Legal
Cookie notice
SourceFinch uses only strictly necessary cookies. They make sign-in and your workspace work, so they do not need consent and cannot be switched off. We use no advertising or cross-site tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
Supabase auth cookies (sb-…) | Keep you signed in and refresh your session securely | Until you sign out or the session expires |
sc_org | Remember which workspace you last selected | Up to 1 year |
sf_oauth_request | Protect the sign-in step when you connect an MCP client or app with OAuth | 10 minutes |
sf_new_webhook_secret | Show a newly created webhook signing secret to you once | 1 minute |
Analytics without cookies
Our analytics do not set cookies. They use a random identifier kept in your browser’s session storage, which is cleared when you close the tab, and record only the page path. They are skipped entirely when your browser sends Do Not Track or Global Privacy Control.
Bot protection
When bot protection is enabled on sign-up, sign-in and request forms, Cloudflare Turnstile may use cookies or similar technologies strictly to tell people from automated abuse.
More detail is in our Privacy Policy.