Cookie and local storage policy
Last updated: October 4, 2026
This English version is provided for convenience. The French version is the legally binding text and prevails in case of any discrepancy.
1. Trackers used on inbord.io
As of this policy, inbord sets no advertising trackers and uses no third-party analytics tools. Traffic to the site's public pages is measured by inbord itself, without cookies and without storing anything in your browser: when a page is displayed, and again when you leave it, the site tells inbord's server the page address, the site you came from and the time spent. A visitor is only recognized for the current day, through an irreversible fingerprint of their IP address and browser, recalculated every day with a random key that is deleted right away; the IP address is not kept. Nothing is shared with third parties, and the app, client spaces and back office are not measured. The only storage used is the technical storage required for authentication, security, displaying the interface and saving a client form's progress locally.
2. Strictly necessary storage
- Supabase session: keeps the technical data needed to stay signed in to your account. Its duration depends on the session and its renewal.
- Interface preference sidebar_state: remembers whether the side menu is open or closed, for seven days.
- Language preference inbord_lang: set only when you pick a language with the language switcher, so the site shows in that language on your next visits. It is kept for one year and only contains the language code (fr or en). If you don't choose, the language follows your browser settings and no cookie is set.
- Progress inbord_progress_[identifier]: remembers locally, in the client's browser, whether a project space has been started or completed. This information does not contain the form answers.
- Upload resume inbord_uploads: remembers locally the state of file uploads in progress, so an interrupted transfer can pick up where it left off. This information is deleted after seven days and contains no file content.
- Cloudflare cookies __cf_bm and cf_clearance: set by the provider that protects the site against abuse and automated traffic. They are used to tell a visitor from a bot and have no advertising purpose. They last from a few dozen minutes to a few days depending on the cookie.
3. Why is there no consent banner?
The trackers currently in use are strictly necessary for the service requested or for remembering an interface choice. The traffic measurement described above neither sets nor reads anything in your browser, is only used to produce anonymous statistics for inbord and is not combined with any other processing. None of these therefore requires prior consent. If inbord later adds an advertising tool or an analytics tracker that requires consent, it will be blocked until you agree, and an interface will let you accept, refuse or withdraw that consent just as easily.
4. Stripe payments
When a user chooses a paid plan, they are redirected to a secure page operated by Stripe. Stripe may then use its own trackers required for payment, fraud prevention and security, in accordance with its own privacy documentation.
5. Managing or deleting local data
You can delete cookies and site data from your browser settings. Deleting authentication data will sign you out. Blocking some strictly necessary storage may prevent the user or client space from working properly.
6. Contact and changes
For any question, write to support@inbord.io. This policy will be updated before any significant change to the trackers used.