This notice covers cookies and similar storage we use on owlsignal.dev (the marketing site and the dashboard). It does not govern what the Owlsignal SDK does inside your game or site — you configure that, and you disclose it to your own players. §3 summarises what it stores by default so you know what you're disclosing.
Owlsignal does not run third-party advertising networks, analytics tags, or marketing pixels on
our own site. There are no Google Analytics, Facebook Pixel, LinkedIn Insights, or similar
trackers loaded from owlsignal.dev.
We do measure this site — with Owlsignal, running against our own ingest. We run it in stateless mode: the anonymous ID it uses lives in memory for the page load and is never written to your device, so every visit looks like a new visitor to us. We can't tell that you came back tomorrow, and we've accepted that trade.
That's why there's no consent banner here. The EU ePrivacy Directive (Art. 5(3)) applies to storing or reading information on your device — it isn't a rule about cookies specifically, and it isn't a rule about personal data, so "it's only local storage" and "it's anonymous" wouldn't have been good enough. Writing nothing is. The only storage we set is listed below, and all of it is strictly necessary.
All cookies below are strictly necessary — they exist to make the application work, not to track you across sites.
| Cookie / storage | Purpose | Lifetime | Set by |
|---|---|---|---|
sb-access-token | Your authenticated session — proves who you are when calling the dashboard. | 1 hour (refreshed) | Supabase Auth |
sb-refresh-token | Lets us renew your access token without prompting you to log in again. | 30 days | Supabase Auth |
owlsignal-active-tenant | Remembers which organization you're currently viewing. | 30 days | Owlsignal |
The dashboard uses browser localStorage for small UI preferences (the last-viewed app
slug, the loop wizard's draft state, your light/dark choice). This data never leaves your browser.
Clearing site data removes it.
Our own analytics writes nothing here — see §1. If you use the Owlsignal web
SDK on your site with default settings, it does store an anonymous ID under owlsignal:player_hash so you can measure returning visitors; that's storage on your
visitor's device and it's yours to disclose and, if your DPO says so, to ask consent for. Pass persistPlayerHash: false to run stateless like we do.
When you click "Upgrade" we redirect you to Mollie's hosted checkout on mollie.com. Mollie sets its own cookies on its own domain — see Mollie's cookie statement. We don't see or
share those cookies.
If we ever set non-essential storage on this site — including switching our own analytics out of stateless mode — we'll add a consent banner and update this notice before it happens, not after.