defined terms used.** Discry, Operator, Site, Scan, Account, and Fix Kit have the meanings given in the Terms of Use. Badge has the meaning given in the API, MCP and Data License Terms. Controller has the meaning given in the Privacy Policy. In this policy, "Storage" means any information placed on your device or read from it, whether by a cookie, browser local storage, session storage, a pixel, a script, or any similar method.

## 1. Who we are and what this policy is

1.1 The Site at https://discry.ai is operated by Discry LLC, a New York limited liability company (the Operator). You can reach us about this policy at legal@discry.ai.

1.2 This policy is a notice incorporated by the Terms of Use. It explains what Storage the Site places on your device, why, and what you can do about it. It does not create rights or obligations beyond those in the Terms of Use and the Privacy Policy. Disputes are governed by section 14 of the Terms of Use.

1.3 The law behind this policy covers more than the word "cookie". The UK Privacy and Electronic Communications Regulations (regulation 6 and Schedule A1) and Article 5(3) of the EU ePrivacy Directive apply to storing information on, or reading information from, a visitor's device by any method. This policy therefore covers cookies, local storage, session storage, and anything similar.

## 2. The short version

2.1 The Site sets no cookie and no other Storage until you sign in. Once you sign in, the only Storage on your device is the set of first-party session cookies that keep you signed in.

2.2 The Site's analytics tool, PostHog, runs without cookies, without local or session storage, and without session replay.

2.3 Because the only Storage the Site ever sets is strictly necessary to provide a service you asked for (staying signed in), the Site does not show a cookie banner and does not ask for consent to Storage. Section 6 explains why.

## 3. What cookies and similar Storage are

3.1 A cookie is a small text record that a website asks your browser to keep and to send back on later requests to the same site. Local storage and session storage are browser features that let a site keep data on your device without sending it back automatically. Session storage is cleared when the tab closes; local storage and cookies can persist for as long as the site specifies or until you delete them.

3.2 First-party Storage is set by the site you are visiting. Third-party Storage is set by another domain whose content or script the site loads. Strictly necessary Storage is Storage without which a service you explicitly requested cannot be delivered. Storage that is merely useful, convenient, or useful only to the operator is not strictly necessary and needs consent.

## 4. What the Site actually sets

4.1 The table below is the complete inventory. Completeness rests on the Site's code: no code in the Site writes to local storage, session storage, or `document.cookie`, and every cookie or storage key is set by one of two named libraries, the Supabase auth library and the PostHog library. The result was then confirmed in a browser on the home page and the Scan page (section 9). It is not copied from a vendor template.

| Storage | Set by | When | Purpose | Lifetime | Party | Basis |
|---|---|---|---|---|---|---|
| Session cookies named with the prefix `sb-` (the Supabase auth cookie family, which may be split across several numbered cookies) | The `@supabase/ssr` library, through the Site's middleware and server code | Only after you sign in with GitHub, Google, or a magic link | Carries your signed-in session so that pages such as `/account` and scan claiming work | 30 days, set by Discry rather than left at the library default. The cookie is refreshed on every page request while you stay signed in, so the 30 days run from your last activity, not from when you signed in. The other attributes come from the library: `SameSite=Lax`, path `/`. Discry has not yet measured the exact values on the live site; see section 9 | First party (discry.ai) | Strictly necessary: authentication for a service you requested |
| Short-lived sign-in handshake cookies with the same `sb-` prefix | The same library | During the sign-in redirect only | Verifies that the sign-in that comes back from GitHub, Google, or the magic link is the one you started | Cleared by the library when sign-in completes | First party | Strictly necessary: security of the sign-in you requested |
| PostHog analytics cookies (`ph_*`) | None | Never | Not applicable | Not applicable | Not applicable | Not applicable: PostHog runs in memory only and sets no cookie and no local or session storage key |
| Local storage or session storage keys of any kind | None | Never | Not applicable | Not applicable | Not applicable | No code in the Site writes to local storage, session storage, or `document.cookie` |
| Vercel infrastructure cookies | The hosting platform, if at all | Unknown | Would exist only to deliver the Site (routing and protection of deployments) | Set by Vercel, not by Discry | First party if set | Nothing in the Site's code configures one. Platform cookies cannot be detected by a check against a local build, so this row is resolved by the production re-check in section 9; if one is found on the live site it is listed here as strictly necessary for delivery |

4.2 Cookie names and attributes for the `sb-` family are set by the `@supabase/ssr` library and the Supabase project settings, and the Site's code passes through what the library supplies. The lifetime is the exception: the Site sets it to 30 days, in place of the library's much longer default. The session cookie is re-issued on every request the middleware handles, so a signed-in visitor's cookie is continuously refreshed and the 30 days run from the last request, not from the sign-in. A session left idle for 30 days expires on its own.

4.3 You can sign out. The Account page carries a "Sign out" control that clears the `sb-` cookies and returns you to the home page. Deleting the `sb-` cookies in your browser (section 8) does the same thing. The Site still has no account deletion route: to close an Account, email legal@discry.ai, as the Privacy Policy describes.

## 5. Analytics without cookies

5.1 PostHog is the only analytics tool on the Site. There is no Google Analytics, Google Tag Manager, Meta pixel, or advertising tag. PostHog sends to servers in the United States.

5.2 PostHog is configured so that it keeps its state only in the memory of the open page. It writes no cookie and no local or session storage key. Any identifier it generates exists only while the page is open and is gone when you close or reload it, so it cannot recognise your browser on a later visit.

