Cookie Policy

Last updated: June 11, 2026

This Cookie Policy explains how Dream Industria LLC ("we," "us," or "our"), doing business as Supora, uses cookies and similar technologies when you visit supora.io or use our customer support platform (the "Service"). It explains what these technologies are, why we use them, and your choices for controlling them.

This policy should be read alongside our Privacy Policy, which describes how we handle personal information more broadly.

1. What are cookies and similar technologies?

A cookie is a small text file that a website stores on your device when you visit it. Cookies let a site remember your actions and preferences (such as being signed in) across pages and visits.

We also use similar technologies that are not technically cookies but serve comparable purposes:

  • Local storage (localStorage) - a browser store that lets a site save data on your device. Unlike a cookie, it is not sent to a server with every request, but it can persist information across sessions. We treat local storage the same way we treat cookies for the purposes of this policy and applicable law (such as the EU/UK ePrivacy rules).

Wherever this policy refers to "cookies," it also covers these similar technologies unless we say otherwise.

2. How we use these technologies

We use cookies and similar technologies for two purposes only:

  • To make the Service work - keeping you signed in, securing your session, and supporting core features. These are strictly necessary.
  • To understand how the Service is used - basic, privacy-respecting product analytics so we can improve the Service.

We do not use cookies for advertising, ad targeting, or cross-site tracking, and we do not sell information collected through cookies. We do not share cookie data with advertising networks or data brokers.

3. Cookies we use

Strictly necessary cookies

These cookies are required for the Service to function and cannot be switched off in our systems. They are set in response to actions you take, such as signing in. You can block them through your browser, but parts of the Service will not work.

We sign you in with a magic link or your Google account (no passwords), and authentication is handled by @auth/core. The following cookies support sign-in and session security:

Cookie Purpose Type Duration
authjs.session-token Keeps you signed in to your account after you click your magic link. First-party, strictly necessary Session / up to 30 days
authjs.csrf-token Protects sign-in and form submissions against cross-site request forgery. First-party, strictly necessary Session
authjs.callback-url Remembers where to return you after sign-in completes. First-party, strictly necessary Session

In production (HTTPS), these cookies carry the secure-prefixed names __Secure-authjs.session-token, __Host-authjs.csrf-token, and __Secure-authjs.callback-url, with the Secure, HttpOnly, and SameSite attributes set.

Remembering your consent choice. When you make a choice in our consent banner, we save that choice in your browser's local storage so we don't have to ask you again on every visit. This record is strictly necessary - it is how we honor your preference - and is itself exempt from consent.

Sign-in with Google

If you choose to sign in using your Google account, the authentication flow uses short-lived cookies to keep the exchange secure:

Cookie Purpose Type Duration
authjs.pkce.code_verifier Secures the OAuth exchange with Google (PKCE). First-party, strictly necessary A few minutes (sign-in only)
authjs.state Prevents tampering during the Google sign-in flow. First-party, strictly necessary A few minutes (sign-in only)
authjs.nonce Validates the Google (OpenID Connect) response to prevent replay. First-party, strictly necessary A few minutes (sign-in only)

Once you are signed in, your session is maintained by the strictly necessary cookies listed above.

Separately, Google sets its own cookies on its own domains (such as accounts.google.com) when you authenticate. These are controlled by Google, not by us, and are governed by Google's Privacy Policy. We do not control or have access to them.

4. Analytics - local storage, not cookies

We use Mixpanel for basic product analytics to understand how the Service is used (for example, which features are used and where users encounter problems) so we can improve it.

Mixpanel is configured to store its data in your browser's local storage, not in cookies. This data uses a randomly generated identifier to distinguish sessions; it is not used to identify you personally for advertising and is not combined with advertising profiles.

Because local storage is treated like a cookie under applicable privacy laws, we disclose it here and, where required, request your consent before enabling analytics (see section 6).

5. Your choices

Consent

Where required by law (for example, in the EU, UK, and similar jurisdictions), we ask for your consent before using non-essential technologies such as analytics. Strictly necessary cookies do not require consent because the Service cannot function without them.

Where a consent banner is shown, you can accept or decline non-essential technologies, and you can change your choice at any time using the controls provided on the site.

Browser controls

Most browsers let you view, manage, block, and delete cookies through their settings, and clear local storage. The steps differ by browser:

If you block or delete strictly necessary cookies, you will be signed out and core features of the Service will not work.

Do Not Track and Global Privacy Control

Because there is no finalized industry standard for "Do Not Track" (DNT) browser signals, we do not currently respond to them. Our position on browser privacy signals is described further in our Privacy Policy.

6. Changes to this policy

We may update this Cookie Policy from time to time to reflect changes to the technologies we use or for legal or operational reasons. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review it periodically.

7. Contact

If you have questions about this Cookie Policy or our use of cookies and similar technologies, contact us at privacy@supora.io, or by post at:

Dream Industria LLC
30 N Gould St, Ste R
Sheridan, WY 82801
United States