Effective date: July 31, 2026
Overview
This Cookie Policy explains how Haplotype Wallet ("we," "us," or "our") uses cookies, browser local storage, session storage, and similar technologies when you use our Services. It should be read with our Privacy Policy and Service Provider List.
We currently use essential technologies for authentication, saved preferences, security, error reporting, and performance diagnostics. We do not use advertising or marketing cookies, cross-site tracking, or optional analytics tools.
The consent banner lets you record a preference for optional measurement. No optional measurement tool is active today, so accepting or rejecting that category does not change the essential technologies described below. Before we activate an optional measurement tool, we will update this Policy and the notice and ask for a fresh choice.
What are cookies and similar technologies?
Cookies are small text files stored by a website in your browser. Local storage and session storage are browser features that store information for an origin. Local storage generally remains until it is cleared; session storage generally lasts only for the browser tab or authentication flow. These technologies may remember a session or preference or help a service coordinate a secure request.
Categories we use
- Essential operations. Always active because they provide authentication, remember privacy and display preferences, protect the Services, and let us detect and diagnose errors and material performance problems. This category includes WorkOS AuthKit, the c15t preference manager, the theme preference, and our narrowly configured Sentry monitoring.
- Optional measurement. Off by default. No technology currently uses this category. A saved choice in this category will not authorize a future tool without an updated notice and fresh choice.
We treat Sentry as an essential operational service because we use it only for error reporting, incident investigation, and sampled performance diagnostics needed to keep the Services reliable and secure. We do not configure Sentry for advertising, marketing profiles, session replay, or general product-usage analytics. If we materially broaden those purposes, we will reassess the category and obtain any choice required before the broader use begins.
Current cookie and browser-storage inventory
This inventory describes the production web application as of the effective date. Provider-managed names can change as security software is updated; we will update this inventory when a material change affects your choices.
| Technology | Storage or recipient | Purpose and data | Duration |
| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| WorkOS AuthKit | WorkOS authentication cookies, including the workos-has-session session indicator, on Haplotype and WorkOS authentication origins (including auth.haplotype.ai in production) | Essential authentication, session restoration, token rotation, fraud prevention, and sign-out. Stores or processes session and security identifiers, not uploaded Genetic Data or Biomarker and Health Data. | Until sign-out, revocation, or the configured WorkOS session, access-token, or inactivity limit expires. |
| WorkOS AuthKit | workos:code-verifier and, when needed, organization-selection values in session storage | Essential PKCE login protection and completion of an authentication redirect. | Removed after the callback or sign-out, or when the browser tab/session ends. |
| c15t consent manager | c15t first-party cookie on the current host and c15t local-storage record | Essential record of the categories selected, consent metadata, and timestamps. Offline mode sends no consent record to c15t or to our server. | Cookie: 365 days from the latest save. Local storage: until replaced or cleared in the browser. |
| Theme preference | theme in local storage on the current origin | Essential display preference containing light, dark, or system. | Until changed or cleared in the browser. |
| Sentry browser SDK | Diagnostic requests to Sentry; our configuration sets no Sentry cookie or Sentry local-storage item | Essential error and performance monitoring. Events may include an opaque account identifier after sign-in, page or application context, error and stack information, browser and device details, release and environment, timing information, and an IP address processed in delivering the request. We do not send account email addresses, uploaded genetic or biomarker contents, biomarker query contents, credentials, cookies, authorization headers, or session replay. Error events are sent when relevant failures occur; performance traces are sampled at 10%. | No Sentry browser storage. Diagnostic events are retained under our configured Sentry service period and deleted under the retention principles in our Privacy Policy. |
Temporary browser-storage entries may also be created and promptly removed by WorkOS to coordinate token refreshes across tabs or to test whether storage is available. They serve the same essential authentication and security purpose and are not used for advertising or analytics.
Managing your optional preference
The first banner presents Accept optional and Reject optional with equal prominence. Customize opens the detailed preference dialog. You can reopen the dialog at any time using Manage cookies in the footer.
Clearing browser cookies or storage may sign you out, reset the theme, and erase the saved preference. Blocking essential storage may prevent authentication or other parts of the Services from working. Rejecting optional measurement does not disable WorkOS, the preference manager, the theme setting, or the essential Sentry configuration described above.
Do Not Track and Global Privacy Control
We do not use advertising networks, sell or share Personal Data for cross-context behavioral advertising, or track visitors across unrelated services. Because of those practices, a browser Do Not Track (DNT) setting does not cause an additional change to current processing and does not disable essential authentication or reliability monitoring.
We recognize a supported Global Privacy Control (GPC) signal as a request to opt out of sale, sharing for cross-context behavioral advertising, and targeted advertising where applicable law requires. We do not currently conduct those activities, so there is nothing additional to opt out of. GPC does not disable essential WorkOS or Sentry operations. If our practices change, we will honor GPC as required and update this Policy and our Privacy Policy.
Changes to this Policy
We may update this Cookie Policy to reflect changes in technology, law, or our practices. We will revise the "Last updated" date and provide additional notice when required. We will not rely on an old optional-measurement preference to activate a materially different tool without an updated disclosure and fresh choice.