# Cookie Policy — Medrecords AI

> Every cookie Medrecords AI sets, named — provider, purpose, lifetime. Analytics and marketing run by default, public site only, never the platform.

Canonical page: https://medrecords.ai/cookies/

---
New — **Missing Records Detection:** flags every visit, provider, and date missing from the file. [See how →](https://medrecords.ai/product/missing-records-identification/)
[Home](https://medrecords.ai/) ›[Legal Center](https://medrecords.ai/legal/) › — Cookie Policy
Legal · Document 06

## Cookie Policy

Every cookie and browser-storage key we set on medrecords.ai and workspace.medrecords.ai, named and explained. The list is short: sign-in, security, your preferences, analytics, and marketing: all under your control, and none of it on the platform.

Effective: July 13, 2026
 Version 1.2

### What cookies are, and how we approach them

Cookies are small files a website places on your device; "first-party" cookies are set by us, "third-party" cookies by services we use. Browsers also offer localStorage and sessionStorage (persistent and tab-scoped storage we use for interface preferences). This policy, issued by AI Health Studio LLC d/b/a Medrecords AI, covers all of them on **medrecords.ai** (the marketing site) and **workspace.medrecords.ai** (the platform).

2 rules govern everything below: **marketing and analytics cookies run only on this public website, never on workspace.medrecords.ai** , and **no PHI or record content is ever placed in a cookie or browser storage, full stop** . Turn either category off any time via Cookie settings, in the footer.

### Essential cookies — always on; the Services can't work without them

Name
Provider
Purpose
Expires
mr_session
Medrecords AI
Authenticates your platform session. HTTP-only, Secure, SameSite: holds a session identifier only, never PHI.
8h inactivity
mr_csrf
Medrecords AI
Protects forms and API calls against cross-site request forgery.
Session
mr_consent
Medrecords AI
Remembers your cookie choices so the banner doesn't re-ask.
12 months

### Analytics cookies — on by default; turn off any time; marketing site only

Name
Provider
Purpose
Expires
_ga
Google Analytics 4
Distinguishes unique visitors to medrecords.ai. IP anonymization enabled; ad personalization signals disabled.
2 years
_ga_*
Google Analytics 4
Maintains session state for each measurement property receiving this site's pageviews.
2 years
ph_phc_*_posthog
PostHog
Anonymous visitor id for page analytics and session replays of this public site, with everything you type masked before it is stored. Mirrored in localStorage under the same name. US cloud; never used on the platform.
12 months
PostHog and Google Analytics 4 both run today.

Decline analytics and the site works identically. The platform at workspace.medrecords.ai carries **no third-party analytics at all** : usage metering there is first-party Service Data, described in the [DPA](https://medrecords.ai/dpa/) .

### Marketing cookies — on by default; never the platform

Four tools run today: the Meta Pixel, the LinkedIn Insight Tag, the Reddit Pixel and Snitcher, which tell us which ads and companies bring visitors to this site. Their cookies are named below with their provider, purpose, and lifetime. A Google Ads tag and a TikTok Pixel may follow, and each will be listed here before it goes live. Marketing runs by default, site-wide, rather than waiting for an opt-in, and you can turn it off at any time in Cookie settings.

Name
Provider
Purpose
Expires
_fbp
Meta (Facebook)
Anonymous browser id Meta uses to measure which ads bring visitors to this site. Set only on medrecords.ai, never on workspace.medrecords.ai, and never based on anything in a medical record.
3 months
_fbc
Meta (Facebook)
Stores the click id from a Meta ad so a later demo booking can be attributed to that ad. Written only when you arrive from a Meta ad link.
3 months
li_sugr
LinkedIn
Anonymous browser id LinkedIn uses to measure which ads bring visitors to this site.
3 months
bcookie / lidc
LinkedIn
Browser and routing ids the LinkedIn Insight Tag sets to attribute a demo booking to a LinkedIn ad.
1 year / 1 day
UserMatchHistory
LinkedIn
Syncs the anonymous browser id with LinkedIn so ad measurement works across sessions.
30 days
_rdt_uuid
Reddit
Anonymous browser id the Reddit Pixel sets to attribute a demo booking to a Reddit ad.
90 days
rdt_cid
Reddit
Click id carried over from a Reddit ad so the visit can be matched back to the ad that sent it.
90 days
Snitcher tracker
Snitcher
Identifies the company behind a visit from its IP address, for sales follow-up. Snitcher does not publish the specific cookie name(s) or lifetime it sets.
Not published
It runs across this public site, **medrecords.ai** , with no page excluded. It never runs on **workspace.medrecords.ai** , and it is never based on anything inside a medical record: no diagnosis, no document content, and nothing from a file you upload is ever sent to an advertising platform. Global Privacy Control and "Turn off non-essential" in the cookie panel both apply immediately, everywhere, the moment you choose them.

### Browser storage — site preferences and booking attribution

Key
Type
Purpose
Cleared
mr_src
localStorage
Stores a validated source-page label so a demo booking can be attributed. Only that label is forwarded to Cal.com; free-form query values are discarded.
30 days
mr_visitor
Cookie + localStorage
A random anonymous visitor id plus the first page, referrer, and campaign labels (utm_*, click ids) that brought you here, so a later demo booking or file test can be attributed to its channel. Readable by workspace.medrecords.ai so a signup can be tied to its source. Never contains PHI, a name, or contact details.
13 months
mr_visitor_id
Cookie
A compact copy of just the visitor id, for the same attribution purpose.
13 months
mr_ui_layout
localStorage
Remembers your 3-pane workspace layout (pane sizes and collapse states) so the workspace opens the way you left it.
When you clear it
mr_roi_inputs
localStorage
Keeps your ROI-calculator sliders (pages/month, rates) so estimates survive a reload. Never sent to us.
When you clear it
viewer state
sessionStorage
Tab-scoped document-viewer position and zoom during a review session.
Tab close
No record text, patient data, or PHI is ever written to cookies, localStorage, or sessionStorage. Record content renders from the encrypted platform session only.

### Controlling cookies

- **Cookie notice:** a short disclosure on first visit, plus "Cookie settings" in the site footer any time after: turn analytics or marketing off there, and the change applies immediately.
- **Global Privacy Control:** we honor GPC signals as an opt-out of any sale or sharing (of which we do neither) and as a decline of analytics consent.
- **Browser controls:** view, block, or delete cookies in [Chrome](https://support.google.com/chrome/answer/95647) , [Firefox](https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer) , [Safari](https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac) , or [Edge](https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09) . Blocking essential cookies will break sign-in.
- **Google Analytics opt-out:** the [GA opt-out browser add-on](https://tools.google.com/dlpage/gaoptout) works across all sites using GA.

### Updates & contact

If our cookie use changes, this page changes first, with a new effective date, and fresh consent requested for any new non-essential category. Questions or deletion requests for cookie-collected data: [privacy@medrecords.ai](mailto:privacy@medrecords.ai) . This policy is part of the [Privacy Notice](https://medrecords.ai/privacy/) .
