Public pages
The application does not set analytics or advertising cookies when you browse public pages. Search and filter controls work in the current page without saving a browsing profile.
Account cookies
When account services are available and you sign in, the server sets __Host-wb_access and __Host-wb_refresh. These are essential authentication cookies, marked Secure, HttpOnly and SameSite=Lax. JavaScript on the page cannot read them.
The access cookie lasts for the session token’s lifetime, normally about one hour. The refresh cookie lasts up to seven days and may be renewed while you use the account. Signing out clears both cookies. A local development environment uses cookie names without the __Host- prefix.
Your browser choices
You can delete or block cookies in your browser. Public pages will still be available, but the portal will not be able to keep you signed in. No optional-cookie banner is shown because the application does not currently use optional tracking.
Hosting or security providers may apply their own essential protections. These must be reviewed with the final production configuration. If optional tracking is introduced later, this page and the relevant choice controls will be updated before it runs.