Cookies Policy
Last updated:
Language version notice
These legal documents were drafted in Polish. Other language versions may be machine translations and are provided for convenience only. In case of discrepancies, the Polish version prevails.
What this document covers
This policy explains which cookies and which browser storage Medova uses, why, on what legal basis, and how to change it. We apply the ePrivacy Directive (2002/58/EC), Article 173 of the Polish Telecommunications Act and the GDPR (Regulation 2016/679).
By default we set no analytics or marketing cookies at all. Until you click consent in the banner, Google consent mode stays at „denied” and the Meta conversion pixel does not load.
Categories and legal basis
Essential
Needed for the service to work: keeping you signed in, remembering your language, remembering your consent choice, protecting against abuse. These cannot be switched off, because without them the service does not function.
Basis: Article 173(3) of the Polish Telecommunications Act and Article 5(3) of the ePrivacy Directive (the exemption for storage strictly necessary to provide the service the user requested), and Article 6(1)(f) GDPR for any personal data involved.
Analytics
Show us which pages are visited and where people get lost. Set only after your consent.
Basis: Article 6(1)(a) GDPR (consent) and Article 173(1) of the Polish Telecommunications Act.
Marketing
Measure the effectiveness of advertising campaigns and limit repeated display of the same ad. Set only after your consent.
Basis: Article 6(1)(a) GDPR (consent) and Article 173(1) of the Polish Telecommunications Act.
List of cookies and browser storage entries
The full, current list is below this text, in the „Cookies” and „Browser storage” cards. It is generated directly from the register kept in the service's source code, so it cannot drift from what the browser actually stores.
It covers the key name, provider, purpose, consent category and lifetime. The panel for signed-in providers additionally stores view preferences (a collapsed menu, the selected calendar view, an unsent message draft); these are interface settings only, fall under the essential category and are not used for tracking.
Where we load no third-party scripts at all
On pages where the URL itself would say something about your health, we load no third-party analytics or marketing scripts regardless of the consent you have given. This covers in particular the appointment booking wizard, provider profiles and the provider search.
The reason is simple: an address such as „booking an appointment at clinic X” reveals health information by itself, and that information has no business reaching an external advertising vendor.
Changing or withdrawing consent
- In the service: open „Cookie settings” in the footer. Changes take effect immediately, and withdrawing consent stops the scripts from loading right away.
- In your browser: you can delete or block cookies in the browser settings. Browser storage entries can be cleared in developer tools (Application → Local Storage) or by clearing all site data.
- What blocking does: blocking essential cookies makes signing in and remembering your language impossible.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. We ask again when the list of providers or the scope of measurement changes, because earlier decisions no longer describe what is happening.
Third parties and data transfers
The providers named in the list process data under their own privacy policies, and any transfer outside the European Economic Area relies on standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
The full list of processors, with data location and transfer basis, is in the Privacy Policy.
Questions
For anything about cookies and privacy, write to our Data Protection Officer: dpo@medova.health.
What the 16 September 2026 version changed: the list was brought into line with what the service actually stores; Meta conversion cookies and browser storage entries not previously listed were added; measurement that works without cookies was described; the rule about loading no third-party scripts on health-related paths was added; and the entry describing a separate consent store, which has not existed since the banner and the policy page were unified, was removed.
Manage your preferences
You can change your cookie preferences at any time.
Detailed cookie inventory
| Name | Provider | Purpose | Category | Lifetime |
|---|---|---|---|---|
| sb-*-auth-token | Supabase | JWT authentication token | Essential | 1h |
| NEXT_LOCALE | Medova | Language preference | Essential | 1y |
| _ga | Unique analytics visitor ID | Analytics | 2y | |
| _fbp | Meta | Meta conversion measurement browser ID | Marketing | 3mo |
| _fbc | Meta | Recorded click on a Meta ad | Marketing | 3mo |
| _ga_* | Session identifier | Analytics | 2y | |
| _gid | Session identifier | Analytics | 24h | |
| _gat | Request throttling | Analytics | 1min | |
| ab_anon_id | Medova | Anonymous identifier for analytics and experiments | Analytics | 1y |
| ab_disease_v2 | Medova | A/B test variant assignment | Analytics | 30d |
Web Storage (localStorage)
| Name | Provider | Purpose | Category | Lifetime |
|---|---|---|---|---|
| cookieConsent | Medova | Cookie consent preferences | Essential | persistent |
| cookieConsentVersion | Medova | Consent banner version | Essential | persistent |
| stv:theme | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| stv_remember | Medova | Remember me on login | Essential | persistent |
| stv_last_email | Medova | Last used email for login | Essential | persistent |
| stv-msg-notifications | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| stv-workspace-* | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| stv-sidebar-sections-v3 | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| stv-cmd-recent | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| stv-onboarding-dismissed | Medova | Dismissed banner or call-to-action flag | Essential | persistent |
| medova.shell.sidebarCollapsed | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| medova_compare_cities | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| medova-travel-checklist | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| clinic-calendar-view | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| medova-audience-pref | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| push-prompt-dismissed-at | Medova | Dismissed banner or call-to-action flag | Essential | persistent |
| pwa-install-dismissed-at | Medova | Dismissed banner or call-to-action flag | Essential | persistent |
| stv_lead_* | Medova | Dismissed banner or call-to-action flag | Essential | persistent |
| stv:notifications:lastVisit | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| medova.demo.ai-reception.v1 | Medova | Interface preference (theme, layout, list state) | Essential | persistent |
| medova.internal | Medova | Flag marking internal/test traffic | Essential | persistent |
| umami.disabled | Medova | Analytics opt-out flag | Essential | persistent |
