Skip to content

CryptoMetric AI Cookie Notice — counsel-review draft

Draft description of browser storage; the production inventory and retention values require verification.

Draft status

This notice was drafted on 20 September 2026 and is not effective. It must be reconciled against a production browser-storage scan before publication.

Cookies and similar storage

Cookies are small values stored or read by a browser. Similar technologies may include local storage. The final inventory must identify the operator, purpose, type, duration and access for every item rather than relying on broad category labels.

Strictly necessary storage

The current design expects first-party session and anti-forgery cookies needed for authentication, request integrity and security. Browser local storage is also used for a user-selected theme and for `notification_read_ids`: up to the 500 most recently persisted risk-event identifiers used to remember notification read state in that browser. The identifier list is not notification text, but it may be personal data when linked to an account or activity. It has no fixed expiry, remains until overwritten, evicted or the user clears site data, and is not currently cleared automatically on logout or account closure. Storage that is genuinely necessary for a requested service does not depend on optional marketing consent, but it must still be described and protected.

[PENDING verified cookie and local-storage names, providers, precise purposes, lifetimes, browser/account separation, SameSite/Secure/HttpOnly attributes and deletion behavior from a production scan; counsel must confirm the lawful basis and ePrivacy treatment of each item].

Optional analytics and marketing

The planned launch does not include advertising or optional analytics tracking. If optional storage is introduced, it must remain disabled until valid consent, offer an equally prominent refusal, be withdrawable as easily as it was given, and be added to a new notice and verified inventory before use.

Browser and account controls

Users can use service controls and browser settings to remove or block storage. Blocking necessary session or anti-forgery storage may prevent sign-in or protected actions. Withdrawing optional consent must not remove access to functions that do not require that optional storage.

Contact and changes

Questions go to the literal privacy contact in the publisher snapshot once confirmed. A new version will be published before categories or purposes materially change; where consent is required, updating this notice is not a substitute for obtaining it.

Primary sources