Cookie policy

Effective October 1, 2026. This notice explains small browser files and similar technologies used by Zenith.

1. What cookies do

Cookies are text values stored by a browser for a site. They can remember a session, support security, or help a publisher understand aggregate use. They cannot read unrelated files on your device. A browser can delete or block them. For example, a cookie set by zenith's own domain cannot read a cookie set by an unrelated banking site, since browsers isolate cookie storage by domain as a basic security boundary. The practical consequence of this isolation is that cookies used on this site pose no risk of exposing unrelated accounts or files stored elsewhere on a reader's device. An edge case involves private or incognito browsing modes, where cookies are typically stored only for the duration of that browsing session and discarded when the window closes, meaning choices such as the cookie-banner response will not persist to a later private session. Readers using browser extensions that block cookies by default may find that even essential cookies described below are restricted, which can affect basic navigation reliability.

  • a) Domain isolation means a Zenith cookie cannot be read by, or interfere with, an unrelated website's own cookies.
  • b) Private or incognito browsing sessions generally discard cookies, including the cookie-choice preference, once the session ends.
  • c) Browser extensions that block cookies broadly may also block essential navigation cookies, with resulting minor functional effects.

Cookies should also be distinguished from similar technologies such as local storage and session storage, which some browsers also make available to websites. Zenith's own use of these adjacent technologies is limited to the same purposes described throughout this policy, namely remembering a cookie-choice decision and supporting basic navigation, rather than any separate tracking mechanism operating outside the scope described here.

2. Essential cookies

Essential technologies may support navigation, security, and the cookie-choice record. The cookieChoice value used by our banner records accept or reject status. It is a first-party preference and may remain for up to 12 months unless you remove it. Without it, the notice may appear again. A concrete example is a reader who selects "Reject" on first visit; the cookieChoice value stores that decision so the banner does not reappear on every subsequent page view within the browser for up to 12 months. The practical consequence of this cookie being first-party is that it is set directly by zenith's own domain rather than by an external advertising network, and it is not shared with or readable by third-party sites. An edge case involves switching between browsers or devices, for example from a desktop browser to a phone; because the cookieChoice value is stored locally per browser, the choice made on one device does not automatically transfer to another, and the banner will appear again on the new browser until a choice is made there too.

  • a) The cookieChoice value is set and read only by the zenith domain, never shared with external advertising networks.
  • b) A choice made in one browser or device does not automatically apply to a different browser or device.
  • c) Manually deleting browser cookies removes the cookieChoice value and causes the banner to reappear on the next visit.

3. Analytics

If enabled, optional analytics help us understand page visits and broad device patterns. We do not use analytics to diagnose health, infer sensitive traits, or sell profiles. Analytics identifiers may last up to 13 months. They are activated only where the relevant consent choice permits them. A concrete example of the kind of insight analytics provides is aggregate information showing that the Mobility and Recovery pages receive more visits from mobile devices than desktop, which helps inform layout priorities without identifying any individual reader. The practical consequence of the 13-month identifier lifespan is that an analytics cookie set today would, absent a browser-side deletion, expire on its own by roughly the same date in the following year, consistent with common regional guidance on analytics cookie lifespans. An edge case involves a reader who accepts analytics, then later changes their mind using the banner; from that point forward no new analytics data is recorded for that browser, though previously recorded aggregate statistics, which by then are not attributable to the individual visit in an identifiable way, are not individually retrievable or deletable as personal data.

  • a) Analytics output used by Zenith is aggregated and used for layout and content-planning decisions, not individual profiling.
  • b) The 13-month maximum identifier lifespan follows common regional guidance for analytics cookie duration.
  • c) Withdrawing analytics consent stops future data collection but does not retroactively alter already-aggregated historical statistics.

Where analytics is enabled, the specific cookie currently in use is set by Plausible Analytics, a provider chosen specifically because it does not rely on persistent cross-site identifiers and reports aggregate figures only. Readers wanting more detail on this specific provider's own technical approach can consult its publicly published documentation, which this policy summarises rather than duplicates in full.

