Cookies are not the same as local storage
A cookie is a small value a website can ask the browser to store and send with later requests. Local storage is a separate browser facility used by scripts to keep functional information on the device. Similar-technology rules can apply to both, so this page describes each accurately rather than calling everything a cookie.
Functional local storage
| Service | What stays on the device | Current control or technical expiry |
|---|---|---|
| Public website | No application local-storage write was found in the current static site. | Not applicable. |
| Eligibility | The current patient journey does not persist Eligibility answers in local or session storage. Admin credentials and tokens are used for the active session only. | Start again clears the active journey. |
| Entry Assessment | In-progress state, answers and contact context; recent result insights and booking-request summaries. | “Clear device history”; current technical expiry ceiling 30 days. It does not delete cloud reports. |
| Discovery | A pending standalone start request/session/reference identifier and interface preferences. The DAX and assessment answers are not stored in the pending-start record. | Pending start expires after 24 hours and is removed when no longer needed by the start flow. |
| Creator Review Pad | Guest and signed-in device drafts; Supabase authentication session for signed-in use. | “Delete drafts from this device”; current draft expiry ceiling 30 days. The draft control deliberately leaves the sign-in session and cloud reviews alone. |
The 30-day Entry and Creator values are technical safeguards. Final cloud-retention policy is described separately in the Privacy Notice.
External code and destinations
Entry, Discovery and Creator load the Supabase browser library through jsDelivr, which receives normal request metadata when the file loads. When you choose an external clinic/provider link or continue to Calendly, you leave the Hemp & Safety page and the destination’s storage practices apply.
Analytics, advertising and consent
The current launch code does not operate analytics, behavioural advertising, marketing pixels or fingerprinting. On that evidence, an opt-in cookie banner is not required for the current estate and one has not been added.
Your controls
Use the clear controls inside Entry and Creator where available. You can also clear site data in your browser, but doing so may remove a draft or sign you out. Clearing browser information does not delete records already stored in Supabase; use the request route in the Privacy Notice for cloud data.
