Cookie Policy
This English text is for information only. In case of discrepancy, the Turkish version prevails.
This policy describes the cookies, similar technologies, and browser storage used by the gerekli.tr platform on your device. Client-side analytics and performance tools are loaded only after you choose the relevant options in Cookie Preferences. Server-side error logs (Sentry) are processed under legitimate interest independently of cookie consent; for details, see Section 9 of the Privacy Notice (KVKK).
1. What Are Cookies?
Cookies are small text files that websites store in your browser. Similarly, localStorage is used to store data in your browser; unlike cookies, it is not automatically sent with HTTP requests.
sessionStorage is also kept in the browser and normally lasts only for the current browser tab or session. It is not automatically sent with HTTP requests.
2. Essential — localStorage (Not a Cookie)
Data required for gerekli.tr's core functionality is stored in browser localStorage. These are not cookies but do store data on your device:
| Key | Purpose | Duration |
|---|---|---|
gerekli.schedule.v2 | Course schedules, GPA rows, the active plan, theme/language preferences, and catalog preferences | Until cleared from this browser |
gerekli.semester.v1 | Preserved semester/lifecycle data and attendance entries from supported legacy data; attendance tracking is not an active public feature | Until cleared from this browser |
gerekli.semesterArchive.v1 | Completed-term schedule archive snapshots | Until cleared from this browser |
gerekli.academicHistory.v1 | Your approved academic-history snapshot, such as course attempts, ECTS, and term GPAs | Until cleared from this browser |
gerekli.consent.v1 | Your analytics and performance choices | Until cleared from this browser |
Small additional local markers support account/device safety, temporary prompts and article feedback, and local analytics de-duplication. The de-duplication marker is not uploaded as analytics data.
3. Temporary sessionStorage
The app uses short-lived sessionStorage values for tab coordination, completing a sign-in step, temporary interface state, and telemetry de-duplication or trace continuity after the relevant option is enabled. With analytics permission, a random tab reference may accompany explicit course add/remove measurement; it is not a device ID and is hashed before being stored in our backend. The browser normally removes these values when the tab or session ends.
4. Essential — First-Party Cookies
| Cookie | Purpose | Duration |
|---|---|---|
theme | Light/dark theme preference | 12 months |
gerekli.dept | Remembers the selected department/catalog context | 12 months |
NEXT_LOCALE | Remembers your selected language | 12 months |
gerekli_consent | A companion copy of your analytics and performance choices; the app reads the corresponding local preference to decide whether optional tools load | 12 months |
5. Essential — Supabase Auth Session Cookies
When you sign in, the Supabase authentication system uses cookies to manage your session:
sb-*-auth-token— session token used to keep you signed insb-*-auth-token-code-verifier— temporary PKCE verification value used during OAuth sign-in
6. Analytics — PostHog, Vercel Analytics, and Google Analytics 4 (Consent Required)
When you accept analytics preferences, PostHog, Vercel Analytics, and Google Analytics 4 are loaded.
PostHog: Provides product analytics about pages and selected product use. Session replay is disabled in the current public product, so PostHog does not record screen sessions. After loading, it may use ph_* cookies and its own localStorage entries to maintain an analytics session. Data is processed on servers in the EU region at eu.i.posthog.com.
With analytics permission, explicit course add/remove actions are also measured through a separate Supabase path to understand catalog use. This can include course/catalog and term details plus pseudonymous references; it is not sent to PostHog and does not store your name or email.
Vercel Analytics: First-party page view and traffic measurement (may use cookieless measurement methods).
Google Analytics 4: Provides page view and basic traffic measurement. Google Signals and advertising personalization signals are disabled; sensitive URL values are redacted before sending.
These tools are loaded only when you accept analytics preferences. PostHog retention is up to 90 days.
7. Performance — Sentry and Vercel Speed Insights (Consent Required)
With your acceptance of performance preferences, on the client side:
- Sentry (client): Reports sanitized browser-side JavaScript errors and a limited sample of performance traces. Session replay is disabled, and the client is configured not to send cookies or page content. Retention: up to 90 days.
- Vercel Speed Insights: Page load performance (Core Web Vitals)
Note: Server-side Sentry error logs are processed under legitimate interest independently of this category and do not set browser cookies. They may record technical data such as IP address and error messages (PII is minimized).
8. Managing Cookies and Optional Measurement
You can manage your browser storage, cookie, and optional measurement choices in the following ways:
- Cookie Preferences: The "Cookie Preferences" link in the page footer — change your preferences at any time
- First-visit banner: Accept all, essential only, or select your choices and save
- Browser settings: Delete or block cookies
- Session cookies: Sign out to end Supabase session cookies
- Withdrawal: Turning off an optional category stops future client-side collection and attempts to clear known provider cookies. Previously collected provider records are not erased by the browser preference change and follow the retention periods described in the Privacy Notice (KVKK).
9. Contact
For questions about our cookie policy, email hacettepeliyegerekli@gmail.com.
Related documents: Privacy Notice (KVKK) · Privacy Policy