We set no advertising cookies on any page. Visitor data is never sold and never shared with data brokers. Until you answer the banner, neither analytics nor session recording loads: silence counts as refusal, not consent.
The law asks for a list, not for general statements: what exactly is stored on your device, who places it, what for and for how long. That list is below. It covers not only cookies but also browser local storage and device characteristics — the rules are the same for any technology that writes to your device or reads from it.
Only what you cannot receive the service without. This category needs no consent and cannot be switched off — the service would stop working.
| What | Where it is kept | Lifetime | What for |
|---|---|---|---|
gp_lang | browser local storage | until you clear the browser | interface language |
gp_consent_v1 | browser local storage | 6 months | your answer to the banner. Without it we would ask on every visit |
tool settings (gp_layers, gp_show_amounts and similar) | browser local storage | until you clear the browser | remember how you set up the graph and panels. Never sent to our server |
| screening session token | tab memory only | minutes, until the page is closed | protects wallet screening from bulk automated enumeration |
gp_sess | cookie, ours | 30 days with “Remember me”; without it, until the browser closes and no longer than 12 hours | keeps you signed in to your account. Without it you would sign in again on every page |
gp_theft_cases | browser local storage | until you clear browser data | list of theft cases opened from this device (case key, address, amount, date) — so you can return to a case after losing the link. Never sent to our server |
gp_oauth_state | cookie, ours | 10 minutes | protects the sign-in itself: without it a link could force a sign-in to your account |
gp_claim | cookie, ours | 10 minutes | only when a Google sign-in finds an account set up with a password for the same email: it records that Google confirmed the email while you choose to link the accounts or close one that is not yours. It cannot be used to enter the account |
gp_ref | browser local storage | 90 days | who sent you the link to the site. Needed so the invitation is credited to whoever sent it |
None of the above is used for advertising or linked to your identity.
| What | Where it is kept | Lifetime | What for |
|---|---|---|---|
gp_s | cookie, ours | 12 months | tell a returning visitor from a new one |
| browser characteristics: screen, time zone, language, graphics adapter, platform | not stored on your device, sent to our server | — | understand which pages are used and from which devices |
Plainly: taken together these characteristics are stable enough to recognise a device between visits even after the cookie is deleted. That is exactly why we ask, although a browser hands part of this to any website anyway.
Microsoft Clarity, a third-party service, records cursor movement, clicks and scrolling so we can see where a page confuses people. Without your consent its code is not loaded at all — not "loaded and silent", but not loaded.
| Cookie | Lifetime | What for |
|---|---|---|
_clck | 1 year | persistent Clarity visitor identifier |
_clsk | 1 day | joins page views into a single session |
CLID | 1 year | first time Clarity saw this browser |
MUID | about a year | Microsoft browser identifier |
ANONCHK | 10 minutes | Microsoft service check |
MR | 7 days | service: whether MUID needs refreshing |
SM | session | keeps the identifier consistent across Microsoft domains |
These are set by Microsoft, not by us, and Microsoft’s rules apply: Microsoft privacy statement.
At any time and by the same means you gave it — one button, no emails, no explanations:
🍪 Cookie settings
Withdrawal does three things at once: erases your previous answer, deletes the gp_s cookie, and tells Clarity immediately that recording has stopped — not "after a reload", but in the same second. You can also delete and block cookies in the browser itself; the service will keep working.
To have already-collected data deleted, write to [email protected].
If your browser or extension sends a GPC signal, we take it as a refusal — no questions, no "accept" buttons. Offering consent to someone who has already refused through their browser is precisely what disrespecting the signal means. The cookie settings show plainly that the signal was received and honoured.
The signal outranks a stored choice: if you consented a year ago and then turned GPC on, the later instruction wins.
Your answer stands for 6 months, then we ask again. We will also ask again if we change the description of what is collected: consent is given to a specific text, and once that text is different, the earlier answer was about something else.
Your answer itself is written to an append-only log: the law requires not only asking, but being able to prove that we asked and what exactly you answered. The record contains no IP address and no device description — only a random identifier your browser generated for itself and keeps next to your answer, the text version and a digest of the text you were shown, your choice per category, and the date. The log is chained: any later edit breaks the integrity check, and that is visible from outside.
Visit analytics stays with us and goes nowhere else. Session recording is processed by Microsoft and only if you consented to that category. We do not pass or sell visitor data to ad networks, data brokers or anyone else.
Questions about this document or your data: [email protected]. Version 1.0 · August 2026.