Cookie Policy
Every cookie this site sets, what it does and how long it lasts. Optional Google and Meta measurement stays off unless you say yes.
Last updated October 10, 2026 · Operated by Ron Avidor (Israel)
The short version. Three cookies are strictly necessary: two keep you signed in, one remembers your cookie choice. If, and only if, you accept, Google Tag Manager and Meta's pixel measure site activity and which marketing brings in customers. Nothing is sold to anyone.
1. What a cookie is
A small file a site stores in your browser and reads back on your next request. HTTP has no memory of its own, so without one you would be signed out between every page.
2. Every cookie we set
| Name | Purpose | Lasts | Type |
|---|---|---|---|
sb-<project>-auth-token | Your signed-in session, issued by Supabase Auth. Without it you cannot reach your studio, credits or videos. | Refreshed on use; expires after inactivity | Strictly necessary |
sb-<project>-auth-token-code-verifier | Short-lived PKCE verifier that protects the sign-in exchange from interception. Deleted the moment sign-in completes. | Minutes | Strictly necessary |
veymu.consent | Remembers whether you accepted or declined advertising cookies, so the notice stops reappearing. | 12 months | Strictly necessary |
_fbp, _fbc | Set by the Meta Pixel, only after you accept. They let Meta tell us that a purchase came from one of our ads on Facebook or Instagram. | 90 days | Advertising |
_ga, _ga_* | May be set by Google Analytics through Google Tag Manager, only after you accept, to distinguish visits and measure page views and purchases. | Up to 2 years | Analytics |
The authentication cookies are HTTP-only (page JavaScript cannot read them), Secure (sent only over HTTPS) and SameSite (not sent on requests originating from another site, which is what stops cross-site request forgery).
3. Analytics and advertising cookies
We use Google Tag Manager to send page-view and purchase events to the measurement tags configured in our container. A purchase event contains the transaction ID, amount, currency and product purchased. We also run ads on Facebook and Instagram, and use the Meta Pixel and Meta's Conversions API to learn which of them lead to a purchase. With your consent, Meta receives the pages you visit here, and, when you buy, the amount, the product, your email address (hashed, not in plain text), your IP address and browser type.
Without your consent, none of this happens: neither Google Tag Manager nor the Pixel is loaded, no optional measurement cookie is set, and nothing about your purchase is sent to either service. Declining changes nothing about the product.
Optional analytics and advertising cookies are currently off.
What we still don't do: no fingerprinting and no sale of tracking data.
4. Third parties
On our pages, Google and Meta load only if you accept. Our Content Security Policy blocks other third-party scripts. Google's use of data is covered by its privacy policy, and Meta's by Meta's privacy policy.
Two things happen off our pages and are covered by their own policies:
- Checkout. Paying takes you to Dodo Payments's hosted checkout, which sets its own cookies for fraud prevention and session handling. See Dodo Payments's privacy policy.
- Social sign-in. Choosing Google or Facebook sends you to their sign-in page, where their cookies apply.
5. Controlling cookies
You can block or delete cookies in your browser settings. Blocking ours will sign you out and keep you out, there is no way to hold a session without them. You can still browse the public pages.
We honour the Global Privacy Control signal: a browser that sends it is treated as having declined advertising cookies, and is never asked.
6. Related
For everything else we hold, see the Privacy Policy, or write to privacy@veymu.io.
