Last updated: August 21, 2026
Cookie Policy
This policy explains which cookies and other storage technologies CyberProfile uses, for what purpose, how long they last and how you can control them. Nothing that is not strictly necessary is activated without your permission.
1. What are cookies?
Cookies are small text files that a website stores on your device and that are sent back on every visit. They remember information across pages: for example, that you are signed in or which language you prefer.
Alongside cookies there are equivalent technologies, such as browser local storage. Technically they are not cookies, but the law treats them the same way, so we list them here too.
2. Your choice and how to change it
The first time you visit we show a notice with three options: accept, reject or customise by category. Rejecting takes exactly the same effort as accepting: a single click. You can keep using the site normally without accepting anything.
Until you decide, nothing that is not strictly necessary is installed. If you accept and later change your mind, open "Cookie preferences" in the footer: as well as saving your new choice, we delete the cookies that are no longer allowed.
We store your decision for 6 months. After that, or if the purposes we use cookies for change, we will ask you again.
3. Categories
- Necessary — they let you sign in, protect against CSRF attacks and remember the language you picked. The service does not work without them, so they are exempt from consent and cannot be turned off.
- Measurement — they tell us which pages get visited and where people come from, using a visitor identifier that lasts a year. They require your consent. Without it we still count visits, but only in aggregate and without identifying you.
- Third-party functional — one-click Google sign-in (One Tap) outside the sign-in page, and invitation-link attribution. They require your consent because they load resources from Google.
4. Our own cookies
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| authjs.session-token | Keeps you signed in. Named __Secure-authjs.session-token over secure connections. | 90 days | Necessary |
| authjs.csrf-token | Protects authentication forms against forged requests from other sites. | Session | Necessary |
| authjs.callback-url | Remembers which page to return to after you sign in. | Session | Necessary |
| authjs.pkce.code_verifier · authjs.state · authjs.nonce | Security of the sign-in flow with Google, GitHub or LinkedIn (PKCE and anti-CSRF state). | Minutes | Necessary |
| gh_oauth_state · li_oauth_state · yt_oauth_state · oauth_link_state | Anti-CSRF state when connecting your GitHub, LinkedIn or YouTube account to your profile. | 10 minutes | Necessary |
| cp_team_invite · cp_org_invite | Keeps the token of an invitation you opened while you sign in. | 2 hours | Necessary |
| cp_lang | Remembers whether you prefer the site in Spanish or English. Only created if you change the language yourself. | 1 year | Necessary |
| cp_consent | Stores your decision about this policy so we do not ask again. | 6 months | Necessary |
| cp_vid | Random visitor identifier that lets us tell unique visits from page views. It contains neither your name nor your email. | 1 year | Measurement |
| cp_utm | Remembers which campaign or link you first arrived from, so we know which channels work. | 30 days | Measurement |
| cp_ref · cp_ref_user | Attributes an invitation or referral link to whoever shared it. | 30 days | Functional |
5. Third-party cookies
The only third party that can set cookies in your browser through this site is Google, and only in two cases: when you visit the sign-in page (because you have expressed your intention to sign in) or when you have accepted the "Third-party functional" category. Nowhere else on the site is any Google resource loaded.
| Cookie | Owner | Purpose | Duration |
|---|---|---|---|
| g_state | Remembers that you dismissed the one-click Google sign-in prompt so it is not shown again. | Up to 1 year | |
| NID · SIDCC · __Secure-*PSID | Google account cookies, required to identify you with it. Managed by Google, not by CyberProfile. | Variable (set by Google) |
These cookies are governed by Google’s privacy policy (policies.google.com/privacy). You can review and revoke access from your own Google account.
We do not use advertising cookies, third-party networks or cross-site tracking. There is no Google Analytics, no social media pixels and no session recording tools.
6. Browser local storage
Besides cookies, we keep some interface preferences in your browser local storage. They are never sent to our servers, they identify no one, and they exist only so the site looks the way you left it.
- cp-apptheme — whether you prefer the panel light, dark or following your system.
- cp-theme · cp-accent · cp-glass · cp-font · cp-bg — the appearance you chose for your profile.
- cp-dock-hint-seen · cp-rail-groups — hints already seen and menu sections you collapsed.
You can clear them at any time from your browser tools without affecting how the service works.
7. Managing them from your browser
Regardless of what you decide here, every browser lets you view, block and delete cookies from its privacy settings. Note that blocking the strictly necessary ones will prevent you from signing in and using the platform.
Official instructions: Chrome (support.google.com/chrome/answer/95647), Firefox (support.mozilla.org/kb/cookies-information-websites-store-on-your-computer), Safari (support.apple.com/guide/safari/sfri11471) and Edge (support.microsoft.com/microsoft-edge).
8. Changes to this policy
If we add a new cookie or change the purpose of an existing one, we will update this page and ask for your consent again before activating it.
9. Contact
Controller: Gorka El Bochi Morillo, tax ID 46099276P, Carrer Romaní 15, 08184 Palau-solità i Plegamans (Barcelona), España. For any question about this policy, write to gorka@cyber-profile.com.