Cookie and Local Storage Policy
Version 2026-08-19. Effective 2026-08-19. Supersedes the version of 2026-08-12.
This policy lists every item merkleset stores in your browser, and tells you which of them exist only because you agreed to them.
What changed in this version. The previous version of this policy said merkleset ran no analytics and no third-party scripts, and that no consent banner was therefore required. That is no longer true: we now use Google Analytics 4 to measure how the site is used. It is off until you switch it on. On your first visit every storage category is denied, no analytics script is loaded and no analytics cookie is written; a banner asks you to choose; and the script loads only if you accept. Rejecting is one click, exactly like accepting, and either decision can be changed later.
1. The complete inventory
1.1 Strictly necessary — always present, no consent required
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
merkleset.access | localStorage | merkleset (first party) | Holds your short-lived access token so you stay signed in while you browse and can request a download link | Until you sign out or clear site data; the token inside it expires after 15 minutes and is refreshed |
merkleset.refresh | localStorage | merkleset (first party) | Holds your rotating refresh token, so a page reload does not force a new login code | Until you sign out or clear site data; the token inside it expires 30 days after issue |
NEXT_LOCALE | Cookie | merkleset (first party) | Remembers the language you chose, so the site opens in it next time | 1 year, SameSite=Lax |
merkleset.consent | localStorage | merkleset (first party) | Records the analytics choice you made in the banner — accepted or rejected — so we do not ask again on every page, and so a refusal is respected rather than forgotten | Until you clear site data or change the choice; it holds three values only: your decision, the moment you made it, and the version of this policy it was given under |
merkleset.consent is written whichever way you answer, including when you refuse. That
is deliberate and it is what the ePrivacy rules expect: remembering a refusal is what makes
the refusal effective. It is a first-party record of your own choice, it is never sent to a
third party, and it contains no identifier for you.
It stores the version of this policy because consent must be informed about what it covers. If we publish a new version of this policy that changes what analytics does, the stored decision no longer matches it, and the banner asks again — with everything denied in the meantime. A version change is therefore a fresh question, not a silent carry-over.
1.2 Analytics — only after you accept
Nothing in this table exists in your browser unless you have accepted analytics. If you refuse, or if you have not answered the banner yet, the Google Analytics script is never loaded and none of these cookies is created.
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
_ga | Cookie, first party | Google Analytics 4 (measurement ID G-HZFYWX9XE4) | Holds a randomly generated identifier used to distinguish one browser from another, so repeat visits are counted as one visitor rather than several | 2 years from the last visit, which is Google's documented default for this cookie |
_ga_HZFYWX9XE4 | Cookie, first party | Google Analytics 4 | Holds session state for this specific property (the suffix is our measurement ID), so page views can be grouped into a visit | 2 years from the last visit, which is Google's documented default for this cookie |
Both are first-party cookies: they are written by script running on merkleset.com and stored against merkleset.com, not against a Google domain. The lifetimes above are Google's published defaults, which we have not shortened. Note that browsers cap them independently of what any site asks for — Chrome limits a first-party cookie to a maximum of 400 days, and Safari to 7 days for script-written cookies — so in practice these cookies frequently expire sooner than two years, and we have no way to predict which cap applies to you.
If Google adds or renames a cookie in this product, this table stops being complete until we publish a new version of this policy. If you find such a cookie, tell us at privacy@merkleset.com and we will correct it.
1.3 What is never set
We do not use advertising, remarketing or conversion cookies, and the consent signals for them are permanently denied — see section 3. There is no session recording, no heatmap, no A/B testing tool, no social embed and no third-party font, script or content delivery network anywhere on the site.
2. How the consent banner works
- On arrival, everything non-essential is denied. We use Google Consent Mode v2, and the
denial is set before any Google code could run.
analytics_storagestarts denied, so the measurement script is not loaded, not merely told to stay quiet. - The banner asks once, with two equal choices. Accepting and refusing are presented as the same kind of control, side by side. Nothing is pre-ticked, nothing is preselected, and closing or ignoring the banner is not treated as agreement — with no answer, the state stays denied.
- If you accept,
analytics_storageis granted, the Google Analytics script is loaded for the first time, and the two cookies in section 1.2 are written. - If you refuse, we store your refusal in
merkleset.consentand load nothing. No request is made to Google at all. - Nothing is measured while you decide. Because the script is never loaded before consent, there is no "pending" page view held back and sent afterwards.
3. Advertising signals are denied permanently
Google Consent Mode v2 defines three advertising signals — ad_storage, ad_user_data and
ad_personalization — alongside the analytics one. All three are set to denied and are
never granted, whatever you answer. Accepting analytics does not turn any of them on,
because the banner does not offer them: we run no advertising, and there is nothing for you
to opt into. If that ever changes, it will require its own consent request and a new version
of this policy.
4. Changing your mind
Your decision is not permanent and reversing it costs one click.
- From the site: use the cookie-settings control in the site footer. It reopens the same
choice and records the new answer in
merkleset.consent. - Withdrawing consent stops any further measurement immediately:
analytics_storagereturns to denied and no further data is sent. - The cookies already set are yours to clear. Withdrawal prevents future collection; it
does not by itself reach into data already sent to Google. Delete
_gaand_ga_HZFYWX9XE4in your browser's site-data settings, and see section 6 of this policy and section 8 of the Privacy Policy for what you can ask us and Google to do about data already collected. - Clearing site data for merkleset.com erases
merkleset.consenttoo, which means the banner will ask you again on your next visit — with everything denied until you answer.
5. Why consent is required for this and not for the rest
Under the ePrivacy rules, as applied in Spain by the AEPD, prior consent is required to store or read information on your device unless the storage is strictly necessary to provide the service you asked for.
- The two token items in section 1.1 are the login session — without them you would have to enter a new emailed code on every page.
NEXT_LOCALErecords an explicit choice you made in the language switcher, and does nothing else.merkleset.consentrecords the choice this policy is about. Storing a consent decision is itself treated as strictly necessary; the alternative — asking again on every page — would be worse for you and would make a refusal meaningless.- Analytics is not strictly necessary. The site works identically without it. So it needs your prior, informed, freely given consent, which is what the banner collects, and it may not run before you give it.
6. Controlling what is stored
You can clear localStorage and cookies for this site at any time from your browser's settings.
Clearing the token items signs you out. Clearing NEXT_LOCALE makes the site fall back to your
browser's language preference. Clearing merkleset.consent makes the banner ask again.
Clearing the analytics cookies removes the identifier they hold; if analytics is still
accepted, a new one is created on your next visit.
Signing out through the account menu clears both token items immediately.
Browser-level controls also work: blocking third-party or all cookies, private browsing, and
tracking-protection features all apply here as they do anywhere. So does Global Privacy
Control and any browser signal that blocks scripts — none of them is overridden by the
banner. Google publishes a browser add-on that opts you out of Google Analytics on every site
at once, at tools.google.com/dlpage/gaoptout.
7. Server-side logs are not covered by this policy
Our reverse proxy keeps ordinary web server access logs, which include the client IP address. That is a server-side record, not browser storage, so it is not consent-based; it is covered by the Privacy Policy under legitimate interests in security and fault diagnosis. It exists whether or not you accept analytics, and it is not used for measurement.
8. What Google receives, and where it goes
Accepting analytics means data about your visit is sent to Google, which acts as a recipient of that data. What is collected, on what legal basis, for how long, and the fact that this involves a transfer to the United States are set out in the Privacy Policy (sections 2, 5, 6 and 7) and in the Subprocessor Annex. This policy covers the browser storage; that one covers the processing.
9. Contact
Questions: privacy@merkleset.com.