Cookie Policy

Last updated: May 8, 2026

This policy explains what cookies and similar storage technologies Medalty uses, why, and how you can control them. Compliant with GDPR (Regulation (EU) 2016/679), the ePrivacy Directive 2002/58/EC, and Greek Law 3471/2006.

1. What cookies are

Cookies are small text files stored on your device by a website. We also classify under "cookie" any equivalent technology: localStorage, sessionStorage, IndexedDB, Service Worker.

2. Essential-only policy

Medalty uses essential cookies only. We don't use advertising cookies, run third-party analytics (Google Analytics, Meta Pixel, etc.), or track your behavior on other sites.

3. Full cookie inventory

NamePurposeTypeLifetimeProvider
sb-access-tokenStores your sign-in tokenEssential1 hour (rolling)Supabase Auth
sb-refresh-tokenAuto-refreshes the sessionEssential30 daysSupabase Auth
NEXT_LOCALERemembers your language (en/el)Functional1 yearMedalty
medalty-cookie-consentStores your cookie banner choiceEssential1 yearMedalty

Because we use onlyessential/functional cookies, prior consent is not required per EDPB Opinion 5/2020 and Greek law — but we show a banner for transparency and to record that you've been informed.

4. Third-party cookies

No third-party service places cookies on your device through Medalty. We do not use:

  • Google Analytics, Google Tag Manager, GA4
  • Meta (Facebook) Pixel, Instagram tracking
  • TikTok Pixel, LinkedIn Insight, Twitter Pixel
  • Hotjar, Mixpanel, Amplitude, Segment
  • Advertising networks of any kind

5. How to control or delete cookies

You can delete or block all cookies from your browser settings:

Note: if you block all cookies, you will not be able to sign in to Medalty.

6. Withdrawing consent

Since we have no optional cookies, accepting the banner only confirms that you've been informed. You can delete the medalty-cookie-consent cookie from your browser at any time to see the banner again.

7. If we add analytics or functional cookies in the future

We'll display a new banner with separate accept/reject toggles per category, in accordance with Article 7 GDPR. Consent will be opt-in, presented equally ("Decline" equally prominent as "Accept"), and revocable.

8. Contact

privacy@medalty.com