Cookies
Last updated: 19 September 2026
This page explains the cookies, and the local and session storage, that the Onboardly dashboard and public pages use, and why.
1. What these are
Cookies, local storage and session storage are small pieces of data a website stores in your browser. We use them to keep the dashboard working and to remember a small number of preferences.
2. What we store
- sb-<project-ref>-auth-token (Cookie) — Keeps you signed in to the recruiter dashboard. Kept: Up to 400 days, or until you sign out.
- onboardly-recovery-verified (Cookie) — Marks that you arrived at the reset-password page from a genuine password-recovery email link. Kept: A few minutes.
- onboardly-remember-me (Cookie) — Remembers whether you asked to stay signed in on this device. Kept: Up to 30 days, or until you sign out.
- onboardly-device-trust (Cookie) — Proves this browser has already completed the emailed sign-in code, so you are not asked again on it. Holds only a random browser id, an expiry time, and a signature — never your name, email address, IP address, or a device fingerprint. Signed so it cannot be edited or used to sign in as someone else. It stays in place even after you sign out; clearing cookies or using private browsing means the next sign-in asks for a code again. Kept: Up to 30 days.
- onboardly.theme (Local storage) — Remembers whether you chose light, dark, or system appearance. Kept: Until you change it or clear your browser storage.
- onboardly.application-form-draft. (Local storage) — Saves your progress through the candidate application form on this device, so a closed tab does not lose your answers. Kept: Until you submit the form, or clear your browser storage.
- onboardly.tour-handoff (Session storage) — Carries a one-off signal to start the guided dashboard walkthrough right after you sign in. Kept: 30 seconds, or until the browser tab closes.
- onboardly.tour-auto-started (Local storage) — Remembers that this device already started the guided dashboard walkthrough automatically, so a new account is not offered it twice. Kept: Until you clear your browser storage.
- onboardly-docs-sample-language (Local storage) — Remembers which code-sample language you last picked on the developer documentation pages. Kept: Until you change it or clear your browser storage.
- onboardly.cookie-notice-dismissed (Local storage) — Remembers that you dismissed the cookie notice, so it does not show again on this device. Kept: Until you clear your browser storage.
3. No analytics or advertising
Onboardly does not set analytics or advertising cookies, and does not use any third party to track you across websites.
4. Third-party scripts
A small number of features load code from a third party only when that feature is switched on:
- Cloudflare Turnstile — A bot-abuse challenge widget shown on the sign-in, sign-up and password pages. Not currently loaded.
- Meta / Facebook JS SDK — Lets a recruiter connect their own WhatsApp Business Account during setup. Not currently loaded.
5. Clearing cookies and storage
You can clear cookies and site storage at any time from your browser's settings. Doing so will sign you out and reset any remembered preference; it will not delete your account or any data stored on our servers.
6. More information
See our Privacy Policy (/privacy) for how we handle personal data more generally.