Cookie policy
Reviewed 5 October 2026. Gorland uses limited browser storage to keep the publication understandable and secure. We do not use cookies to build sensitive health profiles or to sell reader information. This policy exists as a companion to the privacy policy and focuses specifically on browser-level storage, since that is the technology most readers want a direct, plain-language answer about. It covers every storage value currently set by the site, however small, rather than describing only the ones a reader is likely to notice. Where a future version of the site adds a new storage value, this page will be updated before that value is deployed, not afterward. Readers who want the broader context of how information is used, retained, and shared should also read privacy.php, since the two documents are designed to be read together rather than as substitutes for one another. The scope of this document is limited to the gorland.id domain and its subpages; it does not cover storage set by an external site a reader may reach by following an outbound link, including any affiliate or sponsored link disclosed under advertising.php. Gorland's legal basis for essential storage is legitimate interest in operating a functional, secure website, while any optional storage category would rely on consent recorded through the banner described in Section 2. This document is written for a general reader rather than a technical audience, so where a term like "local storage" or "session identifier" is used, it is explained in plain language rather than assumed to be already understood. The policy is reviewed on the same general cadence as the site's other governing documents, and the date at the top of the page is the most reliable way to confirm whether a reader is viewing the current version.
1. Essential storage
Essential technical records help pages respond correctly and support security. They are normally removed when no longer needed and are not used to target advertising. An example of essential storage is a short-lived flag that remembers whether the mobile navigation menu is open, which exists purely so the interface behaves predictably as a reader taps between sections. Another example is a basic security token used to help distinguish an ordinary page request from an automated or abusive one. Because essential storage is necessary for the site to function at a basic level, Indonesian and comparable international cookie frameworks generally treat it as exempt from the accept-or-reject choice described in Section 2. Removing essential storage through a browser setting will not break the site entirely, but it may cause small inconveniences, such as the mobile menu needing to be reopened after a page refresh. None of these values contain a reader's name, email address, or any health-related content, since their purpose is purely technical rather than descriptive of the person using the site. The security token is regenerated automatically on a rolling basis rather than being tied permanently to one browser installation, which limits how long any single value remains meaningful even if it were somehow intercepted. Gorland does not share essential storage values with any advertising partner, and no essential value is used as an identifier for cross-site tracking of the kind described in Section 3.
- (a) Examples: mobile-menu state flag, basic request-security token.
- (b) Typical lifespan: end of browser session, or up to 24 hours for the security token.
- (c) Consent status: exempt, as these are necessary for the site to operate.
- (d) Data contents: no name, email address, or health-related detail is stored in either value.
- (e) Sharing: not shared with advertising partners or used for cross-site tracking.
2. Cookie choice
The cookieChoice value remembers Accept or Reject for 180 days. Removing browser storage will show the banner again. This value is set the first time a reader interacts with the cookie banner and is read on each subsequent visit so the banner is not shown repeatedly to the same browser. It stores only the choice itself and the date it was made, not a unique identifier that could be used to track a reader across unrelated websites. A reader who selects Reject will not see optional analytics activate, consistent with the consent-first approach described in Section 3, though essential storage from Section 1 will still apply because it is not governed by this choice. If a reader uses more than one browser or device, the choice is remembered separately on each one, since cookieChoice is stored locally rather than linked to an account. The 180-day lifespan was chosen as a reasonable middle point between asking a returning reader to repeat the choice too often and holding a stale preference for an indefinite period; Gorland may adjust this duration in a future revision, in which case the change would be reflected in the review date above. A reader who changes their mind after selecting Accept can clear the value through browser settings at any time, which immediately reverts the site to showing the banner again on the next page load rather than waiting for the 180 days to elapse. Because cookieChoice is read only by pages on the gorland.id domain, it has no effect on and is not readable by any other website the reader may visit.
- (a) Name: cookieChoice.
- (b) Stored values: accepted, rejected, plus the date set.
- (c) Lifespan: 180 days, after which the banner will appear again.
- (d) Manual reset: clearing the value through browser settings shows the banner on the next visit.
- (e) Domain restriction: readable only by pages on gorland.id, not by other websites.
