Last updated: September 2026
This register lists every cookie and similar technology DMflux uses, per our obligations under the Nigeria Data Protection Act 2023 and its GAID 2025. We keep it deliberately short because we use almost none.
These cookies are set by Supabase Auth on hub.dmflux.app when you sign in. They cannot be disabled without breaking sign-in, and they are not used for any other purpose.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
sb-* auth cookies | Supabase Auth · First party | Keeps you signed in and refreshes your session securely | Session / up to 1 week |
sb-* PKCE code verifier | Supabase Auth · First party | Completes email-confirmation and password-reset flows safely | Minutes (deleted after use) |
sb-* auth cookiessb-* PKCE code verifierWhen someone clicks a DMflux tracking link, the redirect is handled entirely server-side. To count clicks accurately we read what every HTTP request naturally contains — timestamp, IP address, user-agent, and language header — and combine them into a one-way hash for duplicate detection. This is described fully in the Privacy Policy.
No JavaScript executes on the visitor, no cookies or other storage are placed on the visitor’s device, and the short-lived deduplication record (used to filter accidental double-taps) expires server-side within minutes.
You can clear or block cookies in your browser settings at any time; blocking the strictly necessary dashboard cookies simply signs you out.
Click records on advertiser campaigns are pseudonymous — we deliberately store no persistent identifier on your device, so a click cannot be traced back to you as an individual. Because of this, DMflux cannot attribute your future clicks to you and therefore cannot offer an individual opt-out that suppresses only your clicks. If you do not want your clicks recorded at all, simply do not open DMflux tracking links. Campaign owners can have a campaign’s click history deleted on request, as described in the Privacy Policy.