Cookie & storage disclosure

MedKura uses browser cookies + localStorage for sign-in, your role-based routing, chat continuity, and (optionally) anonymous performance analytics. We never use marketing / advertising trackers — no Google Analytics, no Facebook Pixel, no AdWords.

This page lists every single item we set in your browser, why we set it, and how long it lives. Under India's Digital Personal Data Protection Act 2023 you have the right to know exactly this.

Your current preference: not decided yet

The banner will appear at the bottom of any page on your next navigation. Pick a preference there.

Strictly necessary

Required for the app to function. Without these, you cannot sign in, your session would not survive a page refresh, and the chat widget could not authorise your messages. DPDP §6(2) "performance of contract" treats these as not requiring separate consent.

medkura_session

Cookie · JS-readable

Signals you are signed in; read by Next.js middleware

Lifetime

7 days

medkura_role

Cookie · JS-readable

Your role (PATIENT/DOCTOR/LAB/HOSPITAL) for portal auto-routing

Lifetime

7 days

medkura_refresh

Cookie · HttpOnly

JWT refresh token so your access token can be renewed without re-login

Lifetime

7 days, path-restricted to /auth/refresh

medkura-auth

localStorage

Holds your access + refresh token in this browser tab so a page reload keeps you signed in

Lifetime

Cleared on sign-out or auth failure

medkura.onboarding-draft.[ROLE]

localStorage

Auto-saves your registration form so a connection drop does not lose typed data

Lifetime

Cleared on successful registration submit

Functional

Improve your day-to-day experience. Optional but losing them means the chat widget would not resume across page reloads, your notification-sound preference would not stick, and the PWA install banner would re-appear after every dismiss.

medkura_visitor_id

localStorage

Anonymous UUID for chat continuity if you are not signed in

Lifetime

Until you clear browser data

medkura_chat_session_id

localStorage

Current chat session ID so a tab refresh resumes the same conversation

Lifetime

Until the chat is closed or expires

medkura_chat_sound_enabled

localStorage

Care Rep chat notification sound on/off preference

Lifetime

Until you clear browser data

medkura_pwa_install_dismissed_at

localStorage

Timestamp when you dismissed the install prompt, so we do not nag again right away

Lifetime

Until you clear browser data

Analytics

Anonymous performance measurements sent only to our own servers. We use this to find slow pages + crashes — never to identify you. We do NOT use Google Analytics, Facebook Pixel, or any cross-site tracker. Default OFF; opt-in only.

Web Vitals beacon

localStorage

Page load timings (LCP, FID, CLS, INP, FCP, TTFB) sent to /api/analytics/vitals

Lifetime

Real-time beacon, no persistent storage

Sentry SDK

localStorage

Error stack traces if a page crashes (PII stripped before send). Only if SENTRY_DSN is configured.

Lifetime

Per-error; not retained client-side

Third-party services

Specialist services that only load when you use a specific feature. Razorpay is loaded only when you reach a payment screen; Daily.co only when you join a video consultation. These providers set their own cookies under their own privacy policies — we link to both below.

Razorpay (checkout.razorpay.com)

Cookie

Payment gateway for consultation fees + EMI

Lifetime

Razorpay-controlled. See https://razorpay.com/privacy/

Daily.co video iframe (daily.co)

Cookie

Telemedicine video consultation room

Lifetime

Daily.co-controlled. See https://www.daily.co/privacy/