Skip to content
LEGAL

Cookie Policy

Last updated: 2026-08-27

This page discloses every cookie and browser-stored identifier written by Rapoport Studio’s marketing site and workspace. Identifier names, retention values, and lawful-basis labels are in English as required by GDPR Art. 13(1)(e).

Marketing site · rapoport.studio

The marketing site uses necessary and functional first-party storage. Cloudflare Web Analytics measures every visit cookielessly. Google Analytics 4 identifiers are created only after you affirmatively accept the Analytics category, and can be withdrawn at any time through Cookie preferences.

IdentifierTypeVendorPurposeRetentionLawful basis
NEXT_LOCALECookie (HTTP; not HttpOnly; SameSite=Lax; Path=/)First-party (next-intl framework)Persists the visitor's language-locale choice so that repeat visits to bare paths (`/`) redirect to the correct locale URL (`/en/`, `/ru/`, `/ro/`)Session — no `Expires` or `max-age`; deleted when the browser closesStrictly necessary — enables consistent language routing as requested via URL locale-prefix navigation; set only on redirect, not on every page load
rs-funnel-sessionsessionStorageFirst-partyPer-tab anonymous UUID that links funnel events (intake step transitions, decision-router clicks, openspec archive downloads) within a single browser tab. Cleared when the tab closes. No cross-session tracking, no PII, no advertising IDs.Per-tab (sessionStorage semantics — cleared on tab close)Functional (anonymous server-side funnel measurement; no client analytics SDK)
rs_docs_sessionCookie (HTTP; HttpOnly; Secure; SameSite=Lax; Path=/; max-age=2592000)First-partyProof-of-knowledge token for the access-restricted engagement-documentation area. Written only after the visitor submits the correct shared access key; contains a keyed digest of that key, no user data and no identifier of any kind.30 days, or until the access key is rotatedStrictly necessary (access control) — without it the restricted area cannot recognise an authorised visitor
sidebar_stateCookie (JavaScript-set; not HttpOnly; SameSite=Lax; Path=/; max-age=604800)First-partyPersists the open/collapsed state of the document rail in the access-restricted engagement-documentation area. Written only inside that area — no page on the public marketing site mounts the component that sets it. Same cookie name and behaviour as the workspace entry below.7 daysFunctional (user interface preference) — no data transmitted to any external party
cookie-consent:v2localStorageFirst-partyStores the visitor's category choices and evidence state so the decision takes effect across page loadsPersistent until browser storage is cleared or consent is replacedStrictly necessary — required to give effect to and evidence the visitor's consent decision
anon-visitor-idlocalStorageFirst-partyAnonymous UUID used to correlate consent evidence; not linked to an authenticated identityPersistent until browser storage is clearedStrictly necessary for consent evidence integrity
_gaCookie (JavaScript-set; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/)Google Ireland Limited and Google LLC (US)Written only after affirmative Analytics consent; distinguishes consenting visitors for Google Analytics 4 measurement180 daysConsent — ePrivacy Art. 5(3) + GDPR Art. 6(1)(a); does not qualify for the CNIL Sheet n°16 exemption
_ga_HQCVK1DP56Cookie (JavaScript-set; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/)Google Ireland Limited and Google LLC (US)Written only after affirmative Analytics consent; maintains session state for GA4 property `G-HQCVK1DP56`180 daysConsent — ePrivacy Art. 5(3) + GDPR Art. 6(1)(a); does not qualify for the CNIL Sheet n°16 exemption
_gcl_auCookie (JavaScript-set; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/)Google Ireland Limited and Google LLC (US)Written only after affirmative Marketing consent; Google Ads conversion attribution180 daysConsent — ePrivacy Art. 5(3) + GDPR Art. 6(1)(a); does not qualify for the CNIL Sheet n°16 exemption

Workspace · app.rapoport.studio

The workspace is an authenticated SaaS application. It uses strictly-necessary session cookies managed by Supabase and functional browser-local state. No marketing or analytics identifiers are written by the workspace.

IdentifierTypeVendorPurposeRetentionLawful basis
sb-nifagnmgwoqkplegsicy-auth-tokenCookie (HTTP; HttpOnly; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/)SupabaseHolds the authenticated user's JWT and refresh token — required for every authenticated request to the workspaceUntil sign-out or token expiry (Supabase default: access token 1 h; refresh token 30 days)Strictly necessary (contract performance) — enables access to the contracted workspace service
sb-nifagnmgwoqkplegsicy-auth-token-code-verifierCookie (HTTP; HttpOnly; Secure; SameSite=Lax; domain=.rapoport.studio; Path=/)SupabasePKCE code verifier — temporary secret required to complete the magic-link / OAuth authentication handshake~5 minutes; deleted on successful code exchangeStrictly necessary (security) — required by the PKCE protocol to prevent authorization-code interception
sidebar_stateCookie (JavaScript-set; not HttpOnly; SameSite=Lax; Path=/; max-age=604800)First-partyPersists the workspace sidebar's open/collapsed state across page navigations7 daysFunctional (user interface preference) — no data transmitted to any external party
canvas:mobile-banner-dismissedlocalStorageFirst-partyRecords that the user dismissed the mobile-use warning banner in the canvas view, suppressing repeat displayPersistent until browser storage is clearedFunctional (user interface preference)
canvas-stage-transition:<canvasId>:<fromStage>:<toStage>localStorageFirst-partyRecords that a stage-transition celebration animation has been shown for a specific canvas and transition pair, preventing repeat display on the same devicePersistent until browser storage is clearedFunctional (user experience — one-shot animation guard)
intake-draft:v1:<type>:<locale>localStorageFirst-partyAuto-saves intake form draft values so the user does not lose work-in-progress entries if they navigate away before submitting30 days (enforced by schema-expiry logic in the storage utility)Functional (prevents user data loss during form completion)

Consent and withdrawal

Two measurement services run on this site, and they are deliberately unequal. Cloudflare Web Analytics counts every visit without cookies and without storing personal data, so basic measurement never depends on your consent. Google Analytics 4 goes further — it writes the Google identifiers listed above and sends usage data to Google LLC in the United States — and it loads only if you accept the Analytics category. Refusing costs you nothing and leaves the cookieless count in place. Withdrawing consent through Cookie preferences disables the Google tag, expires the Google identifiers on this device rather than merely stopping reports, and reloads the page so collection stops immediately. Google Analytics 4 is active as of 27 August 2026, so the Google identifiers listed above are written on this device once you accept the Analytics category — and not before.

Sub-processors

For a full list of third-party processors that may process personal data on our behalf, see our sub-processors page.

Future changes

Any identifier that requires consent is disclosed on this page before it can be written, and is written only after you accept the category it belongs to. You can change or withdraw your choices at any time through Cookie preferences in the footer.

Contact

To raise a concern about our use of cookies or browser-stored identifiers, contact us at legal@rapoport.studio.