← Back to Fragments

Cookie Policy

Last Updated: June 30, 2026

1. What are cookies?

Cookies are small text files stored on your device. Fragment does not use advertising, analytics, or profiling cookies.

2. Strictly Necessary Cookies

We only use cookies essential for security, authentication, and core functionality. Consent is not required.

  • __cf_bm
    Provider: Cloudflare
    Purpose: Security cookie to protect Fragment against bots and malicious traffic
    Duration: Session
  • __dpl
    Provider: Lovable
    Purpose: Deployment cookie required for app routing and functionality. Lovable is our web app hosting provider.
    Duration: Session
  • session-id
    Provider: Supabase / Fragment
    Purpose: Maintains your login session so you don’t have to re-enter credentials
    Duration: Session

3. Local Storage & Similar Technologies

We use your browser's Local Storage to securely store your Supabase authentication token. This is used only to keep you logged in. On mobile devices, we use equivalent secure storage like iOS Keychain or Android Keystore.

Supabase is our backend provider and processes this data to enable authentication.

4. Third-party services

These third parties may set cookies, access local storage, or use device identifiers to provide essential services for Fragment:

  • Cloudflare: Security and CDN services
  • Lovable: Web application hosting
  • Supabase: Authentication and database
  • OneSignal: Technical push notifications. OneSignal stores a unique device token in your browser's Local Storage (IndexedDB) to identify your device and deliver notifications. It does not use cookies for tracking or marketing.

5. How to manage cookies

Because we only use strictly necessary cookies, you cannot disable them without breaking the app. Clear cookies and Local Storage from your browser settings to remove them. This will log you out.

6. Contact us

Questions? support.appfragments@gmail.com

See also our Terms and Conditions and Privacy Policy.