merkleset
法的文書

バージョン: 2026-08-12発効日: 2026-08-12情報提供

本文書は英語のみで公開しています。英語版が正文です:同意は英語原文の SHA-256 に対して記録されるため、翻訳があなたの同意した本文になることはありません。

Cookie and Local Storage Policy

Version 2026-08-12. Effective 2026-08-12.

This policy lists every item merkleset stores in your browser. There are three, all of them needed for the site to work. We use no analytics, no session recording, no advertising and no third-party scripts of any kind.

1. The complete inventory

NameTypeSet byPurposeCategoryLifetime
merkleset.accesslocalStoragemerkleset (first party)Holds your short-lived access token so you stay signed in while you browse and can request a download linkStrictly necessaryUntil you sign out or clear site data; the token inside it expires after 15 minutes and is refreshed
merkleset.refreshlocalStoragemerkleset (first party)Holds your rotating refresh token, so a page reload does not force a new login codeStrictly necessaryUntil you sign out or clear site data; the token inside it expires 30 days after issue
NEXT_LOCALECookiemerkleset (first party)Remembers the language you chose, so the site opens in it next timeStrictly necessary1 year, SameSite=Lax

That is the whole list. Nothing else is written to your browser by us.

2. Why there is no cookie banner

Under the ePrivacy rules, as applied in Spain, prior consent is required to store or read information on your device unless the storage is strictly necessary to provide the service you asked for. All three items above are strictly necessary:

  • the two token items are the login session — without them you would have to enter a new emailed code on every page;
  • NEXT_LOCALE records an explicit choice you made in the language switcher, and does nothing else.

None of them is used for analytics, measurement, profiling or advertising, and none of them is read by anyone but us. So there is nothing to consent to, and a banner asking you to consent to strictly necessary storage would be theatre rather than compliance. We would rather publish this table.

3. What would change that

The moment merkleset adds any analytics, product-measurement, session-recording, A/B testing, social embed or marketing script, this position stops being true. At that point the law requires prior, opt-in, granular consent, with the non-essential scripts blocked until the visitor agrees — and a passive "we use cookies" notice would not satisfy it. Rejecting must be as easy as accepting, and the choice must be re-obtainable and withdrawable.

Adding such a script therefore means shipping a real consent mechanism in the same change, plus a new version of this policy listing what the script stores. We have not done it, we do not currently plan to, and if we ever do you will see a consent request rather than a quiet addition.

4. Controlling what is stored

You can clear localStorage and cookies for this site at any time from your browser's settings. Clearing the token items signs you out. Clearing NEXT_LOCALE makes the site fall back to your browser's language preference. Nothing else breaks.

Signing out through the account menu clears both token items immediately.

5. Server-side logs are not covered by this policy

Our reverse proxy keeps ordinary web server access logs, which include the client IP address. That is a server-side record, not browser storage, so it is not consent-based; it is covered by the Privacy Policy under legitimate interests in security and fault diagnosis.

6. Contact

Questions: privacy@merkleset.com.

sha256 d90b433c1ee9…56cfd0a4e6f0