Cookie policy
Reviewed 1 October 2026. Cookies are small values stored by a browser. Kleven uses them carefully so readers can understand the site’s limited measurement and remember their choice about optional cookies.
1. Essential operation
Some technical storage may be needed for security, delivery, load balancing, or form protection. These functions support the service and are not intended to build a marketing profile. Essential values generally last for a session or a short security period. For example, a short-lived token may be created when you open the contact form, used to confirm that the resulting submission came from that same form rather than an automated script, and discarded shortly after the form is submitted or the browser tab is closed. Load-balancing storage, where used by our hosting provider, helps route a request to the correct server during a single visit and is not retained afterward. These functions operate regardless of the choice made in the cookie banner, because without them the site could not be delivered safely or reliably. We keep the number of essential cookies as small as practical and review them whenever the underlying hosting or security tools change.
- a) Session identifier: expires when the browser tab or session ends.
- b) Form-protection token: expires shortly after submission, typically within the same visit.
- c) Load-balancing marker, where applicable: expires at the end of the session.
2. Cookie choice
The site stores cookieChoice as accept or reject when a reader selects a button in the banner. It is retained until the reader clears browser storage or a new consent mechanism replaces it. This value does not contain a name, email address, or health information. For example, the stored value is simply the word "accept" or "reject" alongside a date, so the banner logic can decide whether to display the prompt again on a later visit. If a reader uses a different browser or device, the choice is not automatically carried over, because the value is stored locally rather than linked to an account. We set this cookie to persist for up to 12 months from the date of the choice, after which the banner will reappear and ask again, consistent with common regional practice for consent refresh. Clearing browser storage at any time resets this value immediately and causes the banner to reappear on the next visit.
3. Analytics
If optional analytics are enabled, they help us understand broad traffic such as page views, device category, and approximate regional patterns. Analytics records are limited and retained for no more than 14 months. We do not use them to infer an individual medical condition. For example, analytics may show that the nutrition section receives more visits on weekday mornings than the stress section, which helps the editorial team decide where to focus future articles, without identifying any specific visitor. Analytics storage typically includes a randomly generated identifier rather than a name or email address, and that identifier is not combined with contact-form submissions. If analytics cookies are enabled, they are generally set to expire after 13 months, consistent with common regional guidance on measurement cookies, and the underlying aggregated records are deleted or anonymised after 14 months as described in the retention summary below. Readers who reject optional cookies will not have an analytics identifier set at all.
4. Preferences
Preference storage can remember choices that make a page easier to use. Such values normally last up to 12 months unless a shorter lifespan is specified. We avoid storing sensitive personal details in preferences. For example, a preference cookie might remember that a reader prefers a larger text size or has already seen an introductory tip for the glossary page, so the tip is not repeated on every visit. These values are set only after the optional cookie category is accepted, in the same way as analytics storage, and are not used to track browsing across unrelated external websites. A preference cookie is generally set to expire after 12 months from when it is created or last updated, after which the related setting simply reverts to the site default. Preferences never include a name, contact detail, or health-related selection.
5. Advertising
Kleven does not use cookies to create a personalised health advertising profile. If a future advertising partner is introduced, it will be disclosed, consent controls will be updated, and the advertising policy will explain the arrangement before optional tracking is used. For example, if a future contextual advertising arrangement were introduced, it would be designed to respond to the general topic of the page being viewed rather than to a reader's inferred personal health history. Any such change would require the cookie banner to present a distinct advertising category, separate from the existing analytics and preference categories, so a reader could accept or reject it independently. We would also update the retention periods listed in this policy and provide at least one clear notice on the homepage before the change takes effect. Until such a change is made, no advertising cookie is set on Kleven.
6. Third parties
Some embedded or linked services may set their own cookies when a reader leaves Kleven or activates content. Their policies govern those values. We keep embedded services limited and prefer links that do not automatically transfer personal information. For example, if an article links to a video hosted on an external platform rather than embedding it directly on the page, the platform's cookies are only set if the reader actively chooses to click through and visit that platform. Where an embed cannot be avoided, we label it clearly so a reader understands they are interacting with a third-party service before any related storage occurs. We periodically review embedded services to confirm they remain necessary and proportionate to the editorial purpose they serve. Readers who prefer not to trigger any third-party storage can choose not to follow outbound links or activate embedded content.
