What these items do
A cookie is information stored in your browser and sent with certain requests. Local storage keeps a preference on your device; session storage keeps information for a tab’s browsing session. These storage mechanisms fall within the rules on access to information on your device, even when they are not technically cookies.
Unspecified uses them to keep an authenticated session, secure sign-in, remember your requested interface settings and restore the prompt you are preparing. They do not replace the account and creation records stored on our servers.
The CNIL exempts authentication trackers and interface customisation that is an intrinsic and expected part of the requested service from prior consent. That exemption applies only to their necessary purpose. It does not authorise unrelated advertising or tracking.
The current inventory
The names below help you recognise entries in your browser settings. The project identifier in an authentication cookie’s name can vary, and the cookie can be split into several numbered parts.
The language appears in the page address; the application does not add a separate language-preference cookie. Exact retention in a browser can also be affected by its privacy settings or automatic storage cleanup.
- Sign-in — sb-…-auth-token
- Cookie managed through Supabase Auth to maintain and refresh your authenticated session. Current library setting: a maximum of 400 days per cookie write; refreshing a session can renew that period. Signing out removes the session cookies. The server can expire or revoke a session earlier, independently of the cookie’s lifetime.
- Secure sign-in return — sb-…-auth-token-code-verifier
- A technical cookie that may be created for a secure authentication or password-recovery flow. Used to verify the return to the site and removed when the flow completes or is cleared. If it remains, it uses the same current maximum cookie lifetime of 400 days. Its presence does not guarantee that a sign-in or recovery link remains valid that long.
- Portrait invitation — unspecified:portrait-invitation
- Session storage of the private invitation token, used to resume the requested process in this tab. Removed on withdrawal. Normally ends with the tab session; browser session restoration may restore it. This does not extend the invitation or permission period enforced by the server.
- Theme — ft-theme
- Local storage for your light, dark or system theme choice. No automatic application expiry: kept until replaced, cleared by you or removed by the browser.
- Image studio settings — uns-gen-settings
- Local storage for your chosen model, format, resolution, quality and number of variations. No automatic application expiry: kept until replaced, cleared by you or removed by the browser.
- Thumbnail size — unspecified:gallery-scale
- Local storage for the gallery size setting you choose. No automatic application expiry: kept until replaced, cleared by you or removed by the browser.
- Studio welcome — unspecified:welcome:…
- Tab session storage used to vary greetings and mascots, with recent message identifiers, the last visit time and the last welcomed sign-in. It contains no name or prompt and is not sent to a server. It normally ends with the tab session; browser session restoration may restore it.
- Studio drafts — unspecified-studio-drafts
- IndexedDB storage, separated by account and project on this device: prompts, settings, references, video cuts, undo/redo history and imported image, video or audio files. Restored for up to 30 days after the last save; expired entries are removed during a later draft save. Unconfirmed image and video requests also keep their original identifier and exact input for up to 30 days, so you can explicitly retry them without creating another request. Closing a tab does not remove them. Clearing site data removes them. This local draft is not a cloud backup; generating or exporting uses the service’s normal uploads and private storage.
- Prompt draft — first-take:prompt:v1
- Session storage for the draft or inspiration you send to the image studio. It can contain your prompt text. Kept for the tab’s session and replaced or removed when you change or clear the draft. Closing the tab normally ends this storage; browser session restoration may restore it.
Google and other services
When Google sign-in is enabled, the Google Identity component loads on the sign-in page, before a click on its button. It communicates with Google to display and operate the sign-in option. Google may use technical authentication mechanisms depending on your browser, its settings and your Google session; these are not advertising cookies installed by the studio.
The complete behaviour of third-party components and infrastructure depends on their configuration and may change. The current application does not integrate an advertising pixel or a browsing-audience measurement SDK. Service consumption statistics come from account and generation records, rather than a separate audience cookie.
If a feature involving non-essential trackers is added, the required information and prior consent controls must be provided before those trackers are used. Refusing an optional purpose must be as straightforward as accepting it, and consent must be withdrawable.
Change or clear your preferences
Clearing browser storage does not delete your server-side account, prompts or generated media, and does not erase any files you downloaded. Use the studio’s removal controls where available or contact us for a personal-data request.
- Use the theme control or the studio controls to change the preference concerned.
- To clear saved items, open your browser’s privacy or site-data settings, search for unspecified.ai and remove its cookies and site storage. Depending on the browser, local storage may be grouped under “site data” rather than “cookies”.
- Sign out to end your current authenticated session. On a shared device, also clear saved site data and close studio tabs, especially if you entered personal information in a prompt.
- Block site cookies or storage through the browser if you prefer. This can prevent sign-in, reset interface settings or stop draft recovery.
Questions or changes
Contact hello@unspecified.ai about cookies or browser storage. This inventory describes the version dated above and must be updated when new storage or tracking features are introduced.
The privacy policy identifies the controller, the processing purposes and legal bases, service providers, retention criteria and your data protection rights.