Cookies & Advertising

Advertising is currently disabled unless every production, legal, account, and consent gate passes. Optional choices never change access to research.

Last updated 26 August 2026

Your choices

Where required, a Google-certified consent management platform using IAB TCF v2.3 offers accept, reject, and granular choices before optional advertising storage or access occurs. Refusal is available without losing research access. The production footer must expose a persistent “Privacy choices” control whenever advertising is active.

You may withdraw consent as easily as you gave it. Browser controls can also clear cookies, but clearing a choice may cause the consent message to appear again.

Current first-party inventory

  • Supabase authentication cookies (`sb-…-auth-token` and related refresh fragments): sign-in and session security; first party; session/persistent duration is controlled by Supabase and the selected sign-in flow.
  • `oe_ad_free`: records the service-confirmed ad-free experience so advertising code is not loaded; first party; refreshed for up to five minutes while signed in.
  • Cloudflare Turnstile, when configured: a strictly necessary abuse-prevention challenge on registration, password login, and password-recovery forms. It processes limited client/network security signals and returns a single-use token that this application does not retain. It is not used for advertising or product analytics. See Cloudflare's Turnstile Privacy Addendum.
  • Consent-platform storage: provider, exact names, purposes, and lifespans must be exported from the final certified CMP and added here before advertising activation.

Google advertising technology

If AdSense is activated, Google and third-party vendors may place and read cookies or use web beacons, IP addresses, and similar technologies to deliver, limit, secure, and measure ads according to your choices. See how Google uses information from sites or apps that use its services.

Personalised advertising is not requested without the required consent signal. The operator also disables Auto ads/Auto optimize and records political/sensitive-category and user-based-advertising settings before activation.

Cookie-free product measurement

Our first-party product measurement does not set an analytics cookie or stable visitor identifier. It sends only an allowlisted event category, research-surface category, and coarse acquisition-source category, then stores daily aggregate counts. It does not store a user or session identifier, URL, search term, raw referrer, IP address, or browser/user-agent in the product-analytics table. Request-security and hosting logs remain covered by the Privacy Policy.

The private growth/revenue report uses server-to-server read-only AdSense and Search Console APIs. It does not install GA4 or another browser analytics tag and does not add an analytics cookie. Only fixed daily provider aggregates are stored; provider page URLs and search queries are not retained.

Ad placement rules

  • Ads are labelled “Advertisement” and separated from navigation, search, reaction controls, and primary-source links.
  • Ads never influence rankings, topic classifications, summaries, or conclusions.
  • No ads appear on account, auth, checkout, legal, marketing, search, status, admin, error, empty, unavailable, or insubstantial pages.
  • We never ask or incentivise a visitor to click an ad.

Ad-free and privacy requests

Signed-in ad-free subscribers do not receive display-ad requests from application components. The subscription changes advertising only. For access, deletion, or objections, see the Privacy Policy.