7. Browser controls
You can delete cookies and storage through browser settings, block third-party cookies, or use private browsing. Blocking all storage may affect a preference or security function. The exact steps differ by browser and device. For example, most desktop browsers provide a privacy or site-settings menu where stored cookies can be viewed individually and removed for a specific site such as this one, rather than only in bulk. Mobile browsers typically offer a similar option under their privacy or history settings, sometimes combined with clearing browsing data for a chosen time range. Using a private or incognito window prevents cookies from persisting after the window is closed, which can be useful for a single visit without changing your saved settings for future visits. If blocking all cookies prevents the contact form's protection token from working, a reader may need to allow cookies for this site specifically while keeping broader restrictions elsewhere.
8. Consent withdrawal
To change a choice, clear site storage and reload the page so the banner appears again. You may then accept or reject optional cookies. Withdrawing consent does not make earlier lawful processing retroactive, but it stops future optional storage where technically possible. For example, if you accepted optional cookies in January 2026 and later decide to withdraw that choice in October 2026, clearing storage and reselecting reject in the banner stops any new analytics or preference cookie from being set going forward. Data already collected under the earlier consent, such as aggregated analytics from that period, is handled according to the retention periods described in this policy rather than deleted immediately on withdrawal, unless you separately request deletion through the privacy policy's rights process. We do not penalise a reader for withdrawing consent by restricting access to ordinary articles or the contact form. If withdrawing consent causes an unexpected display issue, please report it through contact.php so we can investigate.
9. Retention summary
Session values expire when the session ends; security values generally expire within 30 days; cookieChoice lasts until deletion; optional analytics records last up to 14 months; preference values last up to 12 months. These periods may be shortened during technical changes. For example, if we migrate to a new hosting or analytics provider, we may reset all optional cookies during the transition, which would cause the banner to reappear for every reader regardless of a previous choice. We do not extend a retention period beyond what is stated here without updating this policy first and noting the change in the revision history. Where a specific cookie's lifespan differs from the general category figures above, such as a temporary cookie used only during a short technical trial, we will describe that difference separately if the trial is extended beyond a few weeks. The figures in this summary reflect our standard configuration as of the review date at the top of this page.
10. Contact
Questions about cookies can be sent through contact.php or to Jl. Thamrin No. 8, Kebon Melati, Tanah Abang, Jakarta Pusat, DKI Jakarta 10230, Indonesia. Include the browser and page involved, but do not send medical records. For example, a useful report might state "Safari on iPhone, cookie banner reappeared on every page despite choosing accept," which gives us enough technical detail to investigate without needing any personal or health information. We may ask a small number of clarifying questions, such as the approximate date and whether private browsing was active, to narrow down the cause. We aim to acknowledge a cookie-related query within 10 working days, consistent with the timelines described elsewhere in our policies. If the question also touches on a broader privacy right, such as deleting a stored message, we will treat it under the privacy policy's rights process in parallel.
11. Updates
This policy was first published on 1 March 2026 and reviewed on 1 October 2026. A future material change will receive a new date and may be accompanied by a notice. The current version is always the version displayed on this page. For example, the March 2026 version introduced the basic distinction between essential and optional storage, while the October 2026 review added the specific retention figures and the detailed browser-control guidance now shown above. We do not maintain an separate, undisclosed cookie configuration for any particular reader group. If we introduce an entirely new cookie category, such as advertising, this page will be updated before that category is activated, not afterward. Readers can always compare the "reviewed" date at the top of this page against the dates listed here to confirm they are reading the current version.
- a) 1 March 2026 — initial cookie categories published.
- b) 1 October 2026 — current review; retention figures and browser guidance expanded.
- c) Next scheduled review — aligned with the privacy policy's annual review cycle.
12. Questions and complaints
We aim to answer privacy and cookie questions within 30 calendar days. If you remain concerned, you may contact a relevant Indonesian authority. We will cooperate with lawful requests and maintain a record of how a concern was handled. For example, if a reader's concern about analytics cookies cannot be resolved through direct contact within our usual 30-day window, we will explain the specific reason for the delay and provide a revised expected date rather than leaving the request unanswered. Escalation to the relevant Indonesian authority follows the same path described in the privacy policy's complaints section, since cookie consent falls within that broader regulatory framework. We keep a simple internal log of cookie-related questions and their resolution so repeated issues can be identified and addressed in a future policy update. This commitment applies equally whether the question comes through the contact form, by phone, or by letter to the Jakarta address.