legal · cookies

Cookie Statement

Last updated 2026-07-28

Your choice

Necessary storage always runs. Anonymous audience measurement is opt-out; richer analytics and advertising are separate, default-off choices. Change or withdraw any choice here at any time:

 

What we use, by category

  • Authentication / sign-in (strictly-necessary) — Keeps you signed in after magic-link login so the account and dashboard work without re-authenticating each page. · no consent needed
  • Session (strictly-necessary) — Short-lived identifier tying together the requests in a single visit; carries no marketing data. · no consent needed
  • Security (CSRF / anti-abuse) (strictly-necessary) — Protects form and account actions against cross-site request forgery and abuse. · no consent needed
  • Rate-limiting & abuse prevention (strictly-necessary) — Enforces fair-use limits and detects automated abuse of the site and sign-in flow. · no consent needed
  • Essential preferences / UI state (strictly-necessary) — Short-lived non-tracking interface state needed for the site to behave as you requested. · no consent needed
  • Privacy choice (strictly-necessary) — Stores db-consent-v3 for up to 183 days so the site can honour separate Audience measurement, Analytics and Advertising choices; it is not used to track browsing. · no consent needed
  • Anonymous audience measurement (Vercel Web Analytics) (analytics) — Measures aggregate visits to query-free page paths with origin-only referrers and coarse device/geo. It sets no cookie or cross-site identifier; Vercel derives a visitor hash from the incoming request and discards/resets it within 24 hours. It runs unless you opt out and is disabled when the browser supplies Global Privacy Control or Do Not Track. · no consent needed
  • Performance analytics (Vercel Speed Insights) (analytics) — Measures query-free route performance and Core Web Vitals for consenting visitors. Loaded only after Analytics consent. · requires consent
  • Analytics (Google Analytics) (analytics) — Where configured, measures query-free pages and bounded events for consenting visitors. GA4 may set _ga and _ga_<measurement-id> first-party cookies for up to 2 years. Loaded only after Analytics consent; Google Signals and ad-personalisation signals are disabled in our GA4 tag configuration. · requires consent
  • Advertising (Google Ads) (advertising) — Where configured, measures conversions from paid-search ads using bounded conversion and transaction metadata. Loaded only after separate Advertising consent. We do not send form content, prompts, result rows or buyer email to Google Ads. · requires consent

Full statement

RxAtlas uses necessary storage for authentication, requested forms, security, rate-limiting, abuse prevention, essential interface state, and the privacy-choice record db-consent-v3. That choice record stores separate Audience measurement, Analytics and Advertising states, the notice version and decision/expiry times for up to 183 days; it does not record pages visited. Necessary storage runs regardless of your choices because it is required to deliver or secure a service you request. Anonymous audience measurement uses Vercel Web Analytics to count visits to query-free page paths with origin-only referrers and coarse device/geography. Vercel sets no cookie or cross-site identifier; it derives a daily visitor hash from the incoming request and resets/discards that identity within 24 hours. This aggregate measurement runs unless you opt out and is disabled when your browser supplies Global Privacy Control or Do Not Track. The separate Analytics choice is OFF until you opt in. If enabled, bounded Vercel custom events such as a successful sample evaluation or copied API request, Vercel Speed Insights Core Web Vitals, and, where configured, GA4 are collected. GA4 may set _ga and _ga_<measurement-id> first-party cookies for up to 2 years; we disable Google Signals and ad-personalisation signals in our GA4 tag configuration. Advertising is a separate, default-off choice. Where Google Ads is configured, it receives bounded conversion and transaction metadata only after Advertising consent. We do not send prompts, search text, form messages, emails, result rows, raw query strings, tokens, record IDs or buyer email to measurement or advertising services. Google runs in Basic Consent Mode: no Google code or request is loaded before the relevant opt-in. Reject all, Accept all and Manage choices are equally available; you can opt out of audience measurement or change or withdraw either opt-in purpose at any time on this page. Withdrawing reloads the page so optional scripts are removed and makes a best-effort deletion of first-party Google analytics/advertising cookies. We do not use session replay, cross-product identifiers, fingerprinting or behavioural advertising profiles, and we do not sell measurement-derived data. The REST API and MCP endpoint use request-header authentication rather than browser analytics cookies. Questions: data@apex-db.org. Last updated 2026-07-28.