Cookie Policy

Last Updated: August 29, 2026

1. The short version

ArkCloud Health sets three cookies. All three are strictly necessary to sign you in and to keep you signed in. We do not set advertising cookies, analytics cookies, or third-party tracking cookies, and we do not embed third-party tags that set them on our behalf.

Because every cookie we set is strictly necessary, there is no banner asking you to accept or reject categories - there are no optional categories to accept or reject. The notice at the bottom of the page is a disclosure, and dismissing it records nothing about you.

2. Cookies we set

The table below is complete. If a cookie appears in your browser on one of our domains and is not listed here, we would like to know - write to [email protected].

CookieWhat it doesHow long it lastsSet by
arkcloud-sessionHolds your signed session after you sign in. Without it every page load would be anonymous and the secure areas could not be reached at all.8 hours by default. 30 days only if you tick Remember me at sign-in.First party
authjs.csrf-tokenCross-site request forgery protection on the sign-in form. It pairs a value in the form with a value in the cookie, so a request forged by another site cannot sign you in or out.Session - removed when you close the browser.First party
authjs.callback-urlRemembers the page you were trying to reach when you were sent to sign in, so you land back there afterwards.Session - removed when you close the browser.First party

2.1 How these cookies are protected

  • HttpOnly. The session cookie cannot be read by JavaScript, which is what stops a script injected into the page from stealing a session.
  • Secure. Sent only over HTTPS in production, so the cookie never crosses a plain-text connection.
  • SameSite=Lax. Not sent on cross-site requests initiated by another website.
  • Scoped to our own domain. The session cookie is valid across our subdomains so that one sign-in serves the application, the product hosts and the documentation. It is not readable by any other domain.

3. What we do not do

  • No advertising or retargeting cookies, and no advertising network pixels.
  • No analytics cookies. We do not run Google Analytics, or any comparable product analytics tool, on this site or inside the application.
  • No third-party tracking cookies, social widgets or embedded trackers.
  • No cookie is used to profile you, to build an advertising audience, or to follow you across other websites.
  • No cookie carries Protected Health Information. Patient data lives in the application behind authentication, never in a cookie.

Typefaces are self-hosted and served from our own domain rather than fetched from a font network at runtime, so loading a page does not disclose your visit to a third party.

4. Local storage, and your theme preference

Two preferences are kept in your browser’s local storage rather than in a cookie: your light or dark theme choice, and whether you have dismissed the cookie notice at the bottom of the page.

The distinction is not cosmetic. A cookie is attached to every request your browser makes to us; local storage is not sent anywhere at all. It is read by the page you are already looking at and stays on your device. Neither value identifies you, and neither is used for tracking. Clearing your browser’s site data removes both - the theme returns to the default and the notice appears again.

5. Managing cookies

Every major browser lets you view, block and delete cookies for a specific site through its privacy or site-settings panel. You are free to do that at any time, and we do nothing to detect or discourage it.

What blocking will break

Because our cookies are the ones that carry your sign-in, blocking them for this site means you will not be able to sign in: the session cookie is set and immediately discarded by the browser, and the application returns you to the sign-in page. The public pages, this policy included, remain fully readable with cookies blocked.

6. Changes to this policy

If we add a cookie, this page changes in the same release and the Last Updated date above changes with it. A change that introduced any non-essential cookie would also have to change the notice at the bottom of the page, because that notice would no longer be accurate as written.

Questions about this policy go to [email protected]. For how we handle personal information more broadly, see the Privacy Policy.

This Cookie Policy describes cookies set by ArkCloud Health on the domains it operates. It does not cover cookies set by a customer’s own systems where those systems link to or embed ours.