Cookie and analytics statement

Every cookie on both surfaces, named.

Cookies and analytics v1.0 · in effect Updated Privacy Act 1988 (Cth)

This statement names the cookies aurii sets, on the marketing website and in the clinical application, as at 8 October 2026. It is written to the Australian Privacy Principles in the Privacy Act 1988 (Cth). Cookie requests go to privacy@aurii.com.au.

Two surfaces

In this statement, “aurii”, “we” and “our” mean Aurii Pty Ltd (ABN 52 697 638 538). Black Shard Pty Ltd builds, hosts and secures both surfaces under contract.

The marketing website at aurii.com.au and the signed-in clinical application at app.aurii.com.au are separate surfaces. They carry different cookies, set by different code, for different reasons, and the iPhone, iPad and Android apps present the application surface.

The response that serves a page of the marketing website sets no cookie. Every website cookie is written by a script running in the browser, and only in the circumstance stated against it.

Every cookie named here is a first-party cookie on the aurii domain it is listed under, including the three that LinkedIn's tag writes.

The analytics clause in the privacy policy.

Cookies on aurii.com.au

The marketing website sets no strictly necessary cookie. Refusing or deleting every cookie on it costs a visitor no function on any page.

Six is the maximum any one visit can collect. A visit that arrives on an untagged link and did not come from LinkedIn collects two.

  • aurii_ref Channel, aurii's own script, 30 days Written when the link into the site carries ch, utm_source, utm_medium or utm_campaign. It holds that value in a reduced form, lower case with runs of anything that is not a letter or digit collapsed and a 64-character bound. aurii's own tagged links carry a channel word such as linkedin or qr. Path /, SameSite Lax, Secure, readable by this site's own scripts. The first tagged visit writes it and a later visit never overwrites it. An untagged visit writes nothing. Not strictly necessary.
  • _ga Google Analytics 4, about two years Written by Google Analytics 4 under measurement id G-YSM367DY4G to tell one browser from another across page views. Not strictly necessary.
  • _ga_YSM367DY4G Google Analytics 4, about two years The per-property companion to _ga, holding the session state for that measurement id. Not strictly necessary.
  • li_adsId LinkedIn Insight Tag, 180 days A random identifier written on the aurii.com.au domain by LinkedIn's tag, with a browser-storage entry of the same name holding the same value. Path /. It is written on a visit that LinkedIn's tag runs for. Advertising. Not strictly necessary.
  • li_fat_id LinkedIn Insight Tag, 30 days LinkedIn's click identifier, written on the aurii.com.au domain when LinkedIn has appended li_fat_id to the landing address of an advertisement. Path /. Advertising. Not strictly necessary.
  • li_giant LinkedIn Insight Tag, 7 days Written on the aurii.com.au domain by the same tag alongside li_fat_id when that click identifier is present. Advertising. Not strictly necessary.

Google Analytics 4 is fetched on the first click, key press, touch or scroll, 3.5 seconds after the page loads, or when the visitor leaves the page, whichever comes first, so its two cookies are written at that moment and not at page load.

Cloudflare Web Analytics and Black Shard Analytics set no cookie and use no browser storage to measure a visit.

The LinkedIn Insight Tag

aurii advertises on LinkedIn, and the LinkedIn Insight Tag, partner id 10164916, measures what those advertisements produce.

Its loader is served to every visitor on every page. The loader decides in the browser whether to go further, and for almost every visit it stops there: no LinkedIn script is fetched, no LinkedIn host is contacted and no cookie is written.

It goes further for a visit that arrived from LinkedIn, and for a later visit from the same browser while the channel cookie lasts. That is read from the aurii_ref channel cookie holding linkedin, which is kept for 30 days, or from ch=linkedin, utm_source=linkedin or LinkedIn's li_fat_id click identifier on the landing address.

It stops for a browser sending Global Privacy Control or Do Not Track, before any LinkedIn script, cookie or request. It also stops under an automated browser.

On a visit it does run for, it loads LinkedIn's script from snap.licdn.com, writes two or three first-party cookies on aurii.com.au, and reports the pages viewed. LinkedIn sets its own cookies on linkedin.com on that same visit, which LinkedIn handles under its own privacy policy.

One conversion is reported to LinkedIn: the click of a link to app.aurii.com.au/signup, which LinkedIn records as a trial signup start. It is sent once per page at most.

The tag does not run in the clinical application, and no clinical information reaches LinkedIn.

