Cookie Policy
This Cookie Policy explains what browser cookies are, which ones SINK uses today, and how you can manage them.
1. Introduction
Cookies are small text files that a website stores in your browser so core features can work across requests. SINK uses only the minimum cookie footprint needed for authentication, and uses browser storage separately for some player and interface preferences.
2. Strictly necessary cookies
Every cookie SINK sets is strictly necessary, and all of them are first-party. One keeps you signed in; the rest exist only for the few minutes a sign-in, a provider link, or an email change is in progress, and are discarded as soon as it finishes. You cannot disable these and still use the parts of the service that require an account.
| Cookie name | Purpose | Duration | First or third party |
|---|---|---|---|
| authjs.session-token or __Secure-authjs.session-token | Keeps you signed in to your SINK account and protects authenticated requests. | Up to 30 days, with renewal while your session remains active. | First-party |
| authjs.csrf-token, authjs.callback-url, authjs.state, authjs.pkce.code_verifier, authjs.nonce (with __Host- or __Secure- prefixes over HTTPS) | Set by Auth.js during sign-in to protect the form against cross-site request forgery and to carry the return address and the OAuth state, nonce, and PKCE values. | The sign-in attempt only — removed when it completes or the browser closes. | First-party |
| sink_oauth_login_challenge | Carries the encrypted one-time login handoff after you sign in with Google, Facebook, or Apple. | 12 minutes | First-party |
| sink_link_token | Carries the handoff when an existing account has to confirm its password before a new sign-in provider is linked. | 5 minutes | First-party |
| sink_oauth_link_pkce_<provider> and sink_oauth_email_change_<provider> | Hold the PKCE verifier and the email-change context while you link a provider or change your email address in Settings. | 10 minutes | First-party |
3. No analytics, advertising, or tracking cookies
SINK performs no website or product analytics. There is no analytics tag, no measurement or advertising cookie, no remarketing pixel, and no third-party tracker on any page — so there is nothing to consent to and no analytics preference to manage. The browser error reports that keep the service working are cookie-free and build no behavioural profile.
4. How to manage cookies
Most browsers let you inspect, block, or delete cookies in their privacy or security settings. If you clear or block the SINK session cookie, you may be signed out and need to sign in again.
5. Contact
If you have questions about this Cookie Policy, contact hello@sink.fm.
6. Last updated
Last updated: July 30, 2026
