Cookie Policy

Last updated: June 20, 2026

Categories of Cookies We Use

Strictly Necessary

Required for authentication, session continuity, security controls, and CSRF protection. These cookies cannot be disabled without breaking core functionality and are exempt from consent under GDPR Article 5(3).

  • Supabase auth cookies (sb-access-token, sb-refresh-token) — keep you signed in.
  • Cookie consent state — remembers your preferences so we don't re-prompt on every visit.

Analytics (optional)

Privacy-respecting product analytics help us see which pages and features are useful so we can improve the product. Analytics load only with your consent. Genetic data is never sent — we sanitize URLs and event payloads to strip gene names, rsIDs, and trait identifiers, and we never record your session.

  • PostHog — product analytics only (no session recording, no genetic data).

Affiliate Referral

We run an affiliate program, so if a partner refers you we set a single referral cookie (via Affonso), lasting up to 30 days, purely to credit that partner if you sign up or purchase. This is referral attribution — not advertising, not cross-site behavioral tracking, and it never contains genetic data. We don't sell or share your data with ad networks.

Manage Your Preferences

You can change your cookie preferences any time from the Cookie Settings link in the page footer, or by clearing your browser's cookies for exomedna.com.

Questions: support@exomedna.com.