Cookie Policy
Last Updated: September 10, 2026
What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help sites remember preferences and recognise returning visitors.
How we use cookies
We set first-party cookies for request security and your selected language. Theme, consent preferences and sign-in sessions use local storage, described separately below.
Types of cookies we use
The table lists the cookies written by this application, their purposes and maximum lifetimes. All use the root path. Clearing them may reset your language preference or interrupt protected requests.
| Name | Purpose | Duration | Essential |
|---|---|---|---|
| NEXT_LOCALE | Remembers your selected language for routing. SameSite=Lax; Secure on HTTPS. | Duration: 30 days | Essential: Yes |
| i18next | Remembers your language preference for client-side detection. SameSite=Strict; Secure on HTTPS. | Duration: 30 days | Essential: Yes |
| csrf-token-http-only | Server-side token for cross-site request forgery protection. HttpOnly; SameSite=Strict; Secure in production. | Duration: 1 day | Essential: Yes |
| csrf-token | Client-readable token sent in request headers for cross-site request forgery protection. SameSite=Strict; Secure in production. | Duration: 1 day | Essential: Yes |
| sb-<project-ref>-auth-token | Keeps you signed in. Holds the Supabase access and refresh tokens, split into numbered chunks when large. Readable by the page script so the app can restore your session; SameSite=Lax; Secure on HTTPS. | Duration: Session, refreshed while you are active; removed on sign-out or after 30 minutes without activity | Essential: Yes |
| elderwise-last-activity | Records server-confirmed activity for the 30-minute idle policy. The server also retains a session-scoped deadline that cookie deletion cannot reset. HttpOnly; SameSite=Lax; Secure on HTTPS. | Duration: One day of timeout evidence; the session still expires after 30 minutes without activity | Essential: Yes |
Local storage
Local storage stays in your browser and is not automatically sent with HTTP requests. These entries are not cookies.
- elderwise-theme: remembers light, dark or system appearance until changed or cleared.
- elderwise_cookie_consent: stores consent preferences with a 12-month validity period; you can change or clear them earlier.
- i18nextLng: remembers your language until changed or cleared.
Managing cookies
You can clear or block cookies through your browser settings at any time. Disabling essential cookies may affect site functionality.
Related Policies
Questions or Complaints?
If you have questions about how we use cookies or this Cookie Policy, please contact us at dpo@ajentik.ai