Skip to content
Last Updated
|
August 15, 2026

Cookie Policy

Information about the use of cookies on JamBench

Summary

  • ✓ No third-party advertising cookies and no tracking for ads
  • ⚠ First-party attribution/measurement (bb_utm, yt_attr, bb_utm_pending) — named in the tables, not essential
  • ⚠ YouTube videos require your consent before loading
  • ⚠ Campaign attribution (yt_attr) only after consent at sign-up

1. What are Cookies?

Cookies are small text files that websites store on your device. They help save your settings and keep you logged in.

In addition to cookies, we also use similar technologies such as Local Storage and Session Storage, which are also covered in this policy.

2. Types of Cookies

We distinguish between different types of cookies:

By Origin:

  • First-party cookies: Set by JamBench itself
  • Third-party cookies: Set by external services (e.g., Supabase for authentication)

By Duration:

  • Session cookies: Deleted when you close the browser
  • Persistent cookies: Stored for a defined period

3. Cookies & Storage

JamBench sets first-party cookies plus Local Storage and Session Storage. Strictly necessary entries (sign-in, UI, cache-bust) do not require consent. YouTube embeds and the campaign cookie yt_attr require your consent. First-party measurement (bb_utm / bb_utm_pending / bb_utm_clear) is listed in the table and is not essential.

3.1 Authentication (Supabase)

CookiePurposeDuration
sb-*-auth-tokenMaintains your login sessionSession / Persistent
sb-*-auth-token-code-verifierPKCE authentication flowSession

3.2 Functional Cookies (JamBench)

CookiePurposeDuration
geo-countryCountry code for regional display (e.g. date and number formatting). Not HttpOnly; Secure; SameSite=Lax.1 hour
sidebar_stateStores the sidebar state (open/closed)7 days
oc_okAuth performance cache (prevents redundant database queries). HttpOnly, Secure, SameSite=Lax.24 hours
ob_doneOnboarding completion marker for middleware routing logic2 minutes
bb_r301Cache-bust: one-time HTTP cache wipe so stale permanent redirects (e.g. old 301s) do not apply. Set for all visitors. HttpOnly, Secure, SameSite=Lax. Not a login cookie.1 year

Legal basis: § 25(2) No. 2 TDDDG – no consent required as these cookies are strictly necessary for providing the function explicitly requested by the user.

3.3 Local Storage / Session Storage (app preferences)

The following entries remember UI and session state on your device. We do not store an anonymous visitor ID (no bb_anon_presence_id) and we do not send presence heartbeats for logged-out visitors.

KeyStoragePurposeDuration
jambench_preferences_*Local StorageUI preferences (theme, metronome) for signed-out users. After sign-in, preferences are stored server-side.Until cleared
jambench_active_verticalLocal StorageSelected instrument (e.g. “bass”)Until cleared
jambench-content-zoomLocal StorageApp interface zoom levelUntil cleared
kb.sectionViewMode.*Local StoragePractice mode per song/resourceUntil cleared
kb.practiceModal.layoutLocal StoragePractice modal layout (songs and setlists)Until cleared
bb_youtube_volume_v1Local StorageYouTube player volumeUntil cleared
bench:timeline-zoomLocal StoragePractice timeline zoom levelUntil cleared
bb_section_walkthrough_v1_completedLocal StorageRemembers that the section walkthrough has been completedUntil cleared
bb_subsection_drag_hint_v1Local StorageOne-time hint for dragging subsectionsUntil cleared
jambench_session_draft_*Local StorageShort-lived practice-session draft if a save is interruptedUntil successful save or deletion
bb_session_heartbeat_activeLocal StorageCross-tab signal that a practice session is active (signed-in only)Until session end / cleared
bb.journal.scheduledSlotsLocal StorageLocally remembered practice slots pushed to the calendarUntil cleared
jambench_bands_fixture_v1Local StorageLocal band workspace (draft/prototype data on the device)Until cleared
currentUserIdSession StorageTechnical user ID for session navigation (signed-in only, stays in the tab)Browser tab
selectedLibraryPresetId_*Session StorageLast selected library exercise per instrument/workspaceBrowser tab
bb:scrollToPresetIdSession StorageScroll target after navigating to the libraryBrowser tab
sw-update-notifiedSession StoragePrevents a duplicate service-worker update noticeBrowser tab
bb_section_walkthrough_v1_pendingSession StorageSection walkthrough still pending in this tabBrowser tab
jambench_explicit_session_started_atSession StorageTimestamp when you explicitly started a practice sessionBrowser tab
yt_consent_songs_strip_dismissedSession StorageHides the YouTube consent strip on /songs for this tab (“Not now”)Browser tab

Legal basis: § 25(2) No. 2 TDDDG – no consent required; these entries are necessary for the app function explicitly requested (preferences, navigation, practice flow).