LinkedIn's privacy policy.

Analytics on aurii.com.au

Three analytics services run on every page of the marketing website.

  • Google Google Analytics 4, third party, two cookies Measurement id G-YSM367DY4G. It records page views, clicks on telephone and email links, clicks on the App Store badge and on the trial link, and that a form was submitted. Advertising storage, advertising user data and advertising personalisation are denied on every page load, before the tag is fetched, so no Google advertising cookie is written and no cross-site advertising signal is sent.
  • Cloudflare Cloudflare Web Analytics, third party, no cookies It records page views. The beacon script reads and writes no cookie, no local storage and no session storage.
  • Black Shard Black Shard Analytics, first party, no cookies aurii's own collector, run by Black Shard Pty Ltd on its own servers in the Azure Australia East region. It writes no cookie. It reads one browser-storage entry, umami.disabled, and sends nothing while that entry is set. On the marketing website it receives the page address including its query string, the page title, the referring domain where there is one, the screen size and the language.

An email address typed into a sign-up block on this site reaches no analytics service. Only the fact of a submission is counted.

None of the three reads Global Privacy Control or Do Not Track. Only the LinkedIn tag does.

Black Shard Analytics is the one of the three that also runs inside the clinical application.

Browser error reporting

When a script on the marketing website fails in a visitor's browser, the page sends a report to GlitchTip, aurii's own error tracker, which Black Shard Pty Ltd hosts on its own server in Australia.

A report carries whether the fault was an error or a rejected promise, its error class, the page path, the file, line and column in this site's own code, the browser family, and whether the device is a phone, tablet or computer. It never carries the error message, the stack, form contents, a query string, a cookie or an identifier.

This website's own server passes the report on, so the visitor's IP address does not reach GlitchTip. Faults raised by browser extensions and by other sites' scripts are discarded. Reports are kept for 90 days.

The reporter sets no cookie and uses no browser storage.

Cookies the application needs

Every cookie at app.aurii.com.au is first party. None is an advertising cookie, none is read by a third party, and no analytics service writes one.

Strictly necessary here means the application cannot sign a clinician in, keep them signed in, or complete a sign-in handshake without it. A browser that refuses these cookies cannot use the application.

  • Session __Secure-authjs.session-token, 8 hours The signed session token that keeps a clinician signed in. HttpOnly and Secure. Strictly necessary.
  • Forgery __Host-authjs.csrf-token Pairs with a token in the form so a sign-in or sign-out cannot be submitted from another site. Cleared when the browser closes. Strictly necessary.
  • Return __Secure-authjs.callback-url Holds the screen to return to once sign-in finishes. Cleared when the browser closes. Strictly necessary.
  • Handshake __Secure-authjs.pkce.code_verifier, __Secure-authjs.state, __Secure-authjs.nonce, 15 minutes Written only while a sign-in with Google, Microsoft or Apple is in progress, and only for as long as that handshake lasts. Strictly necessary for those three sign-in methods.
  • Device aurii_device_id, 365 days Opaque random bytes that tell one browser from another, so a sign-in from a device the account has not used before can be notified to the account holder. HttpOnly, so no page script reads it, and it carries no user, tenant or device facts. Strictly necessary.
  • Trust aurii_trusted_device, 30 days An opaque token recording that this device has already passed a second factor, so the second factor is not demanded on every sign-in. Rotated on each reissue. Strictly necessary.
  • Practice aurii-active-tenant, 8 hours The practice a clinician who belongs to more than one is currently working in. Same lifetime as the session. Strictly necessary.
  • App sign-in aurii_native_nonce, 5 minutes Written while the iPhone, iPad or Android app exchanges a sign-in token with the server. Strictly necessary on those apps.
  • Handoff aurii_desktop_handoff, 15 minutes Written while a sign-in started on one device is completed on a desktop. Strictly necessary on that path.
  • Biometric aurii_biometric_resume_challenge, 2 minutes A single-use challenge written while Face ID, Touch ID or a device unlock resumes a session. Strictly necessary on that path.

The passkey sign-in challenge moved to server-side storage on 2 October 2026 and is held in the database against the attempt. The two cookies that used to carry it are no longer set.

The access controls behind the session.

Preference cookies in the application

These remember a choice a clinician has already made. Clearing them loses the convenience and nothing else, and none is strictly necessary.

