Draft — pending legal review
This notice is a working draft. It has not been reviewed or approved by a solicitor. The inventory below was compiled from the site’s own code and must be re-checked against the live site before publication — a tag added later will not add itself to this page. Items marked LIKE THIS still need confirming.
Legal
Most cookie notices describe cookies in general and tell you nothing about the site you are on. This one is an inventory: every named item below is something this site genuinely sets, and the list is short because there is not much on it.
A cookie is a small file a website asks your browser to keep and hand back on the next request. Local storage does a similar job but stays in the browser and is never sent to the server. Both are covered here because from your side the question is the same: what is on my device, and why.
Some of it is necessary — without it you could not stay signed in and the site could not remember that you asked for high contrast. Anything not necessary needs your consent, and this site sets none of that kind.
Stating the absences is more useful than listing the presences, so:
If analytics are ever added, this clause changes before the script does.
Two lists. The first is set for everyone; the second only appears if you use the feature that creates it.
| Name | Kind | What it does | Lifetime | Set by |
|---|---|---|---|---|
| amperearc-intelligence | Local storage | Your theme, contrast, motion, transparency, density and cursor preferences. Read before the page paints so the site does not flash the wrong theme at you. | Until you clear it | This site |
| authjs.session-token | Cookie | Keeps you signed in to the installer portal. Only set once you sign in. | 30 days | This site |
| authjs.csrf-token | Cookie | Protects the sign-in form against cross-site request forgery. Security, not tracking. | Session | This site |
| authjs.callback-url | Cookie | Remembers which page to return you to after you sign in. | Session | This site |
| authjs.pkce.code_verifier | Cookie | Used only during a Google sign-in, to prove the sign-in that comes back is the one you started. Discarded as soon as it completes. | 15 minutes | This site |
| authjs.state / authjs.nonce | Cookie | Also sign-in only. Ties the response from Google to your original request so it cannot be replayed. | 15 minutes | This site |
| Name | Kind | What it does | Lifetime | Set by |
|---|---|---|---|---|
| googtrans | Cookie | Remembers the language you picked in the page translation control. Only set if you choose a language. | Session |
Over HTTPS the browser is asked to handle these more strictly, and the names gain a prefix to say so — you will see __Secure-authjs.session-token and __Host-authjs.csrf-token. Same cookies, tighter rules. All of them are set to be unreadable by JavaScript.
This site embeds Google’s page-translation widget so the content can be read in another language. That embed loads a script from translate.google.com, which means Google receives the request — including your IP address — whether or not you translate anything.
If you choose a language, Google sets its own preference cookie so the choice sticks. What Google does with data it receives is governed by Google’s privacy policy, not ours.
Whether to keep this embed at all is under review.
The typefaces are served from Google’s font hosts. Google receives the request and your IP address in order to return the font file, but no cookie is set for it and nothing is stored on your device beyond the browser’s normal file cache.
Portal cookies are only created once you sign in. If you never sign in, they are never set.
If you sign in with a Google account you are sent to Google to authenticate, and Google sets its own cookies on its own domain as part of that. We receive your name, email address and profile picture back — never your password.
Signing out clears the session cookie. What the portal records about you and your hardware is covered in the privacy notice.
When this notice is issued it will carry a version and a date. It should be re-checked whenever a third-party script, embed or measurement tool is added to the site — the inventory above is only worth reading if it is true.
Questions about any of it: Info@amperearc.com.
Related: Privacy notice · Terms and conditions · Support and documentation