MedKura uses browser cookies + localStorage for sign-in, your role-based routing, chat continuity, and (optionally) anonymous performance analytics. We never use marketing / advertising trackers — no Google Analytics, no Facebook Pixel, no AdWords.
This page lists every single item we set in your browser, why we set it, and how long it lives. Under India's Digital Personal Data Protection Act 2023 you have the right to know exactly this.
Your current preference: not decided yet
The banner will appear at the bottom of any page on your next navigation. Pick a preference there.
Required for the app to function. Without these, you cannot sign in, your session would not survive a page refresh, and the chat widget could not authorise your messages. DPDP §6(2) "performance of contract" treats these as not requiring separate consent.
medkura_session
Cookie · JS-readable
Signals you are signed in; read by Next.js middleware
Lifetime
7 days
medkura_role
Cookie · JS-readable
Your role (PATIENT/DOCTOR/LAB/HOSPITAL) for portal auto-routing
Lifetime
7 days
medkura_refresh
Cookie · HttpOnly
JWT refresh token so your access token can be renewed without re-login
Lifetime
7 days, path-restricted to /auth/refresh
medkura-auth
localStorage
Holds your access + refresh token in this browser tab so a page reload keeps you signed in
Lifetime
Cleared on sign-out or auth failure
medkura.onboarding-draft.[ROLE]
localStorage
Auto-saves your registration form so a connection drop does not lose typed data
Lifetime
Cleared on successful registration submit
Improve your day-to-day experience. Optional but losing them means the chat widget would not resume across page reloads, your notification-sound preference would not stick, and the PWA install banner would re-appear after every dismiss.
medkura_visitor_id
localStorage
Anonymous UUID for chat continuity if you are not signed in
Lifetime
Until you clear browser data
medkura_chat_session_id
localStorage
Current chat session ID so a tab refresh resumes the same conversation
Lifetime
Until the chat is closed or expires
medkura_chat_sound_enabled
localStorage
Care Rep chat notification sound on/off preference
Lifetime
Until you clear browser data
medkura_pwa_install_dismissed_at
localStorage
Timestamp when you dismissed the install prompt, so we do not nag again right away
Lifetime
Until you clear browser data
Anonymous performance measurements sent only to our own servers. We use this to find slow pages + crashes — never to identify you. We do NOT use Google Analytics, Facebook Pixel, or any cross-site tracker. Default OFF; opt-in only.
Web Vitals beacon
localStorage
Page load timings (LCP, FID, CLS, INP, FCP, TTFB) sent to /api/analytics/vitals
Lifetime
Real-time beacon, no persistent storage
Sentry SDK
localStorage
Error stack traces if a page crashes (PII stripped before send). Only if SENTRY_DSN is configured.
Lifetime
Per-error; not retained client-side
Specialist services that only load when you use a specific feature. Razorpay is loaded only when you reach a payment screen; Daily.co only when you join a video consultation. These providers set their own cookies under their own privacy policies — we link to both below.
Razorpay (checkout.razorpay.com)
Cookie
Payment gateway for consultation fees + EMI
Lifetime
Razorpay-controlled. See https://razorpay.com/privacy/
Daily.co video iframe (daily.co)
Cookie
Telemedicine video consultation room
Lifetime
Daily.co-controlled. See https://www.daily.co/privacy/
Privacy questions? Email our DPO: dpo@medkura.in