
How cookies and similar browser storage are used on BioPipeline.
This Cookie Policy explains what cookies, local storage, and similar browser technologies BioPipeline uses, why we use them, and how you can control them.
Cookies are small text files stored on your device by your web browser. They help websites remember information about your visit (e.g., login state, preferences) to improve functionality and user experience.
BioPipeline also uses local storage and session storage (HTML5 browser APIs) for similar purposes. These technologies are collectively referred to as "cookies" in this policy.
These cookies are strictly necessary for the Service to function and cannot be disabled without breaking core features.
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
sb-access-token | Authentication token (Supabase) | 1 hour | HttpOnly, Secure |
sb-refresh-token | Session refresh (keep you logged in) | 7 days | HttpOnly, Secure |
__Secure-next-auth.session-token | Next.js session management | Session (until browser closes) | HttpOnly, Secure, SameSite=Lax |
Legal basis: Strictly necessary for contract performance (GDPR Art. 6(1)(b)) — you cannot use authenticated features without these cookies.
These cookies remember your preferences to improve usability. They are not strictly required but significantly enhance your experience.
| Storage Key | Purpose | Duration | Type |
|---|---|---|---|
biopipeline_theme | Dark/light mode preference | Persistent (until cleared) | localStorage |
activePage | Last visited page in app | Session (until tab closes) | sessionStorage |
sidebar_collapsed | Sidebar expansion state | Persistent (until cleared) | localStorage |
Legal basis: Legitimate interest (GDPR Art. 6(1)(f)) — improving user experience without processing personal data.
We do not currently use third-party analytics (Google Analytics, Mixpanel, etc.). If we introduce analytics in the future, we will:
We do not use advertising cookies or third-party ad networks. BioPipeline does not display ads or track users for behavioral advertising.
Some features may use third-party services that set their own cookies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Authentication and database | Supabase Privacy |
| Vercel | Hosting and CDN | Vercel Privacy |
| Stripe (if subscribed) | Payment processing | Stripe Privacy |
We are not responsible for third-party cookies. Review their privacy policies for details on how they use cookies.
You can control or delete cookies through your browser settings. Here are instructions for common browsers:
Warning: Blocking essential cookies will prevent you from logging in and using authenticated features.
To clear BioPipeline-specific storage:
https://www.biopipeline.online and click "Clear All"We respect Do Not Track (DNT) browser signals. If DNT is enabled:
If we introduce analytics in the future, you will be able to opt out via:
| Type | Duration | When Deleted |
|---|---|---|
| Session cookies | Until browser closes | When you close the browser/tab |
| Persistent cookies | 1 hour to 7 days | After expiration or manual deletion |
| Local storage | Indefinite (until cleared) | Manual deletion or browser cache clear |
If we release a mobile app, this Cookie Policy will be updated to cover mobile-specific tracking technologies (e.g., device identifiers, push notification tokens). Native apps do not use browser cookies but may use similar mechanisms.
We may update this Cookie Policy to reflect service changes or legal requirements. Material changes will be notified via:
If we introduce new cookie categories (e.g., analytics), we will request explicit consent where required by law (GDPR, ePrivacy Directive, CCPA).
For questions about cookies or data privacy:
Privacy Team
Email: privacy@biopipeline.online
DPO: dpo@biopipeline.online
Under GDPR, you have the right to:
We comply with the ePrivacy Directive (Cookie Law) by:
Under CCPA, we do not "sell" personal information via cookies. If we introduce advertising cookies, California users will have a "Do Not Sell My Personal Information" link.
For users in other regions (UK, Canada, Australia, Brazil, etc.), we apply GDPR-equivalent standards as a baseline, ensuring compliance with local cookie laws.