Last updated: August 13, 2026
Introduction
This Cookie Policy explains which cookies and similar data storage technologies Doktor Plus uses, what purpose each of them serves, how long it remains on your device, and how you can change or withdraw your choice at any time.
This document forms an integral part of the Doktor Plus Privacy Policy. The terms used here have the meaning set out in the Privacy Policy, and everything this policy does not govern — your rights, retention periods, data recipients and transfers to third countries — is governed by the Privacy Policy.
The policy applies to both of our websites: doktor-plus.com (the informational site) and app.doktor-plus.com (the application for patients and doctors). It does not apply to the Android and iOS mobile applications, nor to the third-party sites we link to — those have their own rules.
A cookie is a small text file that a website stores in your browser and that is returned to the server with every subsequent request. Local storage (localStorage) and session storage (sessionStorage) are related technologies: the data stays in the browser itself and is not sent to the server automatically. The contents of session storage are deleted when you close the browser tab, while local storage has no expiry and remains until you or we delete it. In this document we refer to all three technologies together as cookies.
We set necessary cookies without consent, because without them the requested service cannot function. We set functional cookies when you yourself request the feature they serve, for example when you choose a language or a text size. We set analytical cookies solely with your prior consent.
Read the Privacy PolicyCookie categories
We classify cookies into three categories. The category of each individual entry is stated in the tables that follow.
Necessary
NecessaryThey enable the basic functioning of the site and the application — logging in and maintaining the session, protecting forms against misuse, keeping the data you have entered into a form you have started until you submit it, and rendering pages correctly. They cannot be switched off, they do not identify you, and they are not used to observe your behaviour.
They do not require consent and cannot be disabled.
Functional
FunctionalThey remember a choice you made yourself, or state belonging to something you started, so that you do not have to repeat it — the display language, the text size, the appearance of the navigation, an invitation you arrived with. They are not used for tracking and do not collect data about your behaviour.
They are created only once you use the feature they serve; you can remove them by clearing the site data in your browser.
Analytical
AnalyticalThey give us pseudonymous statistics on the use of the informational site and the application — how many visitors there are, which pages they read, how far they scroll, which buttons they click and where in the application they give up — so that we know what needs fixing. In the application they are linked to your user identifier once you are logged in, but they do not reveal your name or e-mail address, contain no data about your health, and are not used for advertising.
They are set only with your prior consent. If you withdraw it, we stop loading the analytical tools; records they have already written stay in your browser until they expire or until you clear the site data yourself.
We currently use no marketing cookies
We currently set no marketing or advertising cookies — neither on the informational site nor in the application. There are no advertising pixels on our sites (Meta, Google Ads, LinkedIn or similar), we do not build profiles for marketing purposes, and we do not share or sell data from cookies to advertisers or advertising intermediaries. Should that ever change, we will update this policy and ask for your consent before setting any such cookie.
We do not record user sessions and we do not build click maps. Analytics record a predefined set of events, listed in the notes below both tables. Some of those events are sent automatically as you move through a page — for example which sections scroll into view — rather than only when you click something.
Storage on doktor-plus.com
The table lists everything the informational site doktor-plus.com stores on your device. Our server does not set a single cookie — all the entries listed are created in your browser.
| Name | Storage type | Set by | Purpose | Duration | Category |
|---|---|---|---|---|---|
| _ga | Cookie | Google Analytics 4 (Google Ireland Limited) | Stores a pseudonymous browser identifier by which Google Analytics distinguishes one visitor from another and links their visits, so that we can measure the number of visitors and the most read pages. | 2 years, counted from the last visit | Analytical |
| _ga_014R576X0K | Cookie | Google Analytics 4 (Google Ireland Limited) | Records the session state for our measurement property — the session number and identifier, and the time of the last activity — on the basis of which a visit begins and ends. | 2 years, counted from the last visit | Analytical |
| mp_[token]_mixpanel | Local storage | Mixpanel (servers in the European Union) | The main Mixpanel record: a pseudonymous device identifier, common event properties, and information about the page or campaign you first and last arrived from. It serves to attribute analytical events to the same returning visitor. | Until the site data is cleared in the browser | Analytical |
| __mpq_[token]_ev, __mpq_[token]_pp, __mpq_[token]_gr | Local storage | Mixpanel | Queues for analytical events that have not yet been delivered to Mixpanel — for example if you close the page or your connection drops. The contents are sent on your next visit, and the record is deleted at that point. | Until successful delivery or until the site data is cleared | Analytical |
| Mixpanel transient technical keys (__mpq_[token]_ev:X, __mplss_…) | Local storage | Mixpanel | Short-lived auxiliary records that coordinate simultaneous writing from several browser tabs and check whether local storage is available at all. They contain only a random number and no data about you. | Normally milliseconds — they are removed immediately after writing, though one may briefly survive if the browser is interrupted mid-write | Analytical |
| NEXT_LOCALE | Cookie | Doktor Plus (doktor-plus.com) | Remembers the language you selected in the language switcher (Bosnian, Croatian, Serbian, English or German), so that the site is in that language on your next visit. | 1 year from the language selection | Functional |
| doktor-plus-locale | Local storage | Doktor Plus (doktor-plus.com) | The same language setting, stored in local storage as well. It is read when the page loads, before the cookie, so that the page is in the correct language from the very first render. It contains only the language code. | Until the site data is cleared in the browser | Functional |
| dp:vt-from | Session storage | Doktor Plus (doktor-plus.com) | Records which of two pages you came from, so that the transition animation to the next page runs in the correct direction. Purely visual; it contains no identifier and no data about your behaviour. | Deleted on the next page load, and at the latest when you close the tab | Necessary |
| dp_consent | Cookie | Doktor Plus (doktor-plus.com) | Stores your answer to the cookie notice, so that we do not ask again on every visit. It is shared with app.doktor-plus.com so that the same choice applies in the application. It contains only the categories you allowed and the date of your answer — no identifier. | 1 year from your answer, after which we ask again | Necessary |
- The analytical entries in the table are created only after you have given consent. If you do not give consent, or later withdraw it, Google Analytics and Mixpanel are not loaded at all and the records listed are not created.
