The public content pages use ordinary page requests and a small local script for navigation and filtering. They do not set a visitor-profile cookie or require a cookie-consent choice to read an article. The current public experience does not use advertising cookies or analytics tracking scripts.
The secure client portal has separate storage requirements for authentication and the working session. Reading this page does not sign you in. A cookie remaining from a previous portal visit may still be present until it expires or is cleared.
Session cookie
The portal's mb_session cookie identifies an authenticated server session. It is set with HttpOnly and SameSite=Strict attributes and a maximum age of 12 hours; secure transport is used in production. HttpOnly prevents ordinary page scripts from reading the cookie. Signing out clears the session cookie through the logout process.
This is functional authentication storage, not an advertising preference. Blocking it can prevent sign-in from working. The server determines whether the session remains valid; the presence of a cookie alone does not establish current authorisation.
Session storage
The portal uses browser session storage for parts of its working state, including account-view data and interface state. This storage is separate from a cookie and is scoped to the browsing session. It is not a substitute for the server record or an independent source of access rights.
The mb-balances-hidden preference records whether balances are concealed in the interface. Other session values support the authenticated workspace. Some information is exchanged with the server as part of the service, so local storage should not be understood to mean that information is never transmitted.
Local storage and earlier preferences
The existing portal can retain interface preferences in local storage. Earlier site versions used regionConfirmed and cookieAccepted values to remember dismissal of notices. The new public pages do not rely on these values and do not use a citizenship selection to personalise content.
Local storage generally remains until it is removed by the site, the browser or the user. It does not have the same built-in expiry mechanism as a cookie. Clearing site data may remove preferences and require a fresh sign-in, but it does not delete server-held account records.
External requests
The site requests fonts from Google Fonts. Loading an external resource involves a network request to its provider; it is different from placing an advertising cookie. Official sources and other external links open independent websites with their own practices.
Managing storage
Use your browser's site-data settings to inspect or remove cookies and local storage for this domain. On a shared device, sign out after use and avoid saving credentials. Clearing browser data does not replace reporting suspected unauthorised access.
There are no optional public tracking categories to enable on this edition, so an “Accept all” banner would not describe a meaningful choice. If optional tracking is introduced later, this inventory and the controls should be updated before it is activated.
Questions
For privacy questions, contact the address in the privacy notice. For sign-in difficulties after changing browser settings, use access help. Do not send cookie values, passwords or authentication tokens in an ordinary email or screenshot.
Content reviewed 14 September 2026
