HolySN

Cookies

Last updated: 29 September 2026

Browsing this site sets no cookies. There is no analytics script, no advertising pixel and no tracking tag on any page. The few cookies that exist are set by Stripe on the payment page, only when you pay, to prevent fraud; everything else the site keeps is in your own browser's storage and exists only because you signed in or chose something.

The law asks for consent before a site stores or reads anything on your device, except what is strictly necessary for a service you asked for (Article 5(3) of the ePrivacy Directive, and in Italy the Garante's cookie guidelines of June 2021). Everything on this page is of that kind: keeping you signed in, remembering a theme you picked, and letting Stripe check a payment for fraud. Nothing measures you, profiles you or follows you to other sites, so there is nothing to consent to and no banner to dismiss.

Cookies

Set only on the checkout page, and only by Stripe's payment form:

NameSet byLastsWhat it is for
__stripe_midStripe, on holysn.com1 yearFraud prevention: recognises the device across payments
__stripe_sidStripe, on holysn.com30 minutesFraud prevention: ties together the steps of one payment
mStripe, on m.stripe.comAbout 13 monthsFraud prevention on Stripe's own domain
__cf_bmhCaptcha, on hcaptcha.com30 minutesTelling people from bots during the payment's fraud check

Stripe describes these in its own cookie policy. They are not set when you only browse the site.

Storage in your browser

localStorage and sessionStorage are not cookies: they are never attached to a request, so they never reach our server by themselves. They stay on the device where they were set.

KeyWhereWhat it holdsWhen
holysn-site-authlocalStorageYour sign-in sessionWhile you are signed in; removed when you sign out
holysn-account-hintlocalStorageThe name, plan and picture the header shows, so it does not flicker while the session loadsWhile you are signed in; removed when you sign out
holysn-themelocalStoragelight or darkOnly when you press the theme switch in the footer; choosing System removes it
holysn-oauth-pendingsessionStorageThat a sign-in with Google, Microsoft or GitHub is under wayOnly during that sign-in; gone when the tab closes
holysn-upgrade-after-sign-insessionStorageThat you asked for Pro before signing in, so the checkout followsOnly until you are signed in; gone when the tab closes
holysn-billing-viewsessionStorageThe last read of your subscription, so Billing does not ask twiceGone when the tab closes

What else leaves the browser

  • Signing in, and your account. What you type goes to Supabase, which runs the accounts. The privacy policy says what is kept.
  • Paying. The payment form is Stripe's. It loads its typeface from Google Fonts, which sees your IP address when it does.
  • The ordinary server log of a web request. Serving a page means the server sees the request for it. Those logs are short-lived and are not used to build a profile of anyone.

The extension is a separate thing

This page is about the website. What the browser extension stores on your machine, and what it sends when you use the assistant or the credential vault, is set out in the privacy policy.

If this changes

Adding analytics or advertising would mean cookies, or something that behaves like them, that need your consent, and a banner that asks for it before anything is set. If that day comes, this page changes first and says which tool, what it stores and for how long.

Cookies | HolySN