3. Optional measurement
Optional analytics are not required to read the site. If enabled, names and retention details will be listed here before deployment. As of the 5 October 2026 review, Gorland has not activated an analytics or audience-measurement cookie, which means no reader is currently being counted or tracked through this category regardless of the cookieChoice selection. Should Gorland introduce a measurement tool in a future update, the intention is to run it only in an aggregated, non-identifying form, and only after a reader has actively selected Accept rather than by default. Any such addition will include the storage name, the provider operating it, and the retention period, updated in this same section rather than buried elsewhere on the site. A reader who wants to confirm whether this category is currently active may check the date at the top of this page, since any change would be reflected in a revised review date. In the absence of an active analytics cookie, Gorland's understanding of general readership, such as which articles are read most often, currently relies only on server-level aggregate logs rather than a browser-based cookie, and those logs are addressed separately in the privacy policy's server-log section rather than in this cookie-specific document. If a measurement tool is introduced, Gorland intends to favour a provider that offers a reasonable data-processing agreement and clear retention limits over one that offers a more expansive default tracking configuration. The six-month or shorter retention window typical of privacy-conscious analytics tools would be the starting expectation for any such addition, though the exact figure would only be confirmed once a specific provider is selected and listed here.
- (a) Current status: no optional analytics cookie is active.
- (b) Future activation: only after active consent, never by default.
- (c) Disclosure commitment: name, provider, and retention listed here before deployment.
- (d) Current readership insight: limited to aggregate server logs, addressed in the privacy policy, not a cookie.
- (e) Provider preference, if activated: a provider offering a clear data-processing agreement and defined retention limits.
4. Browser controls
Readers can block or delete cookies through browser settings. Blocking essential storage may affect preferences but will not create a separate account. Most current browsers provide a settings menu where stored values can be viewed individually and removed either all at once or one at a time, which gives a reader a more granular level of control than the site's own banner alone provides. Private or incognito browsing modes typically discard all storage, including cookieChoice, as soon as the browsing session ends, which is why the banner may reappear more often for a reader who regularly uses that mode. Browser extensions that block storage more broadly can sometimes prevent the cookie banner itself from functioning correctly, in which case a reader may see the banner on every visit even after making a selection. None of these browser-level choices result in Gorland creating a profile or account for the reader, since the site has no login system to attach such a profile to. A mobile browser typically offers the same storage controls as a desktop browser, though the menu path to reach them may differ by operating system and browser version, so a reader on a phone should look under the browser's own privacy or site-settings area rather than within the Gorland site itself. Clearing storage does not remove a message previously sent through contact.php, since that message is stored on Gorland's server rather than in the reader's browser, and any request to remove that message instead follows the data-subject rights process described in the privacy policy. Readers who want to limit storage without blocking it entirely may also use a browser's built-in tracking-protection feature, which often distinguishes between essential first-party storage of the kind described in Section 1 and third-party tracking storage, which Gorland does not currently set in any case.
- (a) Standard control: browser settings menu, usually under privacy or site data.
- (b) Private browsing: storage is typically cleared automatically at the end of the session.
- (c) Effect of blocking: banner may reappear; no account or profile is created either way.
- (d) Mobile browsers: same general controls, located under the browser's own privacy or site-settings menu.
- (e) Separate from server data: clearing browser storage does not remove a previously sent contact message.
5. Contact
Questions can be sent to [email protected] or +62 857 2309 4185. The policy was reviewed on 5 October 2026. A question specific to cookies, such as how to interpret a storage value found in a browser's developer tools, can usually be answered more quickly than a general privacy inquiry, since this page already lists every current value by name. Gorland aims to respond to a cookie-related question within 5 business days, consistent with the response targets described in the privacy policy for other categories of inquiry. If a reader's question is better addressed by the broader privacy policy, for example a question about retention of a contact message rather than a browser value, the desk will point to the relevant section of privacy.php in its reply. Readers in Indonesia who remain unsatisfied with a response may also raise a concern with the competent authority referenced in the privacy policy's complaints section. A reader writing in about a cookie question is encouraged to mention the browser and device used, since that detail can help the desk reproduce exactly what the reader is seeing, particularly where the question concerns the banner reappearing unexpectedly. Written correspondence about this policy, like correspondence about the other policies on the site, is kept for a limited internal period to support a consistent response if the same reader follows up, after which it is deleted in the ordinary course of mailbox maintenance. This page's revision history, including the 5 October 2026 review noted above, is kept as an internal record so that Gorland can demonstrate when a given storage practice was last confirmed as accurate.
- (a) Cookie-specific questions: usually answered directly from this page.
- (b) Response target: within 5 business days.
- (c) Broader privacy questions: referred to the relevant section of privacy.php.
- (d) Helpful detail: browser and device used, especially for a banner-related question.
- (e) Record-keeping: correspondence kept for a limited internal period, then deleted in routine mailbox maintenance.