Cookie notice

Last updated: August 23, 2026

EarWorm sets three cookies. None of them are for advertising, none are sold, and none track you across other websites.

Authentication (sb-access-token, sb-refresh-token)

Set by our authentication provider, Supabase, when you sign in. They keep you signed in between visits and are refreshed automatically as they near expiry.

These are strictly necessary — without them there is no way to know you are signed in, so the app cannot show your library, your saved songs, or your creator page. They are removed when you sign out.

Radio presence (ew_radio_session)

Set the first time you tune into a radio channel. It holds a random identifier with no connection to your name or email, and exists so the "listening now" count on a channel reflects real presence rather than raw request volume.

It is http-only, meaning page scripts cannot read it, and it expires after 30 days.

What we do not set

No advertising cookies. No third-party tracking pixels. No cross-site profiling. No analytics cookies that follow you off EarWorm.

Payment pages hand off to Stripe, which sets its own cookies under its own domain to process the payment and detect fraud. That happens on Stripe's checkout page, not ours, and is covered by Stripe's privacy policy.

Removing them

Signing out clears the authentication cookies. You can clear all of them at any time through your browser's privacy settings.

Blocking the authentication cookies will prevent you from signing in — the rest of the site, including radio and shared song cards, still works signed out.