AssayPilot · Service information

Cookies and device storage

We use the minimum needed for login, form security and installation.

ap_session

Signed account session cookie, HttpOnly, SameSite=Lax, maximum age 14 days; removed on logout. Required to deliver your workspace.

ap_csrf

Signed form-protection cookie, HttpOnly, SameSite=Lax, maximum age 14 days. Prevents unintended changes from other sites.

ap_admin

Operator tools only: signed unlock cookie, HttpOnly, SameSite=Strict, maximum age two hours. Removed when the operator locks these tools or deletes the account.

PWA Cache Storage

Opening the site registers its service worker. It caches only public CSS, JavaScript and the offline information page, refreshes those assets from the network when available, and removes older AssayPilot static-cache versions. Private experiments, uploaded photos and account pages are not added to this cache. You can remove it through your browser’s site-data settings.

Advertising and third-party tracking

The currently shipped AssayPilot application does not set third-party advertising cookies or use consent-based behavioural tracking. Anonymous allowlisted campaign events may be written in server logs.

Your choice

Strictly necessary login and security cookies do not require an opt-in consent banner. If optional analytics/marketing cookies are added later, they will not be activated before a valid opt-in.