Skip to storage notice
PrivacyTermsCookies & storage

On your device

Cookies & Local Storage

The current estate uses functional browser storage, but the launch code does not set advertising or analytics trackers.

Current version24 August 2026
ScopeWebsite and four current tools
On this pageWhat is the difference?CookiesLocal storageExternal servicesAnalytics & consentYour controls

Cookies are not the same as local storage

A cookie is a small value a website can ask the browser to store and send with later requests. Local storage is a separate browser facility used by scripts to keep functional information on the device. Similar-technology rules can apply to both, so this page describes each accurately rather than calling everything a cookie.

Cookies and authentication

No first-party cookie-writing code, analytics cookie or advertising cookie was found in the current static website or the four in-scope tool clients. Creator Review Pad’s Supabase browser client normally persists its authenticated session in browser storage; the inspected client is not presented here as a cookie-based session.

Supabase or another external destination may use essential security/session technologies on its own domain when you authenticate or follow a link. External clinic websites, Calendly and other destinations have their own cookie notices and controls.

Functional local storage

ServiceWhat stays on the deviceCurrent control or technical expiry
Public websiteNo application local-storage write was found in the current static site.Not applicable.
EligibilityThe current patient journey does not persist Eligibility answers in local or session storage. Admin credentials and tokens are used for the active session only.Start again clears the active journey.
Entry AssessmentIn-progress state, answers and contact context; recent result insights and booking-request summaries.“Clear device history”; current technical expiry ceiling 30 days. It does not delete cloud reports.
DiscoveryA pending standalone start request/session/reference identifier and interface preferences. The DAX and assessment answers are not stored in the pending-start record.Pending start expires after 24 hours and is removed when no longer needed by the start flow.
Creator Review PadGuest and signed-in device drafts; Supabase authentication session for signed-in use.“Delete drafts from this device”; current draft expiry ceiling 30 days. The draft control deliberately leaves the sign-in session and cloud reviews alone.

The 30-day Entry and Creator values are technical safeguards. Final cloud-retention policy is described separately in the Privacy Notice.

External code and destinations

Entry, Discovery and Creator load the Supabase browser library through jsDelivr, which receives normal request metadata when the file loads. When you choose an external clinic/provider link or continue to Calendly, you leave the Hemp & Safety page and the destination’s storage practices apply.

Analytics, advertising and consent

The current launch code does not operate analytics, behavioural advertising, marketing pixels or fingerprinting. On that evidence, an opt-in cookie banner is not required for the current estate and one has not been added.

Reassess before adding technologyIf analytics, embeds, advertising or another non-essential storage technology is added, Hemp & Safety must reassess consent requirements before it is enabled—not after.

Your controls

Use the clear controls inside Entry and Creator where available. You can also clear site data in your browser, but doing so may remove a draft or sign you out. Clearing browser information does not delete records already stored in Supabase; use the request route in the Privacy Notice for cloud data.

Privacy NoticeTerms of UseReturn home

Hemp & Safety

HomeApps & HelpLibraryCreators
info@hempandsafety.com
PrivacyTermsCookies & storage