Sign-in cookies
When you sign in, Showcase sets showcase-access-token and showcase-refresh-token. They keep your account session working and allow a session to be renewed. Both are HTTP-only, SameSite=Lax, and sent only over HTTPS on a secure deployment. Each is configured for a maximum of 30 days; signing out or completing account deletion clears them.
Preferences and local storage
Your chosen light or dark theme is saved as showcase-theme in local storage. A versioned Showcase query cache can retain deliberately public page data for up to 30 days only after you opt in below. Referral codes you use for onboarding or a launch waitlist can also be remembered locally so the referral survives navigation; onboarding codes are removed after account setup, and waitlist codes after a successful join or when you clear site data.
Temporary session storage
Within a browser tab, Showcase may keep a presentation-only session snapshot for up to 12 hours, selected private workspace query snapshots for up to 30 minutes, and in-progress checkout or boost state while you complete an action. Authentication remains controlled by the server-side session, not these browser snapshots. Signing out clears Showcase’s session snapshot and private query cache.
Security and external services
The sign-in flow may load Cloudflare Turnstile to protect against automated abuse. Payment checkout, avatar images, and externally hosted media may contact their respective providers when you use those features. Those providers may operate their own storage under their policies; Showcase cannot control storage on another site after you leave Showcase.
Product Analytics on Builder websites
Showcase does not automatically install the Product Analytics script across Showcase pages. A Builder can install it on a separate Product site. That script is designed to collect only after the Product site grants consent; after consent it can store a Product-scoped anonymous browser ID in local storage and a session marker in session storage. Builders must provide their own appropriate notice and consent mechanism for their sites. Denying consent prevents that script from collecting events.
Your controls
You can sign out to clear authentication cookies, change your theme at any time, and clear Showcase site data in your browser to remove local or session storage. Clearing sign-in cookies signs you out; clearing optional cached data may make the next page load slower. For Product Analytics on another site, use that site’s consent controls or ask its operator to withdraw consent.
Changes
We update this inventory when the site adds, removes, or changes storage technologies. The Privacy policy explains the wider processing of account, Product, payment, and community information.

