Last updated 11 September 2026
This page explains the cookies and similar browser-storage technologies used by the Wheel of Misfortune website. Our own application code does not currently set a first-party HTTP cookie. It uses browser local storage for your storage-notice acknowledgement and, after you sign in, your Supabase authentication session. The Cloudflare Turnstile security check may use provider-controlled storage when it runs.
| Item and provider | Data, purpose and when it is created | Duration and status |
|---|---|---|
wom_cookie_consentWheel of Misfortune, browser local storage |
A policy version, timestamp and acknowledgement that essential storage is in use. It is created only after you dismiss the storage notice and prevents the same notice being shown on every page. It does not record consent for analytics or advertising. | Until you clear site data, reset the notice, or we change the policy version. Strictly necessary preference |
sb-…-auth-tokenSupabase, browser local storage |
Your access and refresh tokens and associated account/session metadata. It is created after account creation or sign-in and lets the website authenticate requests and refresh a valid session without asking you to sign in on every page. | Until you sign out, clear site data, or the session is expired or revoked under the authentication settings. Strictly necessary authentication |
sb-…-auth-token-code-verifierSupabase, browser local storage |
A temporary PKCE verification value may be created during an email recovery or other secure authentication redirect. It allows Supabase to verify that the browser completing the flow is the browser that started it. | Temporary for the authentication flow and removed or replaced by the authentication library when no longer required. Strictly necessary security |
| Turnstile challenge storage Cloudflare |
Cloudflare Turnstile processes a security challenge on sign-in, sign-up and the public security-report form. Cloudflare may read or store challenge information needed to detect automated abuse. If Turnstile pre-clearance is enabled, it can issue a cf_clearance cookie for the protected domain. |
Only when the protected form or challenge runs. Any provider-controlled duration depends on the Turnstile security configuration. Strictly necessary security |
| Analytics and advertising storage | None currently used. We will update this table and obtain consent before enabling any non-essential analytics or advertising storage. | Not active |
No optional analytics or advertising technology is active, so there is currently no optional category to accept or reject. The notice records only that you have seen it. Strictly necessary authentication and security storage remains available because the account and protected forms cannot work without it.
You can reopen the notice at any time:
Signing out asks Supabase to end the current authentication session and removes its local session from this browser. You can also remove the consent record, authentication values and other site data using your browser’s controls for this domain. Clearing authentication storage signs you out but does not delete your account or server-side game records. To request deletion of server-side personal data, use the contact details in our Privacy Policy.
Cloudflare-controlled challenge data may be stored under a Cloudflare or protected-site scope. Your browser’s cookie and site-data controls can display and remove it; removing it may cause the security challenge to run again.
Supabase receives authentication requests and session tokens. Cloudflare Turnstile receives security signals including IP address, user-agent, sitekey, origin and browser or TLS characteristics when a protected form runs.
Public pages also load typefaces from Google Fonts. That request sends ordinary network information such as IP address, user-agent and the requested font resource to Google, but our code does not use Google Fonts to place or read browser storage. Resend sends email and does not need to place storage in your browser through this website. See the Privacy Policy for the personal data these services process away from your device.
Most browsers let you inspect, block or remove cookies and site storage. Blocking all local storage will prevent persistent sign-in and may stop authentication recovery from completing. Browser controls affect only that browser and device.
See our Privacy Policy for how we handle your personal data, and our Terms of Use - Wheel of Misfortune is a game for entertainment only and is not financial advice.
For anything about your data, contact us at privacy@wheelofmisfortune.co.uk.