Privacy and cookies
Cookies and privacy are one page here because on a site of this shape they are one subject. What follows describes what actually happens when a browser loads these pages, and what happens to a message sent through the contact form.
How these pages are served
Every page on this site is a static file. There is no content management system behind it, no login, no user account and no personalisation. The files are hosted on Cloudflare Pages and delivered through Cloudflare’s network.
As the infrastructure provider, Cloudflare processes each request in order to serve it, and keeps operational logs of the kind every web host keeps: the requesting IP address, the user agent string the browser sends, the time of the request, and the address requested. Cloudflare handles that data as the service operator, under its own terms, for delivery, caching and abuse prevention.
What runs in your browser
Everything a page here requests comes from this domain: one stylesheet, and on article pages the illustrations. As the site is built today, reading a page sends no request to any third party, so nobody beyond the host described above learns that you loaded it.
That is checkable rather than something you have to take on trust. Every response carries a Content-Security-Policy header describing the restriction the browser is applying, and the full list of resources a page actually loaded is visible in any browser’s network panel. The date at the foot of this page is the date that description was last true.
Cookies
The pages themselves set no cookies, and there is nothing on the site for a cookie to remember. No consent banner appears for that reason.
Cloudflare may set cookies of its own as part of security and bot management — the ones commonly named __cf_bm and cf_clearance. These are set by the network delivering the site, are used to distinguish automated traffic from human traffic, and are described in Cloudflare’s own cookie documentation.
The contact form
The contact form submits to an endpoint on this same domain. A submission records the topic selected, the name entered, the reply address if one was entered, the message text, the IP address the submission came from, the browser’s user agent string, and the time. The technical fields are recorded because they are what makes it possible to identify and discard automated submissions.
Those records sit in a database the publisher controls, and they are read by the publisher for the purpose the message was sent for: checking a correction, following up a source, answering a question. A reply address is optional on the form, and a message sent without one is still read.
The form is the route to the publication.
Asking for a submission to be removed
A message sent through the form asking for an earlier submission to be deleted is enough; quoting a distinctive phrase from the original makes it findable. The same route works for asking what a previous submission contained. Depending on where you live, the law may give you a right to request access to or deletion of the record, and the route is the same either way.
Children
This is a reference publication about medical treatments approved for adults, written for adults. It is not directed at children, and the contact form asks for nothing that would make sense for a child to send.
Links to other sites
Articles link out to primary sources: FDA and CDC pages, journal articles, professional bodies and government complaint channels. Those sites keep their own logs and set their own cookies under their own policies. A link here is a citation of a document.
Changes to this page
If how the site handles data changes, this page is rewritten to describe the new arrangement and the date below is updated. The date is the only reliable indicator of which version you are reading.
Reviewed: 8 August 2026