← RISE 11

Web storage

Cookie Notice

RISE 11 uses a small, first-party set of strictly necessary session cookies. It does not require advertising or cross-site tracking cookies.

Effective
1 September 2026
Published version
2026-09-01

1. Cookies we use

  • Access session cookie: a short-lived, encrypted-in-transit credential that lets the server recognize an authenticated request.
  • Refresh session cookie: a longer-lived, single-use rotating credential used to renew an authenticated session and detect replay. The corresponding token is stored as a hash on the server.

In production these cookies use the __Host- prefix, Secure, HTTP-only, SameSite, and path restrictions. Browser JavaScript cannot read them, subdomains cannot overwrite them, and the server attaches them only to approved same-origin requests.

2. Why they are necessary

The cookies provide login continuity, session renewal, logout, device and family revocation, multi-factor session state, request authorization, and protection against cross-site request attacks. RISE 11 cannot provide an authenticated web account without them.

3. What we do not use

RISE 11 does not currently set third-party advertising cookies, behavioral profiling cookies, social-network tracking pixels, or cross-site analytics identifiers. If optional measurement is introduced later, this Notice and the interface will be updated before non-essential storage is activated where consent is required.

4. Device storage and capabilities

The installable web app may use browser cache storage and a service worker to make application assets available reliably and provide an offline page. This cache does not replace server authorization and must not contain private authentication credentials. Notification permission and push subscriptions are optional and are created only after a user action.

5. Your controls

You can end server sessions from Security settings, log out one device or all devices, revoke push subscriptions, clear site data in the browser, or block cookies in browser settings. Blocking necessary cookies will prevent authenticated web features from working. Mobile-app secure credential storage is controlled through the app and operating system rather than browser cookies.

6. Contact

Questions about cookies or device storage can be sent to privacy@merchnique.com.