Cookie Policy
Last updated: August 2026
1. What We Store
This site uses first-party HTTP cookies, browser local storage (localStorage), and per-tab session storage (sessionStorage). They support security, preferences, and requested features. Analytics session storage is created only after analytics consent. We use no advertising storage.
2. HTTP Cookies
All HTTP cookies are first-party. Authentication tokens and the rollout-assignment cookie are HttpOnly. The other cookies remember login status or choices made in the interface.
| Cookie | Purpose | Duration |
|---|---|---|
| access_token | Access JWT for server-side authentication | Session / 30 minutes |
| refresh_token | Session renewal token | 7 days |
| logged_in | Non-sensitive login-status flag used by the interface; contains no token | 7 days |
| sc_country | Selected country for the catalogue and prices | 1 year |
| sc_health_rollout | Random identifier for stable feature assignment; contains no health data | 1 year |
| sc_cookie_consent | Stores the cookie-consent choices selected in the notice | 1 year |
| sc_theme | Light/dark theme preference for server and client rendering | 1 year |
| NEXT_LOCALE | Preferred site language | Browser session |
4. Session Storage (sessionStorage)
Session storage is isolated to the current browser tab and is removed when that tab session ends. The analytics identifier is created only after analytics consent.
| Key | Purpose | Cleared |
|---|---|---|
| assistant_session_id | Identifier linking assistant requests in the current tab; contains no conversation text | At the end of the tab session or when the assistant session is reset |
| health.phase4.recommendation.dismissed | Dismissed Health recommendation type for the current tab; contains no Health values | At the end of the tab session |
| analytics_session_id | Random analytics session identifier, created only while analytics consent is active | At the end of the tab session |
3. Local Storage (localStorage)
Browser local storage holds display state and preferences requested in the interface. Authentication JWTs are never stored there. Before registration, the onboarding cache contains shopping and dietary preferences only—never Health consent or allergen data.
| Key | Purpose | Cleared |
|---|---|---|
| user_data | Cached user profile used to render the account menu without a server round-trip | On logout |
| sc_cookie_consent | Cookie notice preference | Persistent |
| theme | Light/dark theme preference | Persistent |
| sc_onboarded | Marks the first-time tour as completed | Persistent |
| sc_onboarding_prefs | Unsigned pre-registration country, supermarket, and dietary preferences; no Health consent or allergen data | Persistent until manually cleared |
| sc_health_signal_onboarded_v1 | Records that the optional Health signal introduction was completed or dismissed; contains no Health values | Persistent |
| sc_personalised_applied | Records whether consented saved preferences were applied to filters; contains no preference values | When personalised filters are reset or storage is cleared |
5. Third-Party Cookies
We do not use tracking, advertising, or social media cookies. No third-party analytics scripts set cookies on this site.
6. Managing Storage
Clearing storage may sign you out, reset your choices, or interrupt requested features. You can clear it manually in your browser settings.
- Chrome / Edge: F12 → Application → Storage
- Firefox: F12 → Storage
- Safari: Settings → Privacy → Manage Website Data
7. Contact
privacy@supercomparator.es




