Cookies
Last updated 4 October 2026
We only set cookies the service needs to work, so there is no consent banner. We use no advertising, tracking, or analytics cookies.
| Name | Why | How long |
|---|---|---|
| sb.session | Keeps you signed in. Holds a random token; the matching record is stored hashed. | 30 days |
| authjs.csrf-token, authjs.state, authjs.pkce.code_verifier, authjs.callback-url | Protect sign-in with Discord or GitHub from forgery and send you back where you started. | Until sign-in finishes |
| sb-connect-nonce, sb-connect | Protect the Add to Discord flow and remember which channel picker you were using. | 10 to 15 minutes |
| sb-theme | Remembers light or dark mode. Only set if you change it. | 1 year |
On HTTPS the session cookie is named __Secure-sb.session. All of these cookies are first party, and the session cookie cannot be read by scripts.
Bot checks on forms
The abuse report form uses Cloudflare Turnstile to tell people from bots. It runs in a frame from Cloudflare and follows Cloudflare's privacy policy.
More about what we collect is in the Privacy Policy.