  • Hospital aurii_active_hospital, 1 year The hospital the patient list and the calendar are scoped to. SameSite Lax, Path /.
  • Resume aurii_last_route, 7 days The last top-level screen opened in the iPhone, iPad or Android app, so it resumes where it was left after the operating system has evicted it. It is not written in a web browser. Transient screens, and the sign-in and setup screens, are never recorded.
  • Passkey offer aurii_passkey_offer, 60 days Records that the offer to set up a passkey was dismissed, so it is not raised again for 60 days.
  • Passkey device aurii_passkey_device, 400 days Records that this device already has a passkey enrolled, so the offer is not made on it.
  • Channel aurii_ch, 30 days One word from a closed list, or other, written when the link into the application carries a channel tag, so an account can be counted against the channel that produced it. HttpOnly. It holds no identifier and no free text.

The application keeps some other preferences in the browser's own storage rather than in a cookie: whether the email-verification prompt has been shown, whether a second sign-in route has been seen, whether a passkey offer has been seen, and whether a federated sign-in was attempted. Clearing site data in the browser removes them.

Analytics in the clinical application

Black Shard Analytics is the only measurement that runs in the clinical application. Google Analytics 4, Cloudflare Web Analytics and the LinkedIn Insight Tag do not run there at all.

It records which screen was opened, together with the browser, the operating system, the device class, the screen size, the language and the country that every web request already carries, and the referring domain where there is one. It does not record the IP address, and region and city are not stored.

Before a measurement is sent, the address is rewritten to a route template, so a patient, encounter, letter, message or any other record identifier is replaced by a placeholder and never reaches the collector. Query strings, page titles and free text are dropped in the same step.

No clinical information is recorded and no session recording is loaded.

It writes no cookie in the application.

The sub-processor ledger.

What a visitor can switch off

Nothing has to be accepted to read this website.

  • Browser Cookie controls Blocking cookies for aurii.com.au stops every website cookie. Clearing site data removes the ones already written, together with the li_adsId browser-storage entry. Blocking cookies for app.aurii.com.au prevents signing in to the clinical application.
  • GPC Global Privacy Control A browser sending Global Privacy Control stops the LinkedIn Insight Tag before any LinkedIn script, cookie or request. It does not stop Google Analytics 4, Cloudflare Web Analytics or Black Shard Analytics, none of which reads the signal.
  • DNT Do Not Track A browser sending Do Not Track has the same effect as Global Privacy Control, and the same limit.
  • Blocking Blocking a service outright An extension, a filter list or a DNS rule that blocks www.googletagmanager.com, static.cloudflareinsights.com, analytics.blackshard.com.au or snap.licdn.com stops that service. Every page of this site renders and works with all four blocked.
  • Storage Turning off Black Shard Analytics A browser-storage entry named umami.disabled, holding any value, stops Black Shard Analytics from sending anything from that browser.
  • Google Opting out of Google Analytics Google publishes a browser add-on that stops Google Analytics measuring a browser on every site that uses it.

A cookie or tracking request, and an objection to any of the measurement here, goes to privacy@aurii.com.au. A security matter goes to security@aurii.com.au.

Access, correction and complaints.

Closing an account and what is removed.

Changes to this statement

Version 1.0, in effect 8 October 2026, is the first version. Until it, the cookie and analytics position was stated in the analytics clause of the privacy policy, which remains the clause in the legal instrument.

It states three things that clause does not. The LinkedIn Insight Tag writes first-party cookies on the aurii.com.au domain, li_adsId for 180 days with a matching browser-storage entry, and li_fat_id and li_giant when LinkedIn's click identifier is on the landing address. The channel cookie on this website holds a reduced form of whatever campaign value arrived, bounded at 64 characters, and the closed list of channel words is applied by the application to its own cookie. Every cookie in the clinical application is named, with its lifetime and whether it is strictly necessary.

The passkey sign-in challenge cookies were retired on 2 October 2026 when the challenge moved to server-side storage.

Earlier wording of the analytics clause is recorded in the version history of the privacy policy.

The privacy policy version history.

Contact

A request about the cookies or the measurement on either surface should name the browser and the page it concerns. A request about an account should name the account email.

Cookies and privacy requests privacy@aurii.com.au
Security matters security@aurii.com.au

The security controls sit on the security page, the sub-processors and certifications on the trust page, and the Australian Privacy Principles mapping on the compliance page.

Email us about cookies

This statement sits alongside the privacy policy and the terms of service.