Whiscret Cookie Policy
Last updated: 10 September 2026
This policy explains which cookies and similar browser-storage entries Whiscret (https://whiscret-production.up.railway.app, and any domain we later move to) places on your device, what they do and how long they last. It is part of our Privacy Policy. The controller is Talha Orak, reachable at talhaorak@gmail.com.
1. The short version
- We use only cookies that are strictly necessary to run Whiscret: keeping you signed in, protecting the Spotify/X account-linking flow, and remembering your cookie choice.
- We also keep two small preference entries in your browser's local storage: your theme and which side panels you collapsed.
- We use no advertising cookies, no tracking cookies and no third-party analytics. We do not embed third-party widgets, so Spotify and X do not set cookies on Whiscret.
- If we ever add optional analytics, it will run only if you chose "Allow analytics" in the cookie notice, and this policy will be updated first.
2. What cookies and local storage are
A cookie is a small text file a website stores in your browser and reads back on later visits. Local storage is a similar browser feature that keeps a value on your device until it is cleared; it is never sent to our server automatically. Both are covered by the same rules: Article 5(3) of the EU ePrivacy Directive, the GDPR, Turkish Law No. 6698 (KVKK) and the Turkish Personal Data Protection Board's Cookie Guideline.
3. Everything we store on your device
| Name | Kind | Set by | Purpose | Duration | Category |
|---|---|---|---|---|---|
sb-<project-ref>-auth-token (large values are split into sb-<project-ref>-auth-token.0, .1, ...) | Cookie | Whiscret (Supabase Auth) | Holds your sign-in session so you stay logged in between pages and visits | Until you sign out; refreshed while you use Whiscret | Strictly necessary |
sb-<project-ref>-code-verifier | Cookie | Whiscret (Supabase Auth) | Secures the one-time link in email confirmation and password-reset emails (PKCE) | Short-lived; removed once the link is used | Strictly necessary |
wsc_oauth_spotify_state | Cookie (HttpOnly) | Whiscret | Protects the Spotify account-linking flow against forged requests (CSRF) | 10 minutes, only during linking | Strictly necessary |
wsc_oauth_twitter_state, wsc_oauth_twitter_verifier | Cookie (HttpOnly) | Whiscret | Protects the X (Twitter) account-linking flow against forged requests and secures the code exchange (PKCE) | 10 minutes, only during linking | Strictly necessary |
wsc_consent | Cookie | Whiscret | Records your choice in the cookie notice (necessary or all) so we do not ask again | 12 months | Consent record (strictly necessary) |
theme | Local storage | Whiscret | Remembers whether you chose the light, dark or system theme | Until you clear browser storage | Preference |
app-settings | Local storage | Whiscret | Remembers which side panels (profile, people to follow, Spotify) you collapsed | Until you clear browser storage | Preference |
<project-ref> is the identifier of our Supabase project. The sb- cookies contain session tokens only; they do not track you across other websites.
4. Consent
- Strictly necessary cookies and storage do not require consent under Article 5(3) of the ePrivacy Directive, the EU data protection authorities' Opinion 04/2012 on cookie consent exemptions, and the Turkish Board's Cookie Guideline. That covers everything in the table above, including the consent-record cookie itself.
- The two preference entries are set only when you use the feature (switching theme or collapsing a panel), which is the kind of user-requested interface customisation that the same guidance treats as exempt.
- Because we use nothing else, the cookie notice you see is informational. The "Allow analytics" option stores your consent for optional analytics we may add in future. You can change your choice at any time by clearing the
wsc_consentcookie (see Section 5); the notice will then appear again.
5. How to control cookies
- Sign out to end your session cookie.
- Your browser lets you view, block and delete cookies and local storage for individual sites. Instructions: Chrome, Firefox, Safari and Edge each have this under Settings, Privacy.
- If you block the
sb-cookies you will not be able to stay signed in. If you block thewsc_oauth_*cookies you will not be able to link Spotify or X. Blocking local storage only resets your theme and panel layout.
6. Changes
We will update this policy if the cookies or storage we use change, and before adding any optional cookie. The date at the top shows the last change.
7. Contact
Talha Orak · talhaorak@gmail.com · Türkiye