Trust center
Cookie policy
Every cookie we set, what it does and how long it stays. Nothing optional is set before you accept it in the banner, and withdrawing removes what consent allowed.
Last updated 20 September 2026 · Trust center
Strictly necessary
Set because the page cannot do what you asked without them. They carry no advertising id and are not shared with anyone.
| Cookie | What it is for | Lasts |
|---|---|---|
| cb_consent | Remembers the choice you made in the cookie banner, so you are not asked again and so everything optional stays off until you say otherwise. | 1 year |
| cb_onb | Carries your answers through the sign-up questions from one page to the next, and links them to your account when you finish. | 30 days |
| cb_oauth | Holds the one-time state and PKCE verifier while you sign in with Google. Without it the sign-in cannot be checked for tampering. | 10 minutes |
| cb_oauth_apple | The same one-time state for signing in with Apple, which returns to us by cross-site form post and needs its own cookie. | 10 minutes |
| cb_demo | Marks which demo workspace you are looking at. The demo needs no account and writes nothing to a real one. | 2 hours |
| cb_demo_return | Parks your own signed-in session while you look at the demo and puts it back when you leave, so you are not signed out. Split across numbered cookies when it does not fit in one. | 7 days |
| cb_scan_import | Carries the scan report you asked to keep into your workspace after you sign in, so the report is not lost at the sign-in step. | 7 days |
| cb_support | Set only for our staff, and only while a firm has granted read-only support access to its own workspace. It is never set in an ordinary visit. | until the grant expires, at most 60 minutes |
| sb-<project>-auth-token | Your signed-in session, set by our authentication provider Supabase. Signing out removes it. | session, refreshed while you are signed in |
Analytics
Set only after you accept analytics in the banner, and deleted when you withdraw. They feed our own counters in our own database — no third-party analytics service is loaded.
| Cookie | What it is for | Lasts |
|---|---|---|
| cb_anon | A random id with no name or address attached, so our own product events can tell one visit from another. Written only after you accept analytics, and deleted when you withdraw. | 1 year |
| cb_attr | The first page and campaign parameters that brought you here, so we can tell which pages bring customers. Written only after you accept analytics, and only when there is something to record. | 90 days |
| cb_ab_<page> | Which version of a landing page you were shown, so you keep seeing the same one. Written only after you accept analytics, and deleted when you withdraw. | 1 year |
| cb_ref | The referral code of the link you arrived through, so the firm that referred you is credited if you subscribe. Written only after you accept analytics. | 90 days |
Changing your mind
The banner writes your choice into cb_consent and nothing optional runs until it says so. Withdrawing analytics deletes the cookies that consent allowed, on the spot. You can also clear them in your browser; the strictly necessary ones come back the next time you use the thing that needs them.
Who to ask
REALTY.TM GROUP sp. z o.o., ul. Bpa Albina Małysiaka 26/15, 30-389 Kraków, Poland. More about how we handle personal data is in the privacy policy.