Cookies
Last updated: 20 April 2026
Byron uses a short list of strictly necessary cookies to keep you signed in and to protect OAuth connections. We don't run advertising trackers, analytics, session replay, or cross-site tracking. Because every cookie we set is strictly necessary for the service you asked for, no consent banner is required under UK GDPR and the PECR. If that changes, we'll ask before setting non-essential cookies.
What we set
| Cookie | Purpose | Lifetime |
|---|---|---|
sb-*-auth-token | Keeps you signed in. Set by Supabase Auth. | Session + refresh |
zernio_oauth_state | CSRF protection during LinkedIn / X connection via Zernio. | 10 minutes |
linkedin_oauth_state | CSRF protection during the direct LinkedIn OAuth handshake. | 10 minutes |
x_oauth | CSRF + PKCE code verifier during the direct X (Twitter) OAuth handshake. | 10 minutes |
Third-party cookies
Stripe may set cookies on its own checkout pages when you subscribe — that happens on stripe.com, not on Byron, and is governed by Stripe's cookie policy. If you open our site via Telegram, Telegram and your operating system may handle in-app browser cookies outside our control.
Turning cookies off
You can block or delete cookies in your browser settings, but if you block the Supabase auth cookie you won't be able to sign in, and if you block the OAuth state cookies you won't be able to connect LinkedIn or X.
If we add analytics
If we later add analytics, product telemetry, or any non-essential cookie, we will put up a proper consent banner that blocks those scripts until you opt in — in line with UK GDPR and PECR guidance.
Contact
Questions? Email hello@getbyron.ai.