4. Preferences

Preference values may remember accessibility or display choices when those features exist. They are not required for public reading. Preference lifespans are normally 12 months. Clearing browser data removes them. A concrete example would be a stored preference for a larger text size or a reduced-motion display setting, consistent with the accommodations described on the Accessibility statement page. The practical consequence of preference cookies not being required for public reading is that every article remains fully accessible by default even to a reader who has never interacted with any preference control. An edge case involves a shared or public computer, where a preference set by one person, for example a larger font size, would remain active for the next person using that browser profile until it either expires after roughly 12 months or is cleared manually, which is a consideration for anyone using Zenith on a shared device.

  • a) Preference cookies supplement, but are never a prerequisite for, basic readability of public content.
  • b) A 12-month lifespan applies to preference values in the absence of manual deletion.
  • c) Shared-device users should be aware that a previous user's display preference may carry over until cleared.

5. Your controls

Select Reject on the banner to decline optional categories. You can also use browser privacy controls, delete stored site data, or block future cookies. Blocking essential technologies may affect small interface functions. Choices can be changed by clearing the cookieChoice value and revisiting the site. A concrete example of using browser-level controls is opening the site-settings panel in a modern browser and manually removing all stored data for the zenith domain, which resets every cookie described in this policy at once. The practical consequence of blocking essential cookies specifically is relatively minor on Zenith, since the site does not require login or checkout functionality; the main effect is that the cookie banner may reappear more often than intended. An edge case involves ad-blocking or privacy-focused browser extensions that proactively strip cookies on every page load; readers using such tools should expect the banner to appear on most visits, which is an expected side effect of that tool's behaviour rather than a site malfunction.

  • a) Browser-level data clearing resets all categories of cookies described in this policy simultaneously.
  • b) Blocking essential cookies on Zenith mainly results in a repeatedly reappearing banner rather than loss of core content access.
  • c) Privacy-focused browser extensions that strip cookies automatically will cause the banner to reappear frequently as an expected side effect.

6. Third parties

Embedded third-party services may set their own cookies if a page uses them. Those providers describe their technologies in their own notices. Zenith limits embeds and reviews whether they are useful to readers. Contact us for a current service question. A concrete example would be an embedded video player on an article discussing a training demonstration, which, if used, may set its own cookies governed by that provider's separate policy rather than this one. The practical consequence of our stated approach to limiting embeds is that most Zenith articles rely on static images and text rather than third-party widgets, which keeps the number of external cookie sources low. An edge case involves a third-party embed that is later removed from a page after publication; any cookies previously set by that provider in a reader's browser are not automatically removed by Zenith and would need to be cleared through the reader's own browser controls described in Section 5.

  • a) Embedded third-party tools, where used, are governed by that provider's own separate cookie and privacy notice.
  • b) Zenith's general preference for static content over embedded widgets limits third-party cookie exposure across the site.
  • c) Removing an embed from a page does not retroactively clear cookies it may have already set in a reader's browser.

7. Do not track

Browser signals vary in meaning and are not interpreted as a universal opt-out by every provider. Our banner remains the clearest way to express an optional analytics choice. We avoid unnecessary tracking. We will review this approach as standards develop. A concrete example of this inconsistency is that a Do Not Track browser signal is treated differently, or sometimes not at all, by different analytics and advertising providers across the industry, which is why no major regulator currently treats it as a binding universal standard. The practical consequence for Zenith readers is that the cookie banner's explicit accept or reject choice is the reliable mechanism for controlling optional analytics on this site, regardless of whether a Do Not Track signal is also enabled in the browser. An edge case involves browsers that enable Do Not Track by default without an explicit user choice; because the signal's meaning is ambiguous in that situation, we continue to rely on the banner interaction itself as the operative signal of reader intent.

  • a) Do Not Track signals are not treated as a substitute for an explicit banner choice on this site.
  • b) Industry-wide inconsistency in honouring Do Not Track is the main reason it is not relied upon as the primary control.
  • c) Browsers enabling the signal by default do not change how Zenith's own banner-based consent mechanism operates.

