School project · Delayed data · Not financial adviceTerms
Skip to content
SINGULARITYTERMINALOpen the terminal
Cookies

Everything this app stores in your browser

Two cookies and a set of localStorage keys, all of them this app's own. There is no analytics cookie, no advertising cookie and no third-party script on any page. Everything stored is either needed to serve you the page you asked for or is a preference you set — except the activity log, which is off until you switch it on.

Why there is no cookie banner

A consent banner exists to obtain permission for storage that is not strictly necessary for a service the reader asked for: tracking, profiling, advertising, third-party analytics. This app sets none of those.

The session cookie is set only after you choose to sign in, and it is what signing in MEANS. The CSRF cookie is a security control on your own writes. Both fall inside the strictly-necessary exemption under the ePrivacy Directive and the UK PECR, so asking would be theatre. The two localStorage keys hold your own display preferences and are never transmitted anywhere.

If a future version adds anything that is not on this page, the banner arrives with it.

The complete list

singularity_sessionCookie
What it is for
Holds the session token after you sign in. This is what keeps you signed in.
When it is set
Set only when you sign in or create an account. Never set for a signed-out reader.
Flags
HttpOnly · SameSite=Lax · Path=/ · Secure when served over HTTPS
Lifetime
Expires at the session TTL, or immediately when you sign out — the token is destroyed server-side first, then the cookie is cleared.
In the code
app/services/auth.py — session_cookie_kwargs
singularity_visitorCookie
What it is for
Remembers that this browser entered an email address, so the terminal does not ask again.
When it is set
Set only when you enter your email to open the terminal. Never set for anyone else.
Flags
HttpOnly · SameSite=Lax · Path=/ · Secure when served over HTTPS
Lifetime
180 days. The server stores only a hash of it, and it can be revoked there.
In the code
app/services/visitors.py — COOKIE
singularity_csrfCookie
What it is for
The readable half of a double-submit CSRF pair. Every state-changing request must echo it in the X-Singularity-CSRF header, which a cross-site page cannot do.
When it is set
Issued on demand by /api/account/csrf, before the first write.
Flags
Readable by this origin's scripts by design — that is the mechanism. SameSite=Lax.
Lifetime
Rotates. A stale token produces a 403 and the client refetches once.
In the code
app/routes_accounts.py — CSRF_COOKIE
singularity_themelocalStorage
What it is for
Dark or light. Read before first paint so the page does not flash the wrong ground.
When it is set
Written when you change the theme.
Flags
Never sent to the server — localStorage is not attached to requests.
Lifetime
Until you clear site data.
In the code
static/app.js, frontend/page_kit.js
singularity_prefslocalStorage
What it is for
Accent, density, number format, default ticker and whether motion is reduced.
When it is set
Written when you change a preference.
Flags
Never sent to the server.
Lifetime
Until you clear site data.
In the code
frontend/page_kit.js — readPrefs

Third parties

No tag manager, no analytics library, no font CDN and no embedded widget on any page. The typefaces are self-hosted and the one JavaScript library in use is vendored into static/vendor and served from this origin.

Financial data is fetched by the SERVER, not by your browser, so those providers never see your address and never set anything in your browser. Who they are is on the subprocessors page.

Three screens are the exception, and they are the only ones. GEO and TMAP load basemap tiles from CARTO, and the Quant Sandbox fetches its Python runtime from jsDelivr the first time you press Run. Those requests leave your browser directly, so CARTO and jsDelivr see your IP address and could set storage on their own origins. Neither is used on any other screen and neither receives anything about what you searched for.

Clearing them

Signing out destroys the session server-side and clears its cookie. Your browser's clear-site-data control removes everything on this page. Nothing here survives it, because nothing here is stored anywhere else.