Cookie Policy
Last updated: 29 September 2026
Version: 2026-09-29_v9
Last updated: 29 September 2026
Provider: DJG Media Limited (trading as Brigid), CRO No. 762838, Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland
Contact: privacy@askbrigid.com
1. What this notice covers
This notice describes cookies and similar device storage used by DJG Media Limited across askbrigid.com, the Brigid clinic app and MyBrigid. Regulation 5(3) of the European Communities (Electronic Communications Networks and Services) Regulations 2011 (S.I. No. 336/2011) requires consent before information is stored on or read from a device, except where it is strictly necessary for a service the user asked for. GDPR also applies where that processing involves personal data.
A strictly necessary item is used only where it is needed for a requested service or security function. Optional analytics or marketing storage requires a valid opt-in before it is used.
2. Optional analytics on askbrigid.com
Optional analytics is enabled, and off until you say otherwise. When you first visit, a card asks whether analytics and marketing cookies may run. Until you choose, the site requests no Google Tag Manager, Google Analytics or advertising resource: the choice is not pre-made, "Essential only" is the same size and colour as "Accept all", and closing the card counts as "Essential only". We verified this on the deployed site with a clean browser before treating this statement as effective.
Your choice is kept in your browser for six months, after which we ask again, and you can change it at any time from "Cookie preferences" in the footer. Withdrawing a category reloads the page so that a script already loaded is not carried forward. A record of the choice is kept for 12 months so that we can show the choice was made (see §6).
The Brigid web app's public, signed-out pages can also load Google Tag Manager, but only if an Analytics choice has been recorded in that browser. It is never loaded while someone is signed in to the app, so page addresses inside the clinical app, which can contain a patient reference, are not sent to Google.
3. Strictly necessary product storage
When a person signs in to a Brigid product, first-party browser storage may be used for these limited purposes:
- Authentication: the Supabase key beginning
sb-ptbcpblrtlvfglqyteju-auth-tokenstores the signed-in session and refresh token. It persists so a user can remain signed in and is removed through the sign-out and revocation process. - Patient-session continuity:
medyou.sessionand related first-party keys link the active patient profile and clinic on that device. Shared-device users should sign out; logout clearing is a production acceptance gate. - Legal and privacy state: versioned terms, clinician-attestation and banner-acknowledgement keys record which notice or gate was displayed. A browser record does not execute the clinic DPA or establish the clinic's lawful basis.
- Security and recovery: short-lived password-reset, session-presence and deployment-recovery flags prevent stale sessions or repeated broken-bundle reloads.
- Completed consultation recording recovery: after an authorised clinician stops a recording, the original audio, transcript and transcript segments are encrypted in a separate first-party IndexedDB store before the network save begins. This copy exists only to finish the requested save if the connection or upload is interrupted.
- User preferences: theme, layout, collapsed panels and similar settings may remain until changed or browser storage is cleared.
The application also contains device-local working-state keys for drafts and window recovery. Some can contain patient or communication content. They are bound to the staff authentication boundary and removed when the staff user changes or signs out. These values are not described as encrypted merely because they are in first-party storage.
4. AI drafts and the device cache boundary
Brigid drafts notes and letters for the clinician to review and sign (Privacy Policy §6). A draft in progress is kept only as device-local working state (§3), bound to the staff sign-in and removed when the staff user changes or signs out; it is not written to an offline patient cache. Legacy test builds may have created keys beginning voice-brigid-summary: or voice-brigid-risks:. The current source classifies these as patient data and removes them at the staff authentication boundary. Older test-browser site data has to be inspected and cleared by the person using that browser. This notice does not claim that a legacy value was encrypted or expired automatically.
5. Offline clinical cache and recording recovery
Brigid does not cache patient rosters or general clinical requests for offline use. The legacy MedProDB compatibility module is fail-closed and is not opened during application startup.
The only launch exception is the completed-recording recovery copy described above. Its audio, transcript and segments are encrypted with a non-extractable key scoped to the signed-in staff user and active clinic. It cannot be used as an offline patient record, and another account or clinic is not shown the recovery item.
- No offline patient roster is available.
- No clinical query payload is written to the legacy cache.
- A completed recording is retried through the same server-acknowledged save path used when the connection is available.
- A successful save removes the device recovery copy. A failed save remains encrypted and retries with a delay.
- Signing out removes the local key and recovery ciphertext. An ordinary staff sign-out checks for a pending completed recording first and presents an explicit choice to stay signed in for retry or sign out and permanently discard the device copy. A security-driven session end, account/clinic change or browser-site-data deletion also removes recovery access. Staff should remain signed in and online while a recording is pending.
6. Optional analytics — what runs after you opt in
Two independent conditions apply: the deployment switch is on, and you have opted in. Before opt-in, analytics resources remain absent rather than operating in a cookieless measurement mode.
Which choice loads what: Analytics loads Google Tag Manager and Google Analytics 4. Google Tag Manager is not loaded on a Marketing choice alone. Google Consent Mode starts every signal as denied, and the advertising signals stay denied unless you grant Marketing. No advertising, remarketing or audience tag is configured in the container.
After you opt in, the site may set or send:
_ga— Google Analytics 4 (Analytics choice only) — distinguishes returning visitors — two years — third party (Google Ireland Ltd)._ga_<container id>— Google Analytics 4 session state (Analytics choice only) — two years — third party.- Google Tag Manager container
GTM-W8VTWTB3— loads only after you grant Analytics — sets no cookie of its own — third party. cookieConsent.v2andmedpro_visitor_id— the visitor's choice and the key that records it — localStorage — first party.
cookieConsent.v2 records the selected categories, banner schema version, timestamp and locally generated visitor identifier for six months, after which the site asks again, or until withdrawal or clearing. medpro_visitor_id is created only once you have made a choice, so that the choice can be recorded and withdrawn; nothing is created while the card is still unanswered. The consent record sent to Supabase includes the choices, schema version, timestamp, expiry and browser user-agent string; provider request logs may also contain network metadata. Withdrawing analytics or marketing consent reloads the next document so an already-loaded third-party script is not carried forward.
7. Advertising and other trackers
We do not use Vercel Analytics or Vercel Speed Insights on any of our websites or apps. The source does not load Facebook Pixel, LinkedIn Insight, Hotjar, Segment, Apollo visitor tracking or Google advertising tags. Enabling any such service requires a documented purpose, vendor and transfer review, updated notice, approved retention and valid opt-in control.
8. Your controls
- Browser controls let you delete cookies, localStorage, sessionStorage and IndexedDB. Doing so can sign you out, remove an unsaved draft, or permanently remove a consultation recording that has not yet reached the clinic record. Do not clear site data while the product shows a recording waiting to upload.
- The Cookie preferences link in the footer reopens choices whenever optional storage is in use. While the analytics switch is off there is no optional storage to manage and the link is not shown.
- Staff using a shared clinic device must sign out and follow the clinic's device-clearing procedure. Closing a tab is not equivalent to signing out.
9. Changes and contact
We update this notice and the consent-schema version before introducing a materially new optional category. Questions or rights requests can be sent to privacy@askbrigid.com.
Related documents
Privacy Policy · Data Processing Agreement · Compliance Overview · Terms of Service · Sub-Processor Register
This page renders the policy itself. Its fingerprint identifies the exact wording under review and, once approved and published, the wording in force.
SHA-256: 389ee1c678ff51e95b0054466a190da11d917ae447d857f9c30d09b30e93c20a
Source: docs/legal/COOKIE_POLICY_2026-09-29_v9.md