Cookie Policy
Last updated : 24 mai 2026
🍪 Short version
Parato uses no advertising cookies, no third-party trackers (Google Analytics, Meta Pixel, etc.), and does not sell any data. Only strictly necessary cookies for the service’s operation are set.
What is a cookie?
A cookie is a small text file placed on your device by a website. It is typically used to remember usage preferences, keep a session open, or measure audience.
Cookies Used by Parato
| Name | Role | Duration | Type |
|---|---|---|---|
| authjs.session-token | Keeps you logged in after magic link authentication | 30 days | Strictly necessary |
| authjs.callback-url | Redirect URL after authentication | Session | Strictly necessary |
| authjs.csrf-token | Protection against CSRF attacks | Session | Strictly necessary (security) |
| __Host-authjs.csrf-token | Secure variant of the CSRF token (HTTPS only) | Session | Strictly necessary (security) |
All these cookies are marked HttpOnly, Secure, and SameSite=Lax: they are inaccessible via JavaScript or cross-site, and only transmit over HTTPS.
What Parato Does Not Use
- ❌ No advertising cookies (Google Ads, Meta Pixel, TikTok Pixel, etc.)
- ❌ No third-party tracking cookies (Google Analytics, Hotjar, Mixpanel, etc.)
- ❌ No embedded social media pixels
- ❌ No cookies shared with commercial partners
Analytics (Vercel Analytics & Speed Insights)
Parato uses Vercel Analytics and Vercel Speed Insights to measure service usage and technical performance. These tools operate without cookies and without any identifying personal data: they only collect aggregated metrics (page visited, browser, region — city/country, never full IP) from anonymized server signals.
Vercel Inc. operates these tools. GDPR-compliant configuration documented here: vercel.com/docs/analytics/privacy.
Consent
Since Parato only uses strictly necessary cookies (exempt from consent under Article 82 of the French Data Protection Act and CNIL Recommendation 2020), and analytics are cookieless and non-identifying, no consent banner is displayed. If Parato were to introduce non-essential cookies in the future, a consent banner would be implemented before any storage.
Local Storage (localStorage / IndexedDB)
Parato also uses your browser’s local storage to:
- Store interface preferences (theme, language) — persistent
- Keep a draft of an in-progress consultation locally — purged after submission
- Service Worker cache for PWA offline mode — purged on logout
This data remains on your device and is not transmitted to Parato.
How to Delete Cookies
You can block or delete Parato’s cookies at any time via your browser settings. Note: deleting the session cookie will log you out, and you will need to reconnect via magic link.
Contact
Questions about cookies: dpo@parato.app