How Dopomo uses cookies
We use cookies sparingly. Strictly-necessary cookies and a single language-preference cookie always operate so the service works. For traffic measurement we use Matomo analytics, which runs without cookies by default; if you turn analytics cookies on in our banner, Matomo may set its own cookies — that consent is handled solely by our banner. We also use Google advertising and measurement cookies — for ad attribution and conversion measurement — which are optional, denied by default under Google Consent Mode v2, and load only if you accept marketing cookies in our cookie banner; you can change or withdraw each consent at any time.
What cookies are
Cookies are small text files saved by your browser on your device. They let a site remember certain information between visits — for example your chosen language or the fact that you are logged in.
How we use them
Cookies and browser storage run the service: keeping your login session, remembering the interface language, and providing basic security — these are strictly necessary and always on. Separately, we use Google advertising and measurement cookies for ad attribution and conversion measurement; these are optional and require your consent. Because of them we show a cookie banner: optional cookies are off by default (Google Consent Mode v2) and load only if you accept, and you can change your choice at any time. Separately, with your consent, Matomo may use its own analytics cookies (section 05).
The types we use
Essential — necessary for the service to work. Without them, login and basic features will not work. The session cookies are marked HttpOnly, meaning they are not accessible to page scripts.
| Name | Purpose | Duration |
|---|---|---|
| better-auth.session_token | Keeps your session after you log in. | 7 days |
| better-auth.session_data | A short session cache. | about 5 minutes |
| better-auth.dont_remember | A “don’t remember me” flag. | Session |
| __cf_bm / cf_clearance | Bot protection at the network edge (Cloudflare). | Short-lived |
| rp_anon_quota | Enforces the monthly free allowance of 3 chat messages for signed-out users (renews monthly on a rolling window from the first message, abuse prevention). First-party, HttpOnly, content-free, no tracking. | 13 months |
| better-auth.better-auth-passkey | If you turn on passkey sign-in (passkey / WebAuthn — e.g. Face ID or a fingerprint), this cookie holds a single-use cryptographic challenge only for the duration of one sign-in or passkey registration. It is not used for analytics or tracking. | Short-lived (one ceremony) |
| __Host-csrf-token | Protects forms and requests against CSRF attacks; tied to your session, content-free. | Session |
| __Host-bot-check | Confirms that the page was loaded by a browser (bot protection). HttpOnly, content-free. | 24 hours |
| dop_consent | Remembers your cookie-banner decision (a copy of the record kept in local storage). | 182 days |
| dop_measurement_optout | Remembers that you switched off measurement without cookies in the cookie settings (a copy of the local-storage entry). Set only when you switch it off; removed when you switch it back on. | 365 days |
| mtm_consent_removed | A Matomo cookie that remembers you switched measurement off in the cookie settings — while it exists, Matomo does not measure your visits. Set only after you switch off “Measurement without cookies”; removed when you switch it back on. | up to 30 years |
In production, the session cookies carry the secure __Secure- prefix, and our own security cookies the __Host- prefix.
The invisible Cloudflare Turnstile bot check we use on sign-up and chat forms sets no cookies of its own. The __cf_bm / cf_clearance cookies above are Cloudflare’s general edge bot-management cookies, separate from Turnstile.
Preferences — remember your settings so you do not have to choose them each time.
| Name | Purpose | Duration |
|---|---|---|
| NEXT_LOCALE | Remembers your chosen interface language. | 1 year |
Analytics (with consent) — set only after you turn analytics cookies on in the cookie banner; they are handled by Matomo, our processor (section 05).
| Name | Purpose | Duration |
|---|---|---|
| _pk_id.* / _pk_ses.* | Matomo cookies that recognise your browser between visits and within a single visit; set only after you turn analytics cookies on in the banner. | 13 months / 30 minutes |
Marketing (with consent) — set only after you turn marketing cookies on in the cookie banner; they are handled by Google (section 06).
