Cookie Policy
Last updated: 2026-08-27
This page discloses every cookie and browser-stored identifier written by Rapoport Studio’s marketing site and workspace. Identifier names, retention values, and lawful-basis labels are in English as required by GDPR Art. 13(1)(e).
Marketing site · rapoport.studio
The marketing site uses necessary and functional first-party storage. Cloudflare Web Analytics measures every visit cookielessly. Google Analytics 4 identifiers are created only after you affirmatively accept the Analytics category, and can be withdrawn at any time through Cookie preferences.
| Identifier | Type | Vendor | Purpose | Retention | Lawful basis |
|---|---|---|---|---|---|
| NEXT_LOCALE | Cookie (HTTP; not HttpOnly; SameSite=Lax; Path=/) | First-party (next-intl framework) | Persists the visitor's language-locale choice so that repeat visits to bare paths (`/`) redirect to the correct locale URL (`/en/`, `/ru/`, `/ro/`) | Session — no `Expires` or `max-age`; deleted when the browser closes | Strictly necessary — enables consistent language routing as requested via URL locale-prefix navigation; set only on redirect, not on every page load |
| rs-funnel-session | sessionStorage | First-party | Per-tab anonymous UUID that links funnel events (intake step transitions, decision-router clicks, openspec archive downloads) within a single browser tab. Cleared when the tab closes. No cross-session tracking, no PII, no advertising IDs. | Per-tab (sessionStorage semantics — cleared on tab close) | Functional (anonymous server-side funnel measurement; no client analytics SDK) |
| rs_docs_session | Cookie (HTTP; HttpOnly; Secure; SameSite=Lax; Path=/; max-age=2592000) | First-party | Proof-of-knowledge token for the access-restricted engagement-documentation area. Written only after the visitor submits the correct shared access key; contains a keyed digest of that key, no user data and no identifier of any kind. | 30 days, or until the access key is rotated | Strictly necessary (access control) — without it the restricted area cannot recognise an authorised visitor |
| sidebar_state | Cookie (JavaScript-set; not HttpOnly; SameSite=Lax; Path=/; max-age=604800) | First-party | Persists the open/collapsed state of the document rail in the access-restricted engagement-documentation area. Written only inside that area — no page on the public marketing site mounts the component that sets it. Same cookie name and behaviour as the workspace entry below. | 7 days | Functional (user interface preference) — no data transmitted to any external party |
| cookie-consent:v2 | localStorage | First-party | Stores the visitor's category choices and evidence state so the decision takes effect across page loads | Persistent until browser storage is cleared or consent is replaced | Strictly necessary — required to give effect to and evidence the visitor's consent decision |
| anon-visitor-id | localStorage | First-party | Anonymous UUID used to correlate consent evidence; not linked to an authenticated identity | Persistent until browser storage is cleared | Strictly necessary for consent evidence integrity |
| _ga | Cookie (JavaScript-set; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/) | Google Ireland Limited and Google LLC (US) | Written only after affirmative Analytics consent; distinguishes consenting visitors for Google Analytics 4 measurement | 180 days | Consent — ePrivacy Art. 5(3) + GDPR Art. 6(1)(a); does not qualify for the CNIL Sheet n°16 exemption |
| _ga_HQCVK1DP56 | Cookie (JavaScript-set; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/) | Google Ireland Limited and Google LLC (US) | Written only after affirmative Analytics consent; maintains session state for GA4 property `G-HQCVK1DP56` | 180 days | Consent — ePrivacy Art. 5(3) + GDPR Art. 6(1)(a); does not qualify for the CNIL Sheet n°16 exemption |
| _gcl_au | Cookie (JavaScript-set; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/) | Google Ireland Limited and Google LLC (US) | Written only after affirmative Marketing consent; Google Ads conversion attribution | 180 days | Consent — ePrivacy Art. 5(3) + GDPR Art. 6(1)(a); does not qualify for the CNIL Sheet n°16 exemption |
Workspace · app.rapoport.studio
The workspace is an authenticated SaaS application. It uses strictly-necessary session cookies managed by Supabase and functional browser-local state. No marketing or analytics identifiers are written by the workspace.
| Identifier | Type | Vendor | Purpose | Retention | Lawful basis |
|---|---|---|---|---|---|
| sb-nifagnmgwoqkplegsicy-auth-token | Cookie (HTTP; HttpOnly; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/) | Supabase | Holds the authenticated user's JWT and refresh token — required for every authenticated request to the workspace | Until sign-out or token expiry (Supabase default: access token 1 h; refresh token 30 days) | Strictly necessary (contract performance) — enables access to the contracted workspace service |
| sb-nifagnmgwoqkplegsicy-auth-token-code-verifier | Cookie (HTTP; HttpOnly; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/) | Supabase | PKCE code verifier — temporary secret required to complete the magic-link / OAuth authentication handshake | ~5 minutes; deleted on successful code exchange | Strictly necessary (security) — required by the PKCE protocol to prevent authorization-code interception |
| sidebar_state | Cookie (JavaScript-set; not HttpOnly; SameSite=Lax; Path=/; max-age=604800) | First-party | Persists the workspace sidebar's open/collapsed state across page navigations | 7 days | Functional (user interface preference) — no data transmitted to any external party |
| canvas:mobile-banner-dismissed | localStorage | First-party | Records that the user dismissed the mobile-use warning banner in the canvas view, suppressing repeat display | Persistent until browser storage is cleared | Functional (user interface preference) |
| canvas-stage-transition:<canvasId>:<fromStage>:<toStage> | localStorage | First-party | Records that a stage-transition celebration animation has been shown for a specific canvas and transition pair, preventing repeat display on the same device | Persistent until browser storage is cleared | Functional (user experience — one-shot animation guard) |
| intake-draft:v1:<type>:<locale> | localStorage | First-party | Auto-saves intake form draft values so the user does not lose work-in-progress entries if they navigate away before submitting | 30 days (enforced by schema-expiry logic in the storage utility) | Functional (prevents user data loss during form completion) |
Consent and withdrawal
Two measurement services run on this site, and they are deliberately unequal. Cloudflare Web Analytics counts every visit without cookies and without storing personal data, so basic measurement never depends on your consent. Google Analytics 4 goes further — it writes the Google identifiers listed above and sends usage data to Google LLC in the United States — and it loads only if you accept the Analytics category. Refusing costs you nothing and leaves the cookieless count in place. Withdrawing consent through Cookie preferences disables the Google tag, expires the Google identifiers on this device rather than merely stopping reports, and reloads the page so collection stops immediately. Google Analytics 4 is active as of 27 August 2026, so the Google identifiers listed above are written on this device once you accept the Analytics category — and not before.
Sub-processors
For a full list of third-party processors that may process personal data on our behalf, see our sub-processors page.
Future changes
Any identifier that requires consent is disclosed on this page before it can be written, and is written only after you accept the category it belongs to. You can change or withdraw your choices at any time through Cookie preferences in the footer.
Contact
To raise a concern about our use of cookies or browser-stored identifiers, contact us at legal@rapoport.studio.