Cookie Policy

Effective Last updated

ScienceBank uses a small number of cookies to keep you signed in, keep your account secure, and remember your language. We do not use cookies to track you, and we do not run advertising or third-party analytics.

1. What a cookie is

A cookie is a small text file a website stores in your browser. It lets the site remember something between one page and the next — for example, that you are signed in.

2. What ScienceBank uses, and why

We use only first-party cookies, meaning cookies set by ScienceBank itself. No third party can read them.

Before you sign in, we set one cookie:

  • NEXT_LOCALE — remembers whether you are reading ScienceBank in English, Spanish or Indonesian. Expires when you close your browser.

When you sign in or use particular features, we set:

  • __Secure-authjs.session-token — keeps you signed in. Expires after 30 days, or immediately when you sign out.
  • __Secure-authjs.csrf-token — a security cookie that prevents another website from submitting forms as you.
  • sb-webauthn-register / sb-webauthn-authenticate — hold a one-time security challenge while you set up or use a passkey. Expire after 5 minutes.
  • orcid_write_state — protects the ORCID connection process. Expires after 10 minutes.
  • sb_sponsor_activity — signs you out of the sponsor portal after 30 minutes of inactivity, because that area shows financial information.

Each of these is necessary for the service to work or to keep your account secure. Most are marked HttpOnly, which means the code running in your browser cannot read them at all.

3. What we do not do

  • We do not use Google Analytics or any other third-party analytics service.
  • We do not use advertising cookies, tracking pixels, or social-media trackers.
  • We do not build advertising profiles, and we do not track you across other websites.
  • We do not sell or share your personal information, as those terms are used in the California Consumer Privacy Act and comparable US state laws. There is therefore nothing for a "Do Not Sell or Share My Personal Information" request to act on.

4. Why we do not show a cookie banner

Under EU and UK law, consent is required before storing cookies on your device unless those cookies are strictly necessary to deliver the service you asked for. Every cookie ScienceBank sets falls into that category: signing you in, protecting your account, or showing the site in your language.

We would rather tell you exactly what we store than interrupt you with a consent dialog that asks permission for nothing. If we ever introduce cookies that do require consent — analytics, for instance — we will ask for it properly, before setting them, and update this policy first (see Section 7).

5. Controlling cookies

You can delete or block cookies in your browser settings; every major browser offers this under Privacy or Security. If you block ScienceBank's cookies, you can still read published articles, but you will not be able to sign in — authentication depends on the session cookie.

Because we set no advertising or analytics cookies, there is nothing to opt out of beyond the essentials above.

6. Related documents

This policy covers cookies specifically. How we handle personal data more broadly is described in our Privacy Statement, and how we use AI tools is described in our AI Use Policy.

7. Changes to this policy

If we change what we store on your device — particularly if we add anything requiring consent — we will update this policy before the change takes effect, and the "Last updated" date above will reflect the revision. Questions: admin@sciencebank.com.