Cookie Policy
Last updated August 27, 2026
EnoughLine uses a small number of cookies and browser storage keys, all of them strictly necessary to keep you signed in, keep your session secure, and remember choices you have made in the interface. This page explains what each one does, who sets it, and how long it lasts.
What we do not do
- We do not use advertising cookies or share data with advertising networks.
- We do not sell your personal information to anyone.
- We do not embed third-party tracking pixels on signed-in pages that render your financial data.
Strictly necessary cookies
These are set by our authentication provider (Supabase) and are required for the service to function. They are first-party cookies scoped to the origin you signed in from. Disabling them will sign you out.
- sb-*-auth-token — your session token. Set on sign-in, rotated on refresh, cleared on sign-out. Lifetime up to one week.
- sb-*-auth-token-code-verifier — used briefly during the sign-in redirect handshake, cleared as soon as the session is established.
Preferences (browser storage, not cookies)
We store a few interface preferences in your browser's localStorage and sessionStorage. These never leave your device.
- theme — your chosen colour theme (light, dark, or follow OS). Persisted across visits.
- privacyDefault — whether amounts start hidden or visible when the app opens (see Settings → Privacy). Persisted across visits.
- privacy — the show/hide amounts toggle for the current browser tab only, from the eye icon in the header. Cleared when the tab closes.
Product analytics
We use Mixpanel to understand which pages people use and where new visitors drop off during sign-up. Mixpanel stores a small first-party identifier in your browser's local storage so it can tell a returning session from a new one; it does not set third-party tracking cookies. The identifier we send is a hashed workspace ID — not your email, not your name, and never any financial data or content you have entered into the app. Details are in our Privacy Policy.
Payment
Checkout and subscription management are hosted by Stripe. When you visit those pages, Stripe may set its own cookies to prevent fraud and remember your session with them. Those cookies are governed by Stripe's cookie policy.
Bank and brokerage connections
Linking an institution opens a widget from Plaid or SnapTrade in an embedded frame. Those widgets may set cookies within their own frame to maintain the connection flow. Those cookies are governed by Plaid's and SnapTrade's respective policies and are removed when the flow closes.
Your choices
- You can clear cookies and local storage in your browser at any time. Clearing them will sign you out and reset your theme and privacy defaults.
- You can block third-party cookies in your browser without affecting the strictly necessary first-party cookies used for sign-in.
- To close your account and remove all data we hold about you, use Settings → Delete account.
Contact
Questions about this policy: support@enoughline.com.