5.3 Session replay is off. No recording of your screen, clicks, or typing is made. Automatic capture of clicks and form interactions is off. Query strings and hash fragments are stripped from page and referrer URLs before any event leaves your browser, so parameters such as scan domains or tokens in a URL are not sent to PostHog. Only ten named event properties, with string, boolean, or string-array values, are ever mirrored to PostHog; the Site's own database remains the record of events.

5.4 If the Site is deployed without a PostHog key, PostHog does not load at all and nothing is sent.

5.5 Cookieless does not mean invisible. When your browser sends an event to PostHog, PostHog's server receives that request, including your IP address and browser headers, in the same way any server you connect to does. What PostHog receives and how long it is kept is described in the Privacy Policy, which is the document for that question. This policy is about Storage on your device, and on that question the answer is: none.

## 6. Why there is no cookie banner

6.1 Consent is required before Storage is set or read unless the Storage is for the sole purpose of transmitting a communication, or is strictly necessary to provide a service the visitor explicitly requested. That is the rule in Article 5(3) of the ePrivacy Directive and in regulation 6 and Schedule A1 of the UK Regulations. Authenticating a user who has asked to sign in is a named example of strictly necessary Storage in the UK Schedule.

6.2 Applying that rule to the inventory in section 4: the `sb-` cookies exist only because you chose to sign in and only so that you stay signed in; they are set after your request, not before, and they serve you rather than Discry. Nothing else is set by the Site's code. There is therefore no non-essential Storage for a banner to gate, and a banner asking consent for nothing would be noise.

6.3 The absence of a banner is a consequence of the configuration, not a policy choice that overrides it. If the Site ever adds Storage that is not strictly necessary, consent will be asked before that Storage is set, and this policy will change first (section 10).

6.4 The Site does not currently read or act on the Global Privacy Control signal, because it sets no Storage that the signal would need to switch off. We have not sold personal information and have not shared it for cross-context behavioural advertising, and use no advertising technology.

## 7. Pages and requests that are not on discry.ai

7.1 **Sign-in providers.** When you sign in with GitHub or Google you are sent to their pages. Any cookies set there are set on their domains under their own notices. The Site requests no extra permission scopes from either provider.

7.2 **Stripe checkout.** A Fix Kit purchase happens on a checkout page that Stripe hosts on its own domain for Sold through Link, LLC, the merchant of record; the Site sends you there and you are sent back afterwards. No Stripe script is loaded on discry.ai, so no Stripe cookie is set on this Site. Storage on the checkout page is governed by Stripe's and Link's own cookie notices.

7.3 **Fonts.** The Site serves its typefaces from discry.ai itself. Loading a page contacts no third-party font host, so no font host can set a cookie or Storage through the Site.

7.4 **Badges and machine surfaces.** Badges are static image files and the data endpoints are plain responses; neither carries a script, so embedding or calling them sets no Storage in the browser of a visitor to another site.

7.5 **Email.** Discry sends only transactional email, through Resend. We do not intentionally use tracking pixels in email: the Site's code passes no tracking option and the templates contain no pixel. Whether Resend's own open or click tracking is switched on for the sending domain is a setting outside the code that we have not yet confirmed; the fact sheet records this as an open item.

## 8. How to control Storage in your browser

8.1 Every major browser lets you view, block, and delete cookies and site data, either for all sites or for discry.ai alone. The setting is usually under Privacy, Security, or Site data. Your browser's help pages have the current steps.

8.2 What happens if you do: blocking or deleting the `sb-` cookies signs you out, and the Site will not let you claim scans or view your Account until you sign in again. It is not the only way to sign out: the "Sign out" control on the Account page clears the same cookies for you, and a session left idle for 30 days expires by itself. Nothing else on the Site changes, because nothing else on the Site depends on Storage. Blocking third-party cookies has no effect on the Site, which sets none.

8.3 You do not need to opt out of analytics Storage, because there is none. If you want to stop analytics requests entirely, a content blocker that blocks `us.i.posthog.com` will do so without breaking the Site.

## 9. How this inventory was checked and how you can check it

9.1 Before this policy was written, a pre-production build of the Site was loaded in a browser with analytics enabled, on the home page and the Scan page: `document.cookie` was empty, and local storage and session storage held no keys. That check covers what the Site's own code and libraries set; it cannot see cookies the hosting platform might add, which is why the check is repeated against the live site before each version of this policy is published. Under the Site's code, the only Storage a visitor can receive is the `sb-` session cookie family, and only after signing in.

9.2 You can repeat this. Open your browser's developer tools, choose the Application or Storage panel, and look at Cookies, Local Storage, and Session Storage for discry.ai. Signed out, all three should be empty. Signed in, you should see only cookies whose names start with `sb-`. If you see anything else, tell us at legal@discry.ai with the name of the item and the page you were on, and we will correct either the Site or this policy.

## 10. Changes to this policy

10.1 This policy is re-checked whenever the Site's analytics configuration, authentication library, or hosting changes, and whenever a new script or embed is added. Analytics settings are compiled into the Site at build time, so a configuration change takes effect only on a new deployment, and this policy is reviewed against each such deployment.

10.2 Each version carries an effective date and version number. When the version changes, the previous version is kept unchanged in Discry's legal archive and is available on request to legal@discry.ai, so you can see what changed. Material changes that would introduce non-essential Storage are made only with consent asked first (section 6.3).

## 11. Contact

11.1 Questions about this policy, or a report of Storage this policy does not list, go to legal@discry.ai. Postal address: 418 Broadway, Suite 10855, Albany, NY 12207.

11.2 For how personal data is handled, including data sent to PostHog, Supabase, Vercel, Stripe, and Resend, and for your rights as a data subject, see the Privacy Policy, where the Controller is identified.
