How SkromaPASS uses cookies
This policy explains how SkromaPASS uses cookies and similar technologies to improve your user experience and ensure the proper functioning of the service.
A cookie is a small text file placed on your device (computer, smartphone, tablet) when you visit a website. Cookies allow the site to remember your preferences and improve your experience.
Note: Cookies cannot damage your device or run programs. They do not contain viruses.
These cookies are essential for the website to function and cannot be disabled. They are generally set in response to your actions (login, preferences).
| Cookie | Purpose | Duration |
|---|---|---|
| next-auth.session-token | Maintains your login session | 30 days |
| next-auth.csrf-token | Protection against CSRF attacks | Session |
| next-auth.callback-url | Redirect after login | Session |
| __Secure-next-auth.session-token | Secure session (HTTPS) | 30 days |
These cookies do not collect any personally identifiable information and are necessary for you to use SkromaPASS.
Cloudflare Turnstile is used on our forms to distinguish humans from automated bots. It may set a temporary token during verification.
| Cookie | Purpose | Duration |
|---|---|---|
| cf_clearance | Cloudflare anti-bot verification | Session |
SkromaPASS respects your privacy and does not deploy any of the following cookies :
In addition to cookies, SkromaPASS uses your browser's local storage for:
Important: Your passwords are NEVER stored in plain text in Local Storage. All sensitive data is encrypted.
You can configure your browser to refuse cookies or be notified when a cookie is set:
If you disable all cookies, you will no longer be able to log in to SkromaPASS as session cookies are required for the service to function.
The SkromaPASS browser extension uses browser APIs to:
The extension collects no browsing data and only communicates with SkromaPASS servers.
SkromaPASS uses third-party services for hosting and infrastructure:
May collect technical logs (IP address, user-agent) to ensure the service operates correctly.
Vercel Privacy PolicyHosts your encrypted data in European datacenters (GDPR compliant).
Supabase Privacy PolicyTransactional email service (verification, notifications, password reset).
Resend Privacy PolicyProtects forms against automated submissions. Only processes signals necessary for verification, with no advertising or cross-site tracking.
Cloudflare Privacy PolicyCookie-free, cross-site tracking-free analytics. Collects anonymous statistics (page views, performance) via a JavaScript beacon. No personally identifiable data is collected.
Learn more about Cloudflare Web AnalyticsWe reserve the right to modify this cookie policy. Any changes will be communicated on this page along with an updated last-modified date.
For any questions regarding our use of cookies, contact us at mattbuchs25@gmail.com
Last updated: March 7, 2026