Everything this app stores in your browser
Two cookies and a set of localStorage keys, all of them this app's own. There is no analytics cookie, no advertising cookie and no third-party script on any page. Everything stored is either needed to serve you the page you asked for or is a preference you set — except the activity log, which is off until you switch it on.
Why there is no cookie banner
A consent banner exists to obtain permission for storage that is not strictly necessary for a service the reader asked for: tracking, profiling, advertising, third-party analytics. This app sets none of those.
The session cookie is set only after you choose to sign in, and it is what signing in MEANS. The CSRF cookie is a security control on your own writes. Both fall inside the strictly-necessary exemption under the ePrivacy Directive and the UK PECR, so asking would be theatre. The two localStorage keys hold your own display preferences and are never transmitted anywhere.
If a future version adds anything that is not on this page, the banner arrives with it.
The complete list
singularity_sessionCookieapp/services/auth.py — session_cookie_kwargssingularity_visitorCookieapp/services/visitors.py — COOKIEsingularity_csrfCookieapp/routes_accounts.py — CSRF_COOKIEsingularity_themelocalStoragestatic/app.js, frontend/page_kit.jssingularity_prefslocalStoragefrontend/page_kit.js — readPrefsThird parties
No tag manager, no analytics library, no font CDN and no embedded widget on any page. The typefaces are self-hosted and the one JavaScript library in use is vendored into static/vendor and served from this origin.
Financial data is fetched by the SERVER, not by your browser, so those providers never see your address and never set anything in your browser. Who they are is on the subprocessors page.
Three screens are the exception, and they are the only ones. GEO and TMAP load basemap tiles from CARTO, and the Quant Sandbox fetches its Python runtime from jsDelivr the first time you press Run. Those requests leave your browser directly, so CARTO and jsDelivr see your IP address and could set storage on their own origins. Neither is used on any other screen and neither receives anything about what you searched for.
Clearing them
Signing out destroys the session server-side and clears its cookie. Your browser's clear-site-data control removes everything on this page. Nothing here survives it, because nothing here is stored anywhere else.