Cookie Policy

Last updated: 26 June 2026

1. About This Policy

This Cookie Policy explains how Kinora uses cookies and similar technologies on our website. It should be read alongside our Privacy Policy, which covers email tracking and other forms of data processing not described here.

2. What Cookies and Similar Technologies Are

Cookies are small text files placed on your device when you visit a website. Similar technologies, such as local storage and session storage, can also store information in your browser. These technologies can be used to make a website work, keep you signed in, remember temporary choices, or help protect the service.

3. What We Use and Why

We use two categories of cookies and browser storage:

  • Strictly necessary: cookies and storage required for authentication, security, and hosting infrastructure. These cannot be switched off and do not require consent under UK cookie rules.
  • Feature storage: limited first-party browser storage used only for your convenience. This data stays in your browser, is never shared with third parties, and is not used for profiling or advertising. It does not affect core website functionality if cleared.

We do not use analytics cookies, advertising cookies, cross-site tracking cookies, or cookies that build behavioural profiles. If we add any non-essential cookies in future, we will update this policy and ask for consent before setting them.

4. Cookies and Storage We Use

The table below lists the cookies and browser storage currently in use on kinora.health. Supabase auth cookie names include your project reference and may appear as multiple chunks (e.g. sb-[project]-auth-token.0).

Name / KeyProviderPurposeTypeDurationNecessary
sb-[project]-auth-tokenSupabaseMaintains your login session and allows it to refresh securelyCookieUp to 1 hour; auto-refreshed while active. Deleted on sign out.Yes
sb-[project]-auth-token-code-verifierSupabaseSecures the login handshake (PKCE flow)CookieDeleted after login completesYes
Turnstile cookies / storageCloudflareBot and abuse detection on login, sign-up, password reset, password change, mailing-list, co-creator, and contact formsCookie / browser storageSessionYes
ARRAffinity
ARRAffinitySameSite
Microsoft AzureRoutes your requests to the same server instance during a visit (infrastructure, set by the hosting platform)CookieSessionYes
kinora_signup_prefillKinoraPre-fills the sign-up form with your name and email if you submitted a co-creator application while logged outsessionStorageCleared on use or when the browser tab closesNo

The Kinora feature storage entry (kinora_signup_prefill) is first-party only, never shared with third parties, and does not affect core website functionality if cleared.

5. Third-Party Services

The following providers may set cookies or use similar technologies as part of the current website:

  • Supabase — authentication and account sessions.
  • Cloudflare Turnstile — bot and abuse protection on forms.
  • Microsoft Azure — website hosting infrastructure (ARRAffinity cookies).

More detail about our service providers, including MailerLite (email delivery and tracking within emails), is available in our Privacy Policy.

6. Managing Cookies

Most browsers allow you to view, delete, or block cookies and browser storage through their settings. Blocking strictly necessary cookies may stop account login, security checks, or other website features from working properly.

The kinora_signup_prefill entry can be cleared at any time through your browser's storage settings without affecting your account or core website access.

7. Changes to This Policy

We may update this Cookie Policy from time to time. The "Last updated" date at the top of this page shows the most recent revision.

8. Contact Us

If you have any questions about this Cookie Policy, contact us at: privacy@kinora.health