Cookie Policy
Last updated July 31, 2026
Plain-language summary. OrbitSub uses almost no cookies. We set one essential cookie to keep you signed in, and our bot-protection provider may set its own to tell humans from bots. A few preferences (like your light/dark theme) are stored in your browser’s local storage, not in cookies.
This Cookie Policy explains how KARAN (“OrbitSub,” “we”) uses cookies and similar browser-storage technologies on the website at orbitsub.com (the “Service”). It should be read together with our Privacy Policy.
1. What cookies (and similar technologies) are
A cookie is a small text file a website stores on your device so it can recognise your browser. Local storage is a related browser technology that lets a site save small pieces of information (like a setting) on your device without sending it to a server on every request. We use both, sparingly, and we explain exactly what for below.
2. The cookies we set
2.1 Strictly necessary — first-party
These are essential for the Service to work. Without them, you could not sign in or stay signed in. They cannot be switched off through a consent banner.
orbit_rt — keeps you securely signed in by holding your session refresh token, so you don’t have to log in on every visit.
Details: first-party; HttpOnly (JavaScript can never read it, which protects it from theft); sent only over HTTPS in production; restricted to our authentication routes; expires after about 30 days.
This is the only cookie OrbitSub itself sets.
2.2 Bot protection — third-party (Cloudflare Turnstile)
To stop automated abuse at sign-up and sign-in, we use Cloudflare Turnstile. When it is active, Cloudflare may set its own cookies (for example, cookies used to distinguish humans from bots and to remember that a challenge was passed). These are set by Cloudflare under its own privacy terms, are used only for security. If Turnstile is not enabled, these cookies are not set.
3. What we store in local storage (not cookies)
The following preferences are saved in your browser’s local storage, not in cookies. They stay on your device, are not automatically sent to our servers, and are not used to track you:
- Theme — your light / dark / system choice, so the interface looks the way you left it.
- Onboarding state — whether you have completed the product walkthrough, so we don’t show it again.
- Cookie/consent choice — your response to our cookie notice, so we remember your preference.
- Interface dismissals — small flags such as a dismissed prompt, so it stays dismissed.
- Citation-style cache — citation styles you’ve used, cached so they load quickly next time.
You can clear local storage at any time through your browser settings.
4. What we do NOT use
- No cross-site tracking or third-party marketing trackers.
- No selling of data. We do not sell any information collected via cookies or storage.
If you use an AI feature, sign in with Google, or make a payment, those providers (Microsoft, Google, PayPal) operate under their own privacy and cookie practices when you interact with them, as described in our Privacy Policy.
5. Managing cookies
Because our only own cookie is strictly necessary to sign you in, disabling it will prevent you from using your account. You can still control cookies and local storage through your browser:
- most browsers let you view, block, or delete cookies and clear local storage in their settings;
- blocking the essential cookie will log you out and stop you from signing in;
- you can clear the preferences we store locally at any time, which simply resets those preferences.
6. Changes to this Policy
If we change how we use cookies, we will update this page and the “Last updated” date above, and where the change is material we will let you know in the Service.
7. Contact us
If you have any questions about this Cookie Policy, contact us at team@orbitsub.com.