CyberProfileCyberProfile Back to home

Last updated: August 21, 2026

Cookie Policy

This policy explains which cookies and other storage technologies CyberProfile uses, for what purpose, how long they last and how you can control them. Nothing that is not strictly necessary is activated without your permission.

1. What are cookies?

Cookies are small text files that a website stores on your device and that are sent back on every visit. They remember information across pages: for example, that you are signed in or which language you prefer.

Alongside cookies there are equivalent technologies, such as browser local storage. Technically they are not cookies, but the law treats them the same way, so we list them here too.

2. Your choice and how to change it

The first time you visit we show a notice with three options: accept, reject or customise by category. Rejecting takes exactly the same effort as accepting: a single click. You can keep using the site normally without accepting anything.

Until you decide, nothing that is not strictly necessary is installed. If you accept and later change your mind, open "Cookie preferences" in the footer: as well as saving your new choice, we delete the cookies that are no longer allowed.

We store your decision for 6 months. After that, or if the purposes we use cookies for change, we will ask you again.

3. Categories

  • Necessary — they let you sign in, protect against CSRF attacks and remember the language you picked. The service does not work without them, so they are exempt from consent and cannot be turned off.
  • Measurement — they tell us which pages get visited and where people come from, using a visitor identifier that lasts a year. They require your consent. Without it we still count visits, but only in aggregate and without identifying you.
  • Third-party functional — one-click Google sign-in (One Tap) outside the sign-in page, and invitation-link attribution. They require your consent because they load resources from Google.

4. Our own cookies

CookiePurposeDurationCategory
authjs.session-tokenKeeps you signed in. Named __Secure-authjs.session-token over secure connections.90 daysNecessary
authjs.csrf-tokenProtects authentication forms against forged requests from other sites.SessionNecessary
authjs.callback-urlRemembers which page to return to after you sign in.SessionNecessary
authjs.pkce.code_verifier · authjs.state · authjs.nonceSecurity of the sign-in flow with Google, GitHub or LinkedIn (PKCE and anti-CSRF state).MinutesNecessary
gh_oauth_state · li_oauth_state · yt_oauth_state · oauth_link_stateAnti-CSRF state when connecting your GitHub, LinkedIn or YouTube account to your profile.10 minutesNecessary
cp_team_invite · cp_org_inviteKeeps the token of an invitation you opened while you sign in.2 hoursNecessary
cp_langRemembers whether you prefer the site in Spanish or English. Only created if you change the language yourself.1 yearNecessary
cp_consentStores your decision about this policy so we do not ask again.6 monthsNecessary
cp_vidRandom visitor identifier that lets us tell unique visits from page views. It contains neither your name nor your email.1 yearMeasurement
cp_utmRemembers which campaign or link you first arrived from, so we know which channels work.30 daysMeasurement
cp_ref · cp_ref_userAttributes an invitation or referral link to whoever shared it.30 daysFunctional

5. Third-party cookies

The only third party that can set cookies in your browser through this site is Google, and only in two cases: when you visit the sign-in page (because you have expressed your intention to sign in) or when you have accepted the "Third-party functional" category. Nowhere else on the site is any Google resource loaded.

CookieOwnerPurposeDuration
g_stateGoogleRemembers that you dismissed the one-click Google sign-in prompt so it is not shown again.Up to 1 year
NID · SIDCC · __Secure-*PSIDGoogleGoogle account cookies, required to identify you with it. Managed by Google, not by CyberProfile.Variable (set by Google)

These cookies are governed by Google’s privacy policy (policies.google.com/privacy). You can review and revoke access from your own Google account.

We do not use advertising cookies, third-party networks or cross-site tracking. There is no Google Analytics, no social media pixels and no session recording tools.

6. Browser local storage

Besides cookies, we keep some interface preferences in your browser local storage. They are never sent to our servers, they identify no one, and they exist only so the site looks the way you left it.

  • cp-apptheme — whether you prefer the panel light, dark or following your system.
  • cp-theme · cp-accent · cp-glass · cp-font · cp-bg — the appearance you chose for your profile.
  • cp-dock-hint-seen · cp-rail-groups — hints already seen and menu sections you collapsed.

You can clear them at any time from your browser tools without affecting how the service works.

7. Managing them from your browser

Regardless of what you decide here, every browser lets you view, block and delete cookies from its privacy settings. Note that blocking the strictly necessary ones will prevent you from signing in and using the platform.

Official instructions: Chrome (support.google.com/chrome/answer/95647), Firefox (support.mozilla.org/kb/cookies-information-websites-store-on-your-computer), Safari (support.apple.com/guide/safari/sfri11471) and Edge (support.microsoft.com/microsoft-edge).

8. Changes to this policy

If we add a new cookie or change the purpose of an existing one, we will update this page and ask for your consent again before activating it.

9. Contact

Controller: Gorka El Bochi Morillo, tax ID 46099276P, Carrer Romaní 15, 08184 Palau-solità i Plegamans (Barcelona), España. For any question about this policy, write to gorka@cyber-profile.com.