This Cookie Policy explains cookies and similar technologies used by the REAB website and related features. Read it with our Privacy Policy, which explains the personal information involved, recipients and privacy rights. “REAB,” “we,” “us” and “our” refer to the business providing the REAB service.
1. What these technologies do
Cookies are small values stored by a browser and sent with relevant requests. Local storage keeps information in a browser until the site or user removes it; it does not necessarily have an automatic expiry. Session storage is generally limited to a browser tab's session. Pixels, tags and scripts can send events to a provider without creating a visible cookie. Mobile apps may use app storage, device identifiers and SDKs for similar purposes.
First-party technologies are set in connection with REAB's domain or service. Third-party technologies involve another provider, such as a payment, sign-in, mapping or advertising service. A session cookie normally lasts for a browser session, although browser session-restoration settings may retain it longer. A persistent cookie has a specified expiry, which can be refreshed when the service uses it again.
2. Purposes
We use storage and related technologies for:
- Sign-in and security: maintaining an authenticated session, protecting sign-in requests, verifying connection flows and supporting fraud prevention.
- Service features and preferences: remembering interface choices, location settings, banner selections and cached data so requested features can work efficiently.
- Usage and performance: recording viewing or interaction activity, understanding visits, diagnosing errors and improving service reliability.
- Referrals and advertising: attributing affiliate referrals, measuring campaigns and using advertising or audience-measurement integrations where enabled.
A technology's legal classification depends on its actual use and the rules that apply where you are. Its appearance in the table below does not by itself mean it is strictly necessary or exempt from consent requirements.
3. REAB cookies and browser storage
The following inventory describes storage implemented in REAB's website and referral service. Names can carry a secure prefix or additional suffix depending on the environment and account. Items are only present when the relevant feature or code path runs.
| Name or group | Provider and storage | Purpose | Lifetime or clearing behavior |
|---|---|---|---|
next-auth.session-token or __Secure-next-auth.session-token, including numbered chunks |
REAB; cookie | Maintains your signed-in website session. | Up to 30 days under the current session configuration; expiry can be refreshed during use. Sign-out removes the session cookies. |
next-auth.csrf-token or __Host-next-auth.csrf-token; next-auth.callback-url or its secure variant |
REAB; cookies | Protects sign-in requests and remembers the return address for authentication. | Normally browser-session cookies. |
| Authentication state, nonce and PKCE cookies, when used by the selected sign-in flow | REAB; cookies | Verifies an authentication redirect and protects the sign-in exchange. | Short-lived; state and PKCE cookies are configured for up to 15 minutes and are cleared as the flow completes. |
geo-data, geo-loaded, geo-timestamp, geo-timestamp-public |
REAB; cookies | Caches location inferred from your connection, such as country, region or city, and tracks when that cache was refreshed. Cached details can include an IP address and approximate coordinates. | Four hours; can be refreshed by later requests. |
browser_unique_id |
REAB; cookie | Distinguishes a browser for service and activity-related requests. | Browser session; no fixed persistent expiry is set by this cookie. |
sidebar:state, sidebar_state |
REAB; cookies | Remembers whether a website sidebar is expanded. | Seven days, refreshed when updated. |
affiliate_ref |
REAB referral service; cookie | Attributes an eligible visit or signup to an affiliate referral. Referral click records can also be kept on the server. | 30 days. Removing the cookie does not erase an attribution already recorded against an account or transaction. |
cookie-consent |
REAB; local storage | Remembers the banner's Accept or Decline selection so it is not repeatedly displayed. | No automatic expiry; remains until removed by the site or browser-data controls. |
sidebar:open, persist:root |
REAB; local storage | Remembers interface state, including sidebar and banner preferences. | No automatic expiry; remains until removed or replaced. |
userInterests |
REAB; local storage | Stores interest selections used by the interest-selection interface. | No automatic expiry; remains until removed or replaced. |
reab_recent_searches |
REAB; local storage | Remembers up to five recent search queries for the search interface. | No automatic expiry; remains until removed or replaced. |
globalMute, globalVolume, globalPlaybackRate, globalQuality |
REAB; local storage | Remembers video sound, playback speed and quality choices. | No automatic expiry; remains until removed or replaced. |
Keys beginning sidebar:following: |
REAB; local storage | Caches a small following-list result for the sidebar. | The application accepts the cache for 15 minutes and removes expired values when read; a value can remain in storage until read or cleared. |
REACT_QUERY_OFFLINE_CACHE |
REAB; local storage | Caches selected account statistics or other eligible query results for reuse. | The application accepts cached data for up to 24 hours and clears account caches on sign-out or account change; a stored value may remain until the application next handles it or you clear site data. |
feed-cache-storage, byte-cache-storage |
REAB; session storage | Caches feed and Bytes data within a tab. | Browser-tab session. |
byte-follow-overrides-v1, byte-impressions-v1 |
REAB; session storage | Remembers follow changes and viewing-event state, including avoiding duplicate impression events within a session. | Browser-tab session. |
videos-last-slug, byte_entry_path, home_page_loaded, home_page_session_id, and keys beginning home_scroll_ or feed-scroll- |
REAB; session storage | Remembers navigation, the last selected video and scroll position when returning to a feed. | Browser-tab session; some entries are removed after use or on refresh. |
reab_open_in_app_dialog_seen, reab.affiliate.attribution_claimed, __chunk_reload_ts |
REAB; session storage | Avoids repeated app-opening prompts, duplicate referral-claim requests and repeated error-recovery reloads. | Browser-tab session. |
oauth_platform, oauth_auth_data |
REAB; local storage | Keeps connection-flow details while you authorize an external social account, including authorization-flow verification information. | Cleared by the completed connection flow; abandoned flows can leave values until removed or replaced. |
Keys beginning reab.nudge. |
REAB; local storage | Limits repeated prompts, such as requests to add a phone number or enable notifications, by storing counts and timestamps. | No general automatic expiry; some values are cleared when the relevant action is completed. |
reab-video-lab-session, reab-video-lab-bandwidth-bps, reab-video-lab-bench-v2, where the diagnostic feature is used |
REAB; session storage | Keeps video-test session, bandwidth estimate and comparison results. | Browser-tab session. |
reab-video-lab-browser, reab-video-lab-clean-run-started-at, where the diagnostic feature is used |
REAB; local storage | Keeps a video-test browser identifier and diagnostic run marker. | No general automatic expiry; the run marker can be cleared through the diagnostic feature. |
The lifetime of browser storage is different from the retention of related server records. Clearing a cache or cookie does not automatically delete your account, purchase history, uploaded content or activity already received by a provider.
