Cookies & local storage
Last updated: July 25, 2026
InboxDome does not use advertising or third-party analytics cookies.
What we store in your browser
This is the complete list. Everything here is strictly necessary for a feature you invoked, and nothing is written until you use that feature.
| Item | Type | Purpose |
|---|---|---|
theme | localStorage | Remembers your light/dark preference |
inboxdome.inboxes.v1 | localStorage | Your recent inboxes and their private access keys, so you can return to them from this browser. Never synced anywhere. |
inboxdome.demo-dismissed.v1 | localStorage | Remembers that you dismissed the sample-message card, so it stays dismissed |
sb-<project>-auth-token | localStorage | Your login session, set by Supabase when you sign in to an account. Removed on logout. |
inboxdome:pending-consent, inboxdome:pending-email, inboxdome:pending-type | localStorage | Carries your signup details across the email-verification step so the consent you gave is recorded against the right account. Cleared once verification completes. |
inboxdome:pw-reset-consumed | sessionStorage | Marks a password-reset link as already used, so a reused link cannot silently reset again |
idkKey | sessionStorage | The API key you pasted into the developer dashboard. Kept for the tab only and never sent anywhere except our API. |
adminKey | sessionStorage | Operator-only. Set exclusively on the internal admin page, never on any page a visitor can reach. |
All of these can be cleared at any time via your browser settings, by logging out, or with the "Delete inbox" action.
Cloudflare, our infrastructure provider, may set strictly necessary security cookies (e.g. bot protection).