ap_session
Signed account session cookie, HttpOnly, SameSite=Lax, maximum age 14 days; removed on logout. Required to deliver your workspace.
AssayPilot · Service information
We use the minimum needed for login, form security and installation.
Signed account session cookie, HttpOnly, SameSite=Lax, maximum age 14 days; removed on logout. Required to deliver your workspace.
Signed form-protection cookie, HttpOnly, SameSite=Lax, maximum age 14 days. Prevents unintended changes from other sites.
Operator tools only: signed unlock cookie, HttpOnly, SameSite=Strict, maximum age two hours. Removed when the operator locks these tools or deletes the account.
Opening the site registers its service worker. It caches only public CSS, JavaScript and the offline information page, refreshes those assets from the network when available, and removes older AssayPilot static-cache versions. Private experiments, uploaded photos and account pages are not added to this cache. You can remove it through your browser’s site-data settings.
The currently shipped AssayPilot application does not set third-party advertising cookies or use consent-based behavioural tracking. Anonymous allowlisted campaign events may be written in server logs.
Strictly necessary login and security cookies do not require an opt-in consent banner. If optional analytics/marketing cookies are added later, they will not be activated before a valid opt-in.