8. Retention

Cookie lifespans are listed above where known. Server logs connected with cookie security are generally retained for 90 days. Contact messages are normally kept for 24 months. Aggregated reports may be retained longer when they cannot reasonably identify a person. A concrete example of an aggregated report retained longer than 90 days is a yearly summary showing overall visit trends across Zenith's main sections, which by its aggregated nature does not identify any individual reader and therefore falls outside the shorter personal-data retention windows. The practical consequence of distinguishing identifiable logs from aggregated reports is that Zenith can retain useful long-term editorial planning statistics without keeping identifiable browsing histories about any specific visitor. An edge case involves a security log that becomes relevant to an active investigation before the 90-day period expires; consistent with the Privacy policy's retention section, such a log may be preserved beyond the normal window until the investigation concludes.

  • a) Aggregated, non-identifying reports may be retained well beyond the 90-day window applied to identifiable security logs.
  • b) Contact-message retention under this policy mirrors the 24-month figure set out in the Privacy policy.
  • c) Logs relevant to an active security investigation may be preserved beyond 90 days until that investigation is resolved.

Readers wanting a single consolidated view of every retention period mentioned across Zenith's policies, rather than cross-referencing this page against the Privacy policy separately, are welcome to request a short written summary through Contact, which we will prepare based on the figures stated in both documents as they stand at the time of the request.

9. Children

Zenith is intended for adults and does not knowingly place marketing cookies for children. Guardians can contact us if a child has interacted with the site. We will review the circumstances. Where appropriate, we will remove related information. A concrete example mirrors the scenario described in the Privacy policy: a household device used by both an adult and a child might generate cookie data under circumstances a guardian later flags to us. The practical consequence of Zenith's adult-oriented subject matter is that marketing cookies are not deployed in a manner designed to appeal to or target children in the first place, which limits the scope of this concern considerably. An edge case involves shared-device cookie data that cannot be clearly attributed to a specific individual, adult or child; in that situation we review the available information as best we can and err toward removal where a guardian raises a genuine concern.

  • a) Marketing or analytics cookies on Zenith are not designed or targeted to appeal to children.
  • b) Guardian-reported concerns are reviewed and, where appropriate, result in removal of related stored information.
  • c) Shared-device ambiguity is resolved in favour of removal when a guardian raises a genuine concern.

10. Questions

Questions can be sent through Contact or to +62 812 7384 5901. Please state the browser and approximate date without sending passwords. We aim to reply within five working days. We may request clarification before changing a technical setting. A concrete example of a helpful question would be a reader reporting that the cookie banner keeps reappearing despite repeatedly selecting Reject, along with the browser name and roughly when the issue began, which helps us diagnose whether it is a local browser setting or a site-side issue. The practical consequence of the five-working-day reply target mirrors the approach described in the Privacy policy's complaints section. An edge case involves a technical question that requires testing on the reporter's specific browser version before we can confirm a fix; in that situation we will say so plainly rather than offering a guess, and may ask for a short follow-up once a proposed fix is in place.

  • a) Reports of recurring banner issues are most useful when they include the browser name and an approximate date.
  • b) The five-working-day reply target aligns with the acknowledgment approach used across Zenith's other policy pages.
  • c) Complex technical issues may require a follow-up exchange before a fix can be confirmed.

11. Changes

This policy was issued October 1, 2026. Changes to technologies or law may lead to a new version. The effective date will be updated at the top. Previous versions may be retained for compliance records. A concrete example of a trigger for a new version would be adopting a new analytics provider with a different cookie lifespan than the 13 months currently described in Section 3. The practical consequence of retaining previous versions internally is that, if a dispute arises about what the policy said at a particular point in time, we can refer back to the exact text that was in effect then. An edge case involves a purely cosmetic update to this page's layout without any change to the underlying cookies used; consistent with the approach described in the Privacy policy, such a change would not by itself warrant a new effective date.

  • a) Adopting a new cookie technology with a different lifespan is a typical trigger for a new version of this policy.
  • b) Internally retained previous versions allow us to confirm exactly what was in effect at a given past date.
  • c) Purely cosmetic page updates, without a change to actual cookie practices, do not require a new effective date.