Legal information
Cookie Policy
This policy explains the cookies Enbilir uses for secure sessions, authentication, and remembering preferences; similar technologies such as localStorage and sessionStorage; and how you can control them.
Last updated: July 13, 2026
The session cookie is set for no more than 7 days.
Behavioral marketing cookie profiling is not currently used.
You can clear browser-stored preferences at any time.
What are cookies and similar technologies?
A cookie is a small text record a website places in your browser. localStorage generally keeps browser-side data more persistently, while sessionStorage usually lasts for the tab or browser session. These technologies do not by themselves access unrelated files on your device.
Enbilir uses them to operate securely, prevent duplicate actions, and remember settings you choose. Their legal treatment depends on purpose rather than the technology's name.
Essential cookies currently used
The following cookies are necessary for membership, authentication, or transaction security. HttpOnly cookies cannot be read by browser JavaScript; in production, Secure cookies are sent only over HTTPS.
- enbilir_session: recognizes a signed-in user and maintains the secure session. HttpOnly, SameSite=Lax, Secure in production; maximum life 7 days and deleted on logout.
- enbilir_google_oauth_state: verifies that a Google sign-in request began in the same browser and reduces redirect attacks. HttpOnly, SameSite=Lax, Secure in production; maximum 10 minutes.
- enbilir_trade_[user]: stores a one-use action key to prevent the same virtual trade from being recorded twice accidentally. HttpOnly, SameSite=Strict, Secure in production; maximum 10 minutes.
Blocking essential cookies may prevent login, Google authentication, and virtual-trade safety functions from working correctly.
Preferences stored in your browser
Enbilir keeps some data in browser storage without sending it to the server or while synchronizing it with your account. These records are not cookies, but we describe them here for transparency and user control.
- Risk-appetite answers, current question, and result state are kept in localStorage so you can resume the test.
- User-guide, guided-help, and education-step viewed/completed status may be kept in localStorage or sessionStorage.
- AI market terminal favorites, sound-alert preference, and short-term repeat-alert suppression records are kept in localStorage; favorites may also synchronize with your account.
- Random session keys may be kept in sessionStorage to avoid measuring the same registration or onboarding visit more than once in one session.
Retention periods
Timed cookies are removed by the browser at the maximum period stated above and may be deleted earlier, such as on logout. sessionStorage usually ends when the tab or browser session closes.
localStorage may not have a fixed automatic expiry. It is removed through a feature's reset option, your browser's clear-site-data control, or when an app update invalidates it. Data synchronized to your account is also governed by the Privacy Notice's retention rules.
Third-party services and content
If you choose Google sign-in, a payment redirect, or externally hosted video/content, your browser may visit or load the provider's domain. Those providers may apply their own cookie and privacy rules.
Where non-essential third-party content uses identifiers, the required preference mechanism is applied before loading where practicable. Review the provider's policy when following an external link.
Analytics and marketing technologies
Enbilir currently does not build third-party advertising or behavioral-marketing profiles through cookies. First-party systems may measure feature use, performance, and onboarding with an account or random session key to improve the service.
If non-essential analytics, personalization, or marketing cookies are added, this policy and the preference panel will be updated. Consent-based technologies will be off by default, and rejecting will be as accessible as accepting.
Managing cookies and storage
Use your browser's privacy or site-data settings to view, delete, or block cookies. localStorage and sessionStorage are usually removed with the browser's clear-site-data control.
Clearing all site data signs you out and may remove risk-test progress, favorites, sound, and help preferences. Browser deletion does not remove server-side account records; use account controls or the KVKK application channel for those records.
Updates and contact
This policy is updated when cookie names, purposes, or periods change, with prominent changes announced through an appropriate interface. A new consent purpose is not activated under an old preference.
Contact the Company at info@ultraakil.com about cookies and data-protection preferences.