Cookie Notice
Last engineering verification: 5 September 2026
About this notice
Emerging Pharma Tech uses cookies and browser storage to keep its authenticated intelligence service secure and to remember features that a user requests. A cookie is a small value that a website asks a browser to retain and return. Browser local storage and session storage retain values in the browser but do not automatically send those values with each request.
This notice applies to the Emerging Pharma Tech web application. In this notice, “we”, “us”, and “our” mean Emerging Pharma Tech.
Strictly necessary cookies
No advertising, behavioural analytics, or cross-site tracking is enabled in the current platform. These cookies are set by Emerging Pharma Tech on the same site the user visits; they are first-party cookies.
| Cookie | Provider and purpose | Retention | Production security |
|---|---|---|---|
messages | Emerging Pharma Tech; first-party. Transient account confirmation feedback across the email-verification redirect. Strictly necessary; no tracking. | Session; removed when consumed or when the browser session ends. | HttpOnly; Secure; SameSite=Lax; host-only; path /. |
pharma_access | Emerging Pharma Tech; first-party. Carries the short-lived access JSON Web Token used to authenticate API requests. | 15 minutes. | HttpOnly; Secure; SameSite=Lax; host-only; path /. |
pharma_refresh | Emerging Pharma Tech; first-party. Carries the refresh JSON Web Token used to continue an authenticated session. Refresh tokens rotate on use and the replaced token is blacklisted. | 14 days, unless rotated, invalidated, or removed on logout sooner. | HttpOnly; Secure; SameSite=Lax; host-only; path /. |
csrftoken | Emerging Pharma Tech; first-party. Supplies the value that the frontend returns in the X-CSRFToken header to protect state-changing requests from cross-site request forgery. | 364 days (31,449,600 seconds), unless replaced or removed sooner. | Frontend-readable by design and not HttpOnly; Secure;SameSite=Lax; host-only; path /. |
sessionid | Emerging Pharma Tech; first-party. Lets the django-axes abuse-prevention control correlate its security access log after sign-in. It does not contain the JWT authentication identity and does not authenticate the user outside the internal Django administration interface, where a cookie of the same name carries a staff login. | 14 days, unless expired or removed sooner. | HttpOnly; Secure; SameSite=Lax; host-only; path /. |
The two JWT cookies and the security access-log cookie are HttpOnly, so browser JavaScript cannot read their values. The csrftoken value remains frontend-readable so the frontend can copy it into the security header.
These cookies are strictly necessary for authentication, continuity and token refresh, CSRF protection, and security access logging. The authentication and CSRF cookies cannot be disabled while using authenticated features. Removing or blocking them will sign the user out or prevent protected actions from working.
With SESSION_LOGIN=False, password authentication does not create a general authenticated Django login session; the two JWT cookies authenticate application access. The django-axes security control independently creates sessionid to correlate its security access log. That cookie contains no Django authentication identity and does not authenticate the user outside the internal Django administration interface, where a cookie of the same name carries a staff login.
Other browser storage
The application uses the following first-party functional browser storage. These uses do not support advertising, cross-site tracking, behavioural analytics, or user profiling.
themeremembers the selected light or dark presentation until changed or site data is cleared.epi.sidebar.preferencerestores the sidebar state until changed or site data is cleared.- A per-user key prefixed
pharma:ws:<user>keeps an offline-tolerant mirror of server-backed workspace state until replaced, cleaned up, or cleared. The server remains authoritative. - A per-user key prefixed
pharma:molecule-overview-columns:v1:<user>restores the columns chosen for molecule Overview tables until the selection changes or site data is cleared. pharma:direct-import-uploadkeeps administrator import-recovery state for the browser-tab session or until removed sooner.pharma:view-as:return-pathreturns an administrator to a validated local route and lasts for the tab session or until read and removed.
Sentry diagnostics
When explicitly enabled, the application sends redacted error events and sampled performance traces to Sentry for reliability and security diagnostics. Sentry acts as a diagnostic processor. The current integration does not set a Sentry cookie or write Sentry values to browser storage, and Session Replay is disabled.
The default performance trace sampling rate is 10%, and profiling is disabled by default. The application disables default PII collection and removes cookies, request bodies, query strings, browser user context, authorization values, email-like text, tokens, secrets, and presigned URL credentials before transport. Diagnostic events are retained under contracted account settings only as long as needed for reliability and security. Applicable contractual and transfer safeguards govern the processing.
Choices and future technologies
There is currently no optional cookie-choice control because the authentication, security-logging, and CSRF cookies are required for the service and the listed storage is not used for optional tracking. This is not consent to future uses.
Before enabling analytics, advertising, cross-site tracking, Session Replay, or other optional storage or access technology, we will review this notice and applicable law. Where consent is required, the technology will be blocked before consent and the interface will provide equally easy accept and reject actions, granular choices, withdrawal, and policy/choice version records.
Changes and contact
We review this notice when a material cookie, processor, retention period, or data use changes. Questions can be sent to admin@emergpharma.com.
Emerging Pharma Tech, Innovation One, Level 1, DIFC, Dubai, UAE