Cookie inventory
| Cookie | Purpose | Duration | Set by |
|---|---|---|---|
| Supabase auth session | Strictly necessary — maintains SaaS login session | Session | Supabase |
| rv_admin_mfa | Admin two-factor verification | 1 hour | CareerEvaluations.com |
| Plausible opt-out | Opt you out of Plausible analytics | 1 year | Plausible (if opted out) |
When GA4 is enabled (optional — NEXT_PUBLIC_GA_MEASUREMENT_ID set)
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics user identification | 14 months (default) |
| _ga_* | GA4 session data | 14 months |
Opt-out for GA4: browser ad blocker; GA opt-out browser add-on at tools.google.com/dlpage/gaoptout; DNT/GPC signals are honored.
Cookie consent banner
GDPR-compliant consent banner on first visit. Stores preference in localStorage. Blocks Plausible and GA4 until consent given. When GA4 is enabled, the banner gates gtag.js initialization on the stored consent key.