Cookie Policy
This Policy explains how NeoMCQ uses cookies, session tokens, and local storage mechanisms to authenticate accounts, save user preferences, and safeguard platform security.
1. What Are Cookies & Local Storage?
Cookies are small text files stored on your computer, tablet, or mobile browser when you visit a web platform. Local storage and session storage are modern HTML5 web technologies that allow applications to store data directly within your browser.
NeoMCQ utilizes essential cookies and local storage items strictly to maintain user sign-in sessions, remember your active examination curriculum, store UI dark/light mode choices, and protect against automated security exploits.
2. Strictly Necessary Essential Cookies
These cookies are mandatory for the application to function. Without them, secure authentication, billing verification, and candidate dashboards cannot be provided:
- Supabase Auth Tokens (
sb-*-auth-token): Cryptographically signed HTTP-only session cookies issued by Supabase Auth to keep you securely signed in as you navigate between MCQ practice drills, quizzes, and flashcards. - CSRF Protection & Security Headers: Tokens used to verify that server requests originate genuinely from your browser session, preventing Cross-Site Request Forgery (CSRF) attacks.
3. Preference & State Storage
We use local storage keys to remember your personalized workspace configuration:
neomcq_user_session: Stores non-sensitive cached user state (active exam selection, target year) to prevent unnecessary re-fetching on page load.theme: Remembers your preferred interface appearance (dark mode, light mode, or system default).
4. Security, Fraud Prevention & Performance
Security cookies and edge telemetry logs allow us to identify bot scraping networks, brute-force login attempts, and quota circumvention scripts. We do NOT use invasive advertising tracking cookies or cross-site tracking beacons.
5. Third-Party Service Provider Cookies (Razorpay & Supabase)
When completing subscription transactions, Razorpay’s embedded checkout iframe may drop temporary fraud detection cookies to verify cardholder authorization and prevent carding attacks.
6. Managing & Disabling Cookies
You can manage or disable cookies through your browser privacy settings (e.g., Chrome Settings > Privacy and Security > Cookies).
Note: Disabling essential authentication cookies will prevent you from signing in to your NeoMCQ account or accessing paid study features.
7. Policy Updates & Inquiries
Questions regarding cookie management may be submitted to privacy@neomcq.com.