Cookie Policy

Last updated

This document is a working draft prepared alongside the product and has not yet been reviewed by legal counsel. The bracketed placeholders below still need the registered entity details filled in. Do not rely on it as a binding agreement until it has been signed off.

This policy explains what we store on your device and why. OTOLAB is a working tool rather than an ad-supported site, so the list is short: what is here exists to keep you signed in and to remember how you like the interface configured.

1. What we mean by cookies

We use "cookies" loosely to cover cookies proper plus the other client-side storage a modern web application relies on — local storage, session storage and the service worker cache that makes OTOLAB work offline and installable.

2. Strictly necessary

These cannot be turned off without breaking the platform, and they do not require consent.

  • Authentication tokens — keep you signed in and identify your session. Without them every page load would require logging in again.
  • Session and device identifiers — let you review and revoke active sessions from your profile, and support security checks on sensitive actions.
  • Security tokens — protect form submissions against cross-site request forgery.
  • Service worker cache — stores application assets so the platform loads quickly and continues working through brief connectivity loss.

3. Preference storage

These remember your choices. Clearing them resets the interface to its defaults but loses nothing else.

  • Theme selection — which colour theme and light or dark mode you have chosen.
  • Interface font size — the accessibility text-size setting.
  • Language — your selected interface language.
  • Navigation state — whether the sidebar is pinned, and the mobile navigation layout you prefer.
  • List preferences — sort order and view mode for the tables and grids you use most.
  • Draft recovery — unsaved order drafts held locally so a closed tab does not lose work in progress.

4. Analytics and advertising

We do not run third-party advertising cookies, and we do not sell data to advertisers.

Where hosting-level analytics are enabled, they record aggregate page performance and error rates. They are not used to build a profile of you and are not shared with advertisers.

5. Third-party cookies

Our payment provider sets its own cookies on the checkout pages it hosts, for fraud prevention and to complete the payment. These are governed by that provider's own cookie policy.

6. Managing what is stored

You can clear cookies and site data at any time through your browser settings, and block cookies entirely if you prefer.

Blocking strictly necessary cookies will prevent you from signing in — the platform cannot maintain a session without them. Clearing preference storage is harmless and simply restores defaults.

Push notifications are separate and are only enabled if you explicitly grant permission. You can revoke that permission in your browser or device settings, or in the notification settings inside the application.

We will update this page whenever the storage we rely on changes materially. The date at the top reflects the current version.