Last updated: September 8, 2026
Grabbovoi uses browser storage for authentication, subscription state, and product preferences. We do not use tracking cookies, advertising pixels, or third-party analytics that profile you across the web. Your trade data, P&L, balances, and Supabase user ID are never written into an analytics or tracking payload.
When you sign in, Supabase sets an authentication cookie (usually sb-*-auth-token) scoped to .grabbovoi.com. It is HTTP-only, Secure, and SameSite=Lax. Its only purpose is to keep you signed in as you navigate. We do not read it in any analytics or tracking context.
When you activate a paid plan we set mogul_license and mogul_license_valid so we can gate paid features without a round-trip to Whop on every page. They contain your license key hash and a validation flag — never your card, address, or Whop identity.
We set an mg_session cookie to record the device+browser you're signed in from, so you can see the list under Settings → Active Devices and revoke a device you no longer control. The cookie only stores an opaque identifier; the actual device metadata lives server-side.
If you land on the site via a ?ref=CODE link, we stash the code in a 30-day cookie so the referring user is credited when you subscribe. If you don't arrive via a referral, no such cookie is set.
localStoragelocalStorage keeps product state that must survive a page refresh but doesn't need to sync across your devices. Keys are prefixed grabbovoi_(some legacy mogul_ keys still exist during the migration window). Categories:
grabbovoi_legacy_archive_v1key holding a compressed backup of your pre-migration keys, in case a feature needs to restore the old shape. See Settings → Data Management → "Restore Legacy Data".We collect two categories of server-side telemetry, both scoped narrowly:
/api/perf/vitals): Core Web Vitals numbers (LCP, CLS, INP, TTFB) and the pathname you were on. This lets us diagnose performance regressions. The endpoint strictly rejectsany payload that carries a Supabase user ID, a P&L number, or a trade field. It is not shared with advertisers or third-party analytics networks./api/avatar/discord): when another user has opted into showing a Discord photo, our server fetches the image from cdn.discordapp.com and re-serves it to your browser from our own origin. This means your browser never contacts Discord on our behalf. The endpoint caches responses for 24 h and only accepts well-formed Discord user IDs + avatar hashes.Questions about what we store in your browser? Email support@grabbovoi.com.