3.4 Consent-based (YouTube & campaign attribution)

yt_attr is set when you agree to the Terms of Service and Privacy Policy at sign-up (checkbox on the registration form). For users who are already signed in, the same cookie may also be set when they open a campaign link (/yt/…, /c/…).yt_consent is set only after you allow YouTube to load in the player.

KeyStoragePurposeDuration
yt_attrCookieCampaign attribution: stores utm_source, utm_medium and utm_campaign (JSON) so we can measure which video or Short brought you to JamBench. Not shared with any third party.30 days
yt_consentLocal StorageStores your consent to load the YouTube player (true/false). YouTube is not loaded without this consent.Until revoked / browser data cleared

Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent). You can delete these entries in your browser settings at any time. Using JamBench without the YouTube player is unaffected.

3.5 First-party measurement (attribution)

These entries measure our own campaigns and traffic source (where a registration came from). They are not strictly necessary cookies under § 25(2) No. 2 TDDDG. This is first-party measurement, not third-party advertising cookies. Contents: UTM parameters and, where present, the HTTP referrer; not shared with ad networks.

KeyStoragePurposeDuration
bb_utmSession StorageFirst-touch source in this tab (utm_source, utm_medium, utm_campaign, utm_content, utm_term, signup_referrer). Cleared after successful registration or when the tab is closed.Browser tab
bb_utm_pendingCookieShort-lived hand-off of UTM/referrer data to the OAuth/magic-link callback after the sign-up click. SameSite=Lax, not HttpOnly.1 hour
bb_utm_clearCookieTells the client to clear bb_utm after a successful callback. Value “1”.2 minutes

Legal basis: first-party measurement / legitimate interest in understanding the effectiveness of our own content (Art. 6(1)(f) GDPR). Not described as strictly necessary under § 25(2) No. 2 TDDDG.

4. Third-Party Services & Consent

The following third parties are integrated. Essential services are loaded without consent; for YouTube we collect your consent in advance:

Supabase (Authentication)

We use Supabase for user authentication. This sets the essential authentication cookies listed above.

YouTube (Video Embedding)

JamBench embeds YouTube videos for song playback. Before a video is loaded, we ask for your consent. Only after you click "Allow & load video" will the YouTube IFrame API be loaded — at which point YouTube may set its own cookies to operate the player and collect usage statistics.

Your consent is stored in your browser's Local Storage under (yt_consent) and remains valid until you revoke it. You can revoke consent at any time by clearing the browser storage for this site.

5. Cookie Management

For essential cookies (authentication, UI preferences, cache-bust) no consent is required. For YouTube videos we ask directly in the player for your permission before the YouTube API is loaded. First-party measurement (bb_utm) is described in section 3.5.

You can manage cookies and local storage entries through your browser settings:

  • Chrome: Settings → Privacy and Security → Cookies
  • Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Cookies
  • Edge: Settings → Cookies and site permissions

Note: Blocking essential cookies will prevent you from logging in to JamBench.

The use of cookies is based on the following legal ground:

  • Essential & functional cookies (sb-*, geo-country, sidebar_state, oc_ok, ob_done, bb_r301): § 25(2) No. 2 TDDDG in conjunction with Art. 6(1)(b) and (f) GDPR — no consent required, as strictly necessary for operation and the function explicitly requested by the user
  • Local Storage / Session Storage (app preferences) (jambench_preferences_*, jambench_active_vertical, jambench-content-zoom and others in table 3.3): § 25(2) No. 2 TDDDG — no consent required; technical UI and session preferences
  • YouTube videos (yt_consent): § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR — consent required; collected before the player is loaded
  • Campaign attribution (yt_attr): Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG — consent required; collected at sign-up
  • First-party measurement (bb_utm, bb_utm_pending, bb_utm_clear): Art. 6(1)(f) GDPR — internal traffic/campaign attribution, not strictly necessary storage under § 25(2) No. 2 TDDDG, not third-party ad cookies

Should we introduce third-party analytics or advertising cookies in the future, we will update this policy and obtain your consent. The first-party attribution entries above are listed in full in the tables.

Questions about cookies?

Contact us: damir@jambench.com

More Legal Information

© 2026 jambench.com. All rights reserved.