Rebutta
← Home

Cookie policy

Version 2.0 of 6 August 2026. Draft prepared for review by our law firm.

English translation of the Polish original published at cookies.html. The Polish version is the binding one - if the two ever differ, it prevails.

Why you are seeing a consent banner

Because since August 2026 we have something to ask about: we run advertising campaigns on Meta services (Facebook, Instagram) and we want to know which of them bring in customers. The tool for that is the Meta pixel - a piece of code that tells Meta about your visit and about whether it ended in creating an account.

Without your consent we do not run it at all. Declining takes one click, is displayed exactly as prominently as agreeing, and limits nothing in your use of Rebutta.

Apart from the pixel there are only two cookies left, the ones without which the service would stop working: one keeps you signed in, the other protects sign-in through Google. For cookies strictly necessary to provide the service requested by the user, consent is not required (Article 398(3) of the Polish Electronic Communications Law, implementing Article 5(3) of Directive 2002/58/EC), so we do not ask about them.

The pixel starts only after you click to agree, never earlier. That is the one banner defect that actually costs something, so a separate automated test guards it. We also deliberately do not use the <noscript> version of the pixel - that one would fire without asking anybody for anything.

---

The full list

NameSet byPurposeLifetimeType
lc_sessionrebutta.appkeeps you signed in; without it every click would require signing in again30 daysstrictly necessary
lc_google_stanrebutta.appprotects Google sign-in against a forged cross-site request (CSRF)until sign-in completes, no longer than 10 minutesstrictly necessary
_fbprebutta.appMeta pixel: recognising the same browser between visits, so that ad performance can be counted90 daysmarketing, only with consent
facebook.com cookiesMeta Platforms Irelandlinking the visit to your Facebook or Instagram account, if you are signed in thereas per Meta's policymarketing, only with consent

Both of our own cookies are set with the HttpOnly flag (a script on the page cannot read them), SameSite=Lax (they are not sent with requests coming from other sites) and Secure in the production environment (transmitted over HTTPS only).

lc_session contains a signed session token. It contains no password and no personal data in readable form.

---

What is not here

---

How to remove them

Every browser lets you delete cookies and block them from being stored. Blocking lc_session will make signing in to Rebutta impossible - that is not a restriction on our side, it is simply what happens when the browser has no way of remembering the session.

---

Our other documents

The terms of service, the privacy policy, the data processing agreement, the list of sub-processors and the security description are currently published in Polish only: Terms, Privacy policy, Data processing agreement, Sub-processors, Security. Ask us and we will walk you through any of them in English.

Questions: kontakt@rebutta.app.