Cookies Policy
Reviewed 1 September 2026. Xyjecta uses a small number of browser technologies to keep the site usable and understand broad readership. This page is intended to stand alongside, not duplicate, the broader explanation of data handling in our privacy policy, and it focuses specifically on what is stored in a reader's browser rather than on our internal records. We keep the number of distinct cookies and storage items deliberately small, favouring essential technologies over optional ones wherever a simpler approach achieves the same editorial purpose. A reader who wants the fullest possible control can reject every optional category described below and still read every article on the site without restriction. This document is written to stand on its own, so a reader who arrives here directly from a search engine, rather than following a link from our privacy policy, should still be able to understand the full picture of what is stored and why. We also try to use plain language rather than technical jargon wherever the underlying mechanism allows it, since a cookie policy that cannot be understood by an ordinary reader does little to support genuine informed consent.
1. Essential Storage
cookieChoice remembers whether a reader selected accept or reject. It lasts 180 days and contains no name or contact detail. After 180 days the value expires automatically and the consent banner reappears on the next visit, at which point the reader is asked to choose again rather than a prior choice being assumed to continue indefinitely. The value stored is limited to a short flag and a date, which means it cannot by itself be used to build a profile of browsing behaviour across sessions. If a reader clears their browser storage manually before the 180 days elapse, the same reappearance of the banner occurs, since the site has no other way to recall the earlier choice. The 180-day window was chosen as a reasonable balance between respecting a reader's original choice and avoiding a consent decision that is treated as permanent regardless of how much time has passed. A reader who visits from a different device or a different browser profile on the same device will see the banner again, since cookieChoice does not synchronise across devices or browsers and is not linked to any account identifier.
- a) cookieChoice: essential, 180-day lifespan, stores accept or reject plus a date.
- b) No essential cookie on this site stores a name, email address, or message content.
- c) cookieChoice is set using standard browser storage mechanisms and is readable only by pages served from the Xyjecta domain, not by unrelated third-party sites.
2. Session Data
Temporary session information may disappear when the browser closes. It helps protect forms and does not create a profile. This category is used, for example, to confirm that a multi-field submission such as an event registration was completed by the same browser session that started it, reducing the risk of a form being hijacked partway through. Because this data does not persist after the browser is closed, it cannot be used to recognise a returning reader on a later visit. No session-level identifier is shared with the optional analytics category described below. In practical terms, this means that if a reader begins filling in the contact form described on contact.php, switches to another tab, and returns a few minutes later within the same browsing session, the partially completed state of certain protective checks remains intact, but nothing about that session is retained once the browser window is fully closed. We do not use session data to pre-fill a returning reader's details on a later visit, since doing so would require a longer-lived identifier than this category is designed to provide.
3. Analytics
Optional aggregate analytics may measure page views, referral category, device family, and approximate region. Identifiers are limited to 13 months. Where this category is enabled by a reader's consent, the identifier is used only to distinguish one anonymous visit pattern from another for the purpose of aggregate reporting, such as noticing that an article on recovery receives more weekend readership than weekday readership. The 13-month maximum is applied even if a reader continues visiting the site past that period, after which point a new identifier is generated if analytics remains enabled. Analytics data is never combined with contact-form correspondence or event-registration records described in our privacy policy. The 13-month figure reflects a commonly used ceiling for analytics identifiers among privacy-conscious publishers, and we apply it uniformly rather than extending it selectively for more frequent visitors. Reports generated from this data are reviewed internally by the editorial team to understand which topics, such as mobility or endurance content, draw sustained readership over time, informing future coverage decisions rather than any commercial targeting activity.
- a) Approximate region is derived at a city or province level, not a precise address.
- b) Device family refers to a general category such as mobile or desktop, not a specific device identifier.
- c) Referral category distinguishes broad sources such as search engine, direct visit, or social referral, without identifying the specific search terms a reader used wherever that information is withheld by the referring platform.
4. Preferences
Preference storage may remember display choices where such a feature is introduced. It is not used to infer health or identity. If introduced, a preference item would typically store something limited in scope, such as a reader's choice between a compact or expanded article layout, rather than anything connected to the reader's personal circumstances. Any future preference storage will be described here with its own name and lifespan before it is activated on the site, consistent with the transparency approach used for the items already listed above. A reader who disables preference storage, once such a feature exists, would simply see the default layout on each visit rather than their last chosen option. We anticipate that any such feature, if introduced, would carry a lifespan comparable to the 180-day essential cookie described in Section 1, since a display preference is the kind of choice a reader would reasonably expect to persist across a typical six-month reading relationship with the site without being permanent indefinitely.