4. Provider technologies
The following integrations may use their own storage, identifiers or network requests. Availability depends on the feature, environment, provider configuration and browser settings.
| Provider or integration | Use on REAB | Storage and duration |
|---|---|---|
| Google Tag Manager and tags configured through it | Loads configured measurement or marketing tags and receives page or interaction information. The container can change independently of the website code. | Tag Manager does not establish one universal cookie list. Individual tags determine identifiers, cookies and expiry. Read Google's cookie information. |
| Meta Pixel | Sends page-view and configured interaction events for campaign measurement and advertising. Information can include device, browser and page details. | Cookies or identifiers and their lifetimes depend on Meta's configuration and browser permissions. Read Meta's Cookie Policy. |
| Google sign-in and reCAPTCHA, where used | Enables sign-in and helps detect automated abuse or protect forms. | Provider-controlled cookies or other signals can be used during the relevant flow. See Google's Privacy Policy. |
| Oxam/Chatwoot support chat, where enabled | Maintains a help conversation and associates it with a guest or signed-in user. The widget can use a cookie named cw_user_ followed by the widget identifier. |
Cookie and other storage lifetimes are set by the deployed support widget. REAB resets the widget on sign-out; the chat transcript is a separate server record. |
| Stripe, PayPal, app stores and other payment interfaces | Processes a payment, maintains checkout state and supports payment security or fraud detection. | Provider-specific storage can be set when you use its payment interface. See Stripe privacy information and PayPal privacy information. |
| Embedded, mapping, video or partner features | Delivers the requested content or partner functionality, including locations and mini-app purchases. | Storage and identifiers depend on the selected feature and the provider's notice. |
The production website enables Google Tag Manager and Meta Pixel on configured REAB domains. Loading may be deferred until interaction or a short idle period; that delay is not a consent decision. Some no-script tracking requests can also occur when JavaScript is unavailable. Local development does not run these production-domain tracking integrations by default.
Cookies set by a changing tag container or an independent provider cannot be completely identified from REAB's source code alone. Their exact names and lifetimes depend on the active configuration and provider updates. This inventory therefore distinguishes the known REAB storage periods from provider-controlled technologies.
5. Your choices and the current banner
The current website banner saves whether you select Accept or Decline, and closing it records Decline. That selection hides the banner. It does not currently prevent Google Tag Manager or Meta Pixel from loading and does not provide separate category controls. Do not rely on the banner's Decline selection as an advertising or analytics opt-out.
You can use your browser's privacy settings to block or delete cookies, clear REAB site data, restrict third-party storage or limit tracking. Blocking only cookies may not stop a script or pixel from sending a network request. Stronger browser tracking protection or content-blocking controls may have a broader effect. Clearing site data can sign you out and reset preferences, caches and the banner selection. Blocking storage can also disrupt sign-in, payments or other features.
Google and Meta provide account and advertising controls under their own notices. A provider's control does not necessarily block every request from REAB or erase data already collected. Browser choices apply to that browser or profile and may need to be repeated on other devices. Private browsing may still allow storage during the session.
Where applicable law requires consent or gives you an opt-out right, that requirement remains applicable regardless of a technology's label in this Policy. Contact support@reab.com with questions or a privacy request, including any request relating to targeted advertising, sale or sharing available under your local law.
6. Mobile apps and external sites
Mobile apps may use app storage and SDKs for authentication, feature settings, notifications and diagnostics, rather than browser cookies. Device settings can control permissions, notifications and some advertising identifiers. Deleting browser cookies does not clear mobile-app storage or affect all SDK activity. The Privacy Policy and any relevant mini-app notice explain additional information involved in those features.
If you follow a link or use an independent partner interface, that service may set its own storage and apply its own privacy controls. Review its notice before using it.
7. Changes and contact
We may update this Policy when storage, providers, controls or legal requirements change. The effective date appears on the policy page. For questions about cookies, browser storage or privacy choices, contact support@reab.com.