| Name | Purpose | Duration |
|---|---|---|
| rp_gclid | The Google ad-click identifier (gclid) from the address you arrive on. We store it only after you accept marketing cookies in the banner; without consent the cookie is never created, and once you withdraw consent it is deleted. First-party, HttpOnly; used solely to attribute any purchase to the campaign. | 90 days |
Browser storage (local storage)
Besides cookies, we use browser storage. In local storage we keep: your decision about cookies (dop_cookie_consent), a note that you switched off measurement without cookies (dop_measurement_optout — only after you switch it off in the cookie settings; the same marker is also stored as a cookie of that name), the email address remembered for sign-in (dopomo.login.email), a note that you have a passkey (dopomo.passkey.hint), the theme of the report page (dopomo-report-theme), the number of an order whose payment you started, so that we can count the purchase in our statistics even if you never return to the confirmation page (rp.pending_purchase, up to 7 days), a marker that a given purchase has already been counted (rp.purchase_reported:<order number> — we never remove it), a marker that your account registration has already been counted (rp.reg.fired:<user id> — we never remove it) and — in the temporary residence case (TRC) — the identifier of a scan-page merge in progress (trc-scan-assemble-task-id). In session storage (cleared when you close the tab) we keep: your TRC qualification answers (trc:prequal:answers), the language of the entity page (trc-partner-lang), start-up parameters when you open Dopomo in Telegram (__telegram__initParams), a note that you dismissed the processing notice in the application creator, the Sentry session-replay identifier (sentryReplaySession — replays are masked), technical markers that protect sensitive pages and de-duplicate events, and — only in the application creator, the CUKR case and the temporary residence case — an encrypted local store of answers that never reach our servers (criminal-record answers, ethnic nationality, distinguishing marks; keys dopomo.cukr.criminal.v1, dopomo.trc.criminal.v1, dopomo.cukr.personal-sensitive.v1, dopomo.trc.personal-sensitive.v1, dopomo.paper-forms.personal-sensitive.v1). That store is described in the Privacy Policy, section 05.
Analytics (cookieless by default)
To understand how people use Dopomo and to improve the service, we measure traffic with Matomo configured by default in a cookieless mode. By default, Matomo stores no cookies or other identifiers on your device, anonymises your IP address, and does not track you across services. We look only at aggregate data — which pages are visited and where in the journey people drop off — not at any individual’s profile.
Matomo (InnoCraft) is hosted in the European Union and acts as our processor under a data-processing agreement. In its default mode Matomo stores nothing on your device, so it needs no cookie consent. The cookie banner offers three categories: essential (always on), analytics — if you turn these on, Matomo may set its own cookies (_pk_*) that recognise your browser between visits — and marketing, i.e. the Google cookies described under “Third parties”. You can change your choice at any time in “Cookie settings” in the footer.
Third parties
For traffic measurement we use Matomo analytics, cookieless by default (described above), hosted in the EU. For error monitoring we use Sentry (EU), which does not set its own cookies.
We use Google’s advertising and measurement tags (Google Ads and Google Analytics) to attribute visits to our ad campaigns and to measure conversions. These can set Google advertising and measurement cookies. They operate under Google Consent Mode v2: by default they are denied and set no such cookies; they activate only if you accept marketing cookies in our banner, and you can withdraw that consent at any time. Legal basis: your consent (GDPR Art. 6(1)(a)). We do not sell your data, and we do not share it with third parties for their own advertising.
When you arrive from a Google ad, the ad-click identifier (gclid) may be stored on our servers for up to 90 days, linked to a payment order, solely to measure that conversion; it is shared with Google for ad attribution and with no other third party. The legal basis is your consent to marketing cookies (GDPR Art. 6(1)(a)).
Online payments (e.g. for the CUKR case) are made by redirecting you to the Autopay payment provider’s page. Any cookies set on the payment page are governed by Autopay’s cookie policy on its domain, not ours. If in the future we embed an Autopay payment script or widget on our own page, we will update this policy.
How to manage them
You can delete or block most cookies in your browser settings. Bear in mind, however, that blocking essential cookies will make login and the use of some features impossible. You can clear browser storage by clearing the site data in your browser.
You can read more about how we process data in the Privacy Policy.