5. Consent
The banner allows acceptance or rejection. Rejecting optional cookies does not prevent reading editorial pages. The banner is presented on a reader's first visit and again after the cookieChoice value expires or is cleared, as described in Section 1. Choosing reject disables the analytics category described in Section 3 while leaving the essential and session categories active, since those are necessary for the site's basic technical operation rather than optional in the same sense. A reader can revisit their choice at any time by clearing the cookieChoice item in their browser settings, which causes the banner to reappear on the next page load. We do not use a pre-ticked acceptance box or a design that makes rejection meaningfully harder to select than acceptance, since both options are presented with equal visual weight on the banner. Consent collected through the banner is treated as the lawful basis for the analytics category specifically, consistent with the legal basis explanation set out in our privacy policy for optional, non-essential processing.
6. Browsers
Browser settings can clear or block cookies. Some functions may respond differently after deletion. Most modern browsers allow a reader to view, delete, or block cookies on a per-site basis through their privacy or security settings, and the exact menu location varies between browsers and versions. Blocking essential storage entirely may cause a multi-step form, such as an event registration, to behave unpredictably, since the browser will not retain the information needed to track progress between steps. We do not consider a reader who blocks all cookies to be in breach of any term, and ordinary articles remain fully readable under that configuration. Readers using a privacy-focused browser mode, such as a strict tracking-prevention setting, may find that the consent banner reappears more frequently than the 180-day cycle described in Section 1, since such modes often clear site storage automatically between sessions regardless of the lifespan we set. This is an expected consequence of browser-level privacy controls rather than a malfunction of the site.
7. Providers
Hosting and measurement providers may process technical events under their own contractual and security commitments. Our hosting provider necessarily sees basic request information, such as which page was requested and when, as an ordinary part of serving the site, independent of any cookie choice a reader makes. Where an analytics provider is used, it operates under a data-processing arrangement limiting its use of the information to providing the measurement service to Xyjecta, rather than its own independent purposes. Further detail on the categories of processor used is set out in our privacy policy, which this page supplements rather than replaces. We select providers that offer region-appropriate hosting or at minimum contractual safeguards consistent with the international-transfer approach described in our privacy policy, since server infrastructure for a site serving Indonesian readers may nonetheless be located outside Indonesia. We periodically review whether a provider's practices remain consistent with the commitments described here, and we would update this page promptly if a change in provider altered the categories of cookie in use.
8. Retention
Consent choice lasts 180 days; server security records may last 90 days; aggregated reports may be retained five years. These figures mirror the retention periods described in our privacy policy for the corresponding categories of information, since a cookie value and the server-side record it relates to are generally retired on a consistent schedule. The 90-day security record period applies to the underlying server logs rather than to the cookie itself, and is intended to be long enough to investigate a suspected abuse pattern without keeping routine technical logs indefinitely. Aggregated reports kept for five years contain no individual-level identifier by the time that period begins, consistent with the approach described for readership statistics in our privacy policy. We chose the five-year figure for aggregated reporting because year-over-year comparison, such as understanding how readership of strength-related content has shifted since the site launched, requires a longer historical baseline than the 13-month analytics identifier itself provides, even though the identifier used to build that aggregate has long since expired.
9. Questions
Contact Xyjecta at Jalan Garuda No. 12, Kebon Sirih, Menteng, Jakarta Pusat 10340, Indonesia. A question specifically about cookies, as distinct from a broader privacy enquiry, can be sent through the same contact form described on contact.php, and marking the subject as a cookies question helps us route it appropriately. We can also be reached by phone at +62 21 6853 0927 during normal Jakarta business hours for a quicker, more conversational explanation of any of the categories described above. We aim to respond to a cookies-related question within the same timeframe described for general complaints in our privacy policy. A question that requires us to check a specific provider's current practices, rather than simply explaining what is already written on this page, may take a little longer to answer fully, and we will say so if that applies rather than giving an incomplete answer quickly.
10. Changes
The present policy was updated on 1 September 2026 and will be dated again when material practices change. The 1 September 2026 update clarified the specific lifespans listed in Sections 1, 3, and 8 without introducing any new category of cookie beyond those already in use on the site. We expect to review this page alongside our privacy policy on a roughly annual basis, and sooner if we introduce a new analytics provider or a new preference feature. Where a future change would introduce a materially new category of tracking, we intend to refresh the consent banner so that returning readers are asked to make a fresh choice rather than having an old choice silently carried forward. We also intend to keep a brief internal log of each dated revision to this page so that, over time, a reader interested in how our cookie practices have evolved could request a summary of that history through the contact details given in Section 9.