COOKIE POLICY

Last Updated: 4 May 2026

This Cookie Policy explains which cookies Gameket uses, why we use them, and how they affect your data. Cookies are small text files saved by your browser when you use our website.

We currently use cookies mainly for authentication, account state, and security. We do not use advertising cookies in the current website code.

Cookies We Use

Cookie NameTypeData StoredPurposeRetentionAccess
tokenEssentialSigned-in user access token (Bearer token)Authenticates user requests to protected pages and APIs.Up to 30 days or until logoutHttpOnly
isLoggedInEssentialBoolean login stateSupports signed-in experience in the interface.Up to 30 daysClient-readable
emailFunctionalUser email addressUsed for account context and convenience features.Up to 30 daysClient-readable
avatarFunctionalUser avatar URLDisplays the user profile image in the UI.Up to 30 daysClient-readable
isPremiumFunctionalPremium subscription statusEnables premium-specific account behavior in the UI.Up to 30 daysClient-readable
premiumDaysLeftFunctionalRemaining premium subscription daysDisplays subscription countdown information.Up to 30 daysClient-readable
isSuspendedEssentialAccount suspension flagHelps enforce account restrictions in user flows.Up to 30 daysClient-readable
twoFactorLoginTokenEssentialTemporary two-factor login tokenBinds 6-digit authenticator code verification to an active login attempt.Up to 10 minutesHttpOnly
cookieConsentEssentialCookie consent choiceStores whether you accepted the cookie notice so the banner is not repeatedly shown.Up to 180 daysClient-readable
adminTokenEssentialAdmin access tokenAuthenticates access to admin dashboard and admin APIs.Up to 30 days or until clearedHttpOnly
authjs.session-token / __Secure-authjs.session-tokenEssentialAuth.js session identifierMaintains session state during Auth.js sign-in flows.Session or provider-managedHttpOnly
authjs.callback-urlEssentialPost-login return URLReturns you to the intended page after authentication.Short-livedClient-readable
authjs.csrf-tokenEssentialCSRF protection tokenProtects authentication and form actions from CSRF attacks.Session or short-livedClient-readable

How Your Cookie Data Is Used

  • • To keep you logged in and protect access to your account.
  • • To show account context, such as avatar and premium status.
  • • To secure authentication flows with anti-forgery protections.
  • • To support admin-area authentication where applicable.

Managing Cookies

You can manage or delete cookies from your browser settings at any time. Please note that disabling essential cookies may prevent login and other account features from working properly.

You can also log out to clear active session-related cookies from Gameket.