Cookie Policy
Last updated: September 10, 2026
1. What cookies are
Cookies are small text files that are placed on your computer or mobile device when you visit a website. Some information described below is stored the same way (in your browser's local storage) rather than as a cookie — we cover both here, since both work by remembering something on your device between visits.
2. How we use them
We use cookies and local storage to keep you signed in, remember your preferences, and — only where you accept it — to understand how the Service is used. We only collect and use this data in accordance with our Privacy Policy.
3. Cookies and local storage we set
| Name | Type | Purpose |
|---|---|---|
authjs.session-token (__Secure- prefixed in production) | Essential | Keeps you signed in |
NEXT_LOCALE | Essential | Remembers whether you're using the site in English or Icelandic |
matinn-locale-landing | Essential | One-time helper so a signed-in user lands in their chosen language right after sign-in |
matinn.invite | Essential | Holds a household invite for up to one hour while you complete sign-in |
matinn-terms-accepted | Essential | Records that you ticked the Terms of Service box before signing in |
cookie-consent, cookie-consent-version (local storage) | Essential | Remembers your cookie preference so we don't ask again |
matinn-app-theme (local storage) | Functional | Remembers your Light / Dark / Nordic / Forest theme choice |
Essential items are necessary for the website to function and cannot be switched off. The functional item above is set only in your browser's local storage, not as a cookie sent to us.
4. Third-party cookies
We only load the following third-party scripts. Each is documented in our
Content Security Policy (src/proxy.ts), which is the authoritative list of
what a page is allowed to load:
- Paddle (
*.paddle.com) — our merchant of record. When you open the checkout overlay, Paddle sets its own cookies to run the payment and fraud-prevention flow securely. We never see your card details. - Aidbase (
*.aidbase.ai) — powers the support chat widget. It may set its own cookie to keep your chat session working across page loads. - Google (
www.googletagmanager.com) — loads Google Analytics 4 (GA4), but only on deployments where we have configured a Measurement ID. When active, Google sets analytics cookies (such as_gaand_ga_*) to distinguish visitors and measure usage. This is the only analytics vendor that sets cookies.
We also use Vercel Analytics for page-view metrics. It is cookieless — it does not read or set any cookie or local-storage value on your device.
Signing in with Google uses Google's own sign-in flow and is subject to Google's cookies during that process; we don't control those. Matinn accounts are created with Google or with an email sign-in link.
5. Managing your preferences
You can control cookies in several ways:
- Most browsers allow you to manage or delete cookies through their settings.
- Use our cookie consent banner to accept or decline the non-essential items above.
- Contact us (details below) with any question about a specific cookie.
Declining the non-essential items does not affect essential ones — those are required for sign-in, language selection, and similar core functions to work at all.
6. Data retention
- Session cookies are deleted when you close your browser.
- The essential cookies above expire on their own (an hour or less, except the session and locale cookies, which last for the length of your session/preference).
- If GA4 is active for a given deployment, Google's analytics cookies are retained per Google's own policy (typically up to 26 months).
7. Changes to this policy
We may update this Cookie Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page.
8. Contact us
If you have questions about our use of cookies, please contact us at samband@matinn.is.