Cookie Policy
Last updated August 27, 2026
Every cookie inbl.link sets is strictly necessary. There are no advertising or tracking cookies, which is why there's no consent banner.
The short version. We set cookies to keep you signed in, to remember that you've unlocked a download, and to secure the SoundCloud login handshake. That's the entire list. Our analytics don't use cookies at all.
Why there's no cookie banner
Consent banners exist because most sites load advertising and cross-site tracking cookies, which require permission. We don't load any. Everything below is necessary to deliver a feature you asked for, which is exempt from consent requirements under EU, UK, and Canadian rules.
Specifically, we avoided the usual sources of tracking cookies:
- Analytics. We self-host Umami, which is cookieless and doesn't store anything on your device. See the Privacy Policy.
- Fonts. Served by inbl.link itself, not a font CDN.
- Music players. Our SoundCloud players stream through inbl.link rather than embedding SoundCloud's widget, so SoundCloud doesn't set cookies on you while you browse a creator page.
- Advertising. We run none.
Cookies on public pages
These may be set when you visit a creator page, release page, or download gate.
| Name | Purpose | Expires |
|---|---|---|
inbl_g_... |
Remembers that you unlocked a specific download gate, so you don't have to complete the steps again. One per gate. Contains a random token, not your email. | 7 days |
sc_oauth_state |
Security check that protects the SoundCloud login from being hijacked | 10 minutes |
sc_oauth_verifier |
Cryptographic proof tying your SoundCloud login back to the browser that started it | 10 minutes |
sc_oauth_gate |
Remembers which gate you were on so you land back in the right place | 10 minutes |
sc_oauth_comment |
Holds the comment you typed while you're away at SoundCloud, if the gate asks for one | 10 minutes |
sc_oauth_unlock |
Preserves progress you'd already made on the gate during the SoundCloud round trip | 10 minutes |
The five sc_oauth_* cookies only appear if you start a SoundCloud connection, and
they're deleted as soon as you come back. All of them are HTTP-only, meaning scripts on the page
can't read them.
Cookies when you're signed in
These appear only once you have an account and are using the creator dashboard.
| Name | Purpose | Expires | Set by |
|---|---|---|---|
__session |
Keeps you signed in as you move between pages | Session | Clerk |
__client_uat |
Keeps your sign-in state in sync across tabs | 1 year | Clerk |
_cfuvid |
Security and abuse protection on the sign-in service | Session | Cloudflare, via Clerk |
inbl_profile |
Remembers which of your creator pages you were last editing | 1 year | inbl.link |
onboarding_bypass |
Short-lived marker used while you finish signing up | 2 minutes | inbl.link |
We also briefly use your browser's session storage during sign-up to hold the username you're claiming. It's cleared when you finish.
Embedded content
If a creator adds a YouTube video to their page, that video loads from YouTube's privacy-enhanced
domain (youtube-nocookie.com). It doesn't set identifying cookies unless you press
play, at which point YouTube's own privacy policy applies to that playback.
Links out to Spotify, Apple Music, Bandcamp and similar are ordinary links. Nothing loads from those sites until you click through.
Controlling cookies
You can block or delete cookies in your browser settings — look under Privacy in Chrome, Firefox, Safari, or Edge. If you block ours, sign-in won't persist and you'll have to complete a download gate's steps every time you return to it.
Changes
If we ever add a cookie that isn't strictly necessary, we'll update this page and add a proper consent control before it's set. We have no plans to.