Cookies and local storage
1. What are cookies and local storage
Cookies are small text files that websites store in the user's browser. Local storage (localStorage, sessionStorage) refers to browser areas where applications can store data between sessions or during a single session.
2. Authentication cookies (essential)
To enable account login and maintain an authenticated session, MedFlash uses cookies set by the Supabase Auth library. These cookies:
| Name / pattern | Purpose | Duration |
|---|---|---|
| sb-*-auth-token | Supabase authentication session token | Until account logout |
| sb-*-auth-token-code-verifier | PKCE verifier for the OAuth flow | Short-lived (within authentication flow) |
These cookies are necessary for the operation of the service. Without them, account login is not possible. No consent is required as they are technically necessary.
3. Local storage (localStorage)
| Key | Purpose | Data |
|---|---|---|
| mf_hses_v1_<userId>_<examId> | Active exam session marker — prevents duplicate results on page reload | user_id, exam_id, session_id (UUID) |
localStorage does not contain cookies, analytics data or marketing identifiers. The key is used exclusively to ensure exam integrity.
4. Session storage (sessionStorage)
| Key | Purpose | Lifetime |
|---|---|---|
| mf_rn_<userId> | Flag to prevent re-sending the admin email notification of a new registration within one browser session | Until the tab/browser is closed |
sessionStorage is cleared when the browser is closed and contains no personal user data.
5. Analytics and marketing trackers
6. Cookie management
Most browsers allow you to view, block or delete cookies in settings. Note that blocking authentication cookies makes account login impossible.
7. Why there is no cookie consent banner
MedFlash does not display a cookie consent banner because it uses only technically necessary storage technologies. If in the future we add non-necessary trackers, we will implement an appropriate consent mechanism before loading them.