Cookie policy
What NeuroScribe stores in your browser, and why.
Version 2.0 · In force from 20 August 2026 · Applies to neuroscribe.co.uk and the NeuroScribe clinical workspace
The short version
NeuroScribe uses only the cookies and browser storage needed to make the platform work: keeping you signed in, remembering your multi-factor session, and completing subscription payments. There is no advertising, profiling, cross-site tracking, session replay or third-party analytics.
Because every item below is strictly necessary to deliver a service you have requested, it falls within the exemption in regulation 6(4) of the Privacy and Electronic Communications Regulations 2003 (PECR), so no consent banner is presented. If we ever introduce a non-essential cookie, it will be off by default and will only be set after you give consent, with an equally prominent way to refuse or withdraw it.
What is stored
- Authentication session (strictly necessary): a session token and refresh token held in browser local storage by our authentication provider, so you stay signed in between page loads. Cleared when you sign out.
- Multi-factor state (strictly necessary): the assurance level of your current session, so a verified authenticator code is not requested on every page.
- Payment session (strictly necessary): cookies set by our payment provider during checkout and while managing a subscription, used for fraud prevention and to complete the transaction. Card details are never stored by NeuroScribe.
- Interface preferences (functional): small values such as a remembered panel or theme choice, where you have set one.
No clinical record content is written to cookies or browser storage for persistence beyond the working page.
How long it lasts
Session values last for the lifetime of your sign-in and are removed when you sign out or when the session expires. Payment provider cookies follow that provider’s own lifetimes, which are documented in their cookie notice.
Managing cookies
You can clear or block cookies and local storage in your browser settings, and signing out clears the authentication and multi-factor values immediately. Because the values above are strictly necessary, blocking them will prevent sign-in, multi-factor verification and payment from working.
We do not respond to Do Not Track or Global Privacy Control signals, because we set no tracking or advertising cookies for those signals to switch off.
Third-party storage
Our authentication and database provider and our payment provider set the strictly necessary values described above under their own notices. Our AI drafting provider receives de-identified text through a server-side request only and sets nothing in your browser. We embed no social media widgets, advertising pixels, tag managers or third-party fonts that would report your visit elsewhere.
Clinical data and browser storage
Patient identifiers, clinical free text and reports are held in the database, not in cookies or local storage. Record content held in memory while you work on a page is discarded when the page closes. On a shared device, sign out rather than only closing the tab.
Changes and complaints
Material changes are published here with a new version number and effective date before they take effect, and noted in the platform release notes. If you believe we have set storage on your device unlawfully, contact us first; you may also complain to the Information Commissioner’s Office at ico.org.uk.