1. Cookies versus local storage
A cookie is information a website or provider can ask a browser to store and send with later requests. Local storage is a browser-based store that does not automatically accompany every request. Both can remember preferences or sessions. Some third-party service providers can set cookies independently of RatesLab application code.
2. Technologies identified in the current implementation
| Technology | Purpose | Category | Where it operates |
|---|---|---|---|
| Supabase Auth session storage | Keeps invited users signed in and refreshes authentication state | Essential for signed-in tools | Browser local storage / authentication provider |
| RatesLab selected capital preference | Remembers a selected illustrative investment amount between pages | Functional preference | Browser local storage |
| Active simulation preference | Remembers the user's active educational simulation in the browser | Functional preference | Browser local storage |
| Cloudflare Access | Authorises and protects restricted administrator resources | Essential security | Cloudflare-managed session mechanisms on protected paths |
| Cloudflare / service-provider security and diagnostics | Protects service availability, mitigates abuse and logs technical requests | Essential security / operations | Hosting or delivery infrastructure |
Individual cookie names, exact provider-set lifetimes and the current Cloudflare dashboard analytics configuration require a live-browser and account-settings inventory; the source repository does not establish every edge-set cookie.
3. Analytics and non-essential tracking
RatesLab may have infrastructure-level traffic measurement or analytics enabled independently of application source code. The current repository review does not establish that advertising, profiling or optional analytics cookies are used, or that they are categorically absent.
Before introducing non-essential analytics, advertising or targeting technologies, the operator should verify applicable consent requirements, document each technology and, where required, offer a consent choice that prevents optional technologies from loading until consent is given. This notice does not claim that a consent manager is currently installed.
4. Managing storage and cookies
You can clear cookies and local storage using your browser's site-data settings. Clearing authentication storage may sign you out; deleting a capital preference may reset it. Disabling essential storage may prevent authentication or some account features from working correctly.
Browser removal is not a server-side account deletion. To request deletion or exercise privacy rights, refer to the Privacy Notice.
5. Changes and transparency
This inventory will be updated when providers, analytics features, storage purposes or retention settings change. A production cookie scan and documentation of optional technologies and applicable consent requirements remain part of the ongoing review.