- In the names of the Mixpanel records, the marker [token] is replaced by the public identifier of our Mixpanel project, so the actual name in your browser differs from the one listed here in that part.
- Analytical events awaiting delivery remain temporarily in your browser's local storage and may contain the path of the page you visited, the address you arrived from, and data about your browser and device. They are deleted as soon as they have been sent successfully, and you can also remove them by clearing the site data.
- Mixpanel processes data on servers in the European Union. Session recording and automatic capture of all interactions are disabled. The events recorded are: page views, scroll depth, sections scrolled into view, clicks on calls to action, clicks on the app-store and login links, expansion of frequently asked questions, contact clicks and language changes.
- Google Analytics is configured solely to measure traffic and is not used together with Google's advertising features, so no advertising cookies are set through it. If that configuration ever changes, we will update this policy and the table above before the change takes effect.
Storage on app.doktor-plus.com
The application for patients and doctors uses product analytics (Mixpanel), which is loaded only after you give your consent. There are no advertising tools in the application. Everything else listed exists so that logging in, language selection, accessibility and the forms you have started work as they should.
| Name | Storage type | Set by | Purpose | Duration | Category |
|---|---|---|---|---|---|
| mp_[token]_mixpanel | Local storage | Mixpanel (servers in the European Union) | The main Mixpanel record: a pseudonymous device identifier and the shared event properties — session marker, platform, application version, interface language and your role (patient or doctor). Once you are logged in, your user identifier is kept alongside it. The address of the page you are on is deliberately not recorded. | Until the site data is cleared in the browser; when you withdraw consent we delete the device identifier and the events waiting to be delivered, and Mixpanel is no longer loaded from the next page load onwards | Analytical |
| __mpq_[token]_ev, __mpq_[token]_pp, __mpq_[token]_gr | Local storage | Mixpanel | Queues for analytical events that have not yet been delivered to Mixpanel — for example if you close the tab or your connection drops. The contents are sent the next time you open the application, and the record is deleted then. | Until successful delivery or until the site data is cleared | Analytical |
| Temporary Mixpanel technical keys (__mpq_[token]_ev:X, __mplss_…) | Local storage | Mixpanel | Short-lived helper records that coordinate simultaneous writes from several browser tabs and check whether local storage is available at all. They contain only a random number and no data about you. | Usually milliseconds — they are removed immediately after the write, although one may remain briefly if the browser was interrupted mid-write | Analytical |
| dp_access_token | Cookie | Doktor Plus (api.doktor-plus.com) | A short-lived session token that authenticates each of your requests to our server and protects the pages available only to logged-in users. It is set by our server and is not accessible to scripts in the page (HttpOnly). | Short-lived — it expires at the deadline determined by the server, and is deleted when you log out | Necessary |
| dp_refresh_token | Cookie | Doktor Plus (api.doktor-plus.com) | The token by which an expired session token is silently renewed, so that you are not logged out in the middle of a consultation. It is set by our server and is not accessible to scripts in the page (HttpOnly). | Longer than the session token; it expires at the deadline determined by the server, and is deleted when you log out | Necessary |
| dp_csrf | Cookie | Doktor Plus (api.doktor-plus.com) | Protection against request forgery (CSRF). It is deliberately readable by scripts in the page, because the application has to return its value in the header of every request that changes data. It is set for the doktor-plus.com domain, so it is sent to its subdomains as well. | Set by the server when you log in and deleted when you log out; the exact lifetime is determined by the server | Necessary |
| dp:locale | Local storage | Doktor Plus | Remembers the interface language you selected (Bosnian, Croatian, Serbian, English or German). It contains only the language code. | Until the site data is cleared in the browser | Functional |
| dp:fontScale | Local storage | Doktor Plus | Remembers the text size you selected in the accessibility settings, so that the application is in that size from the very first render. | Until the site data is cleared in the browser | Functional |
| dp.sidebar.collapsed | Local storage | Doktor Plus | Remembers whether you left the side navigation collapsed or expanded. Interface appearance only. | Until the site data is cleared in the browser | Functional |
| dp.push.token | Local storage | Doktor Plus (value assigned by Google Firebase Cloud Messaging) | Records the identifier by which this browser receives notifications about consultations, so that when you log out we can unsubscribe exactly this device and prevent notifications from continuing to reach the previous user on a shared computer. | Until you log out or the site data is cleared; it is created only after you allow notifications in the browser | Functional |
| dp.referral.pending | Local storage | Doktor Plus | Keeps the referral code you arrived with, for example by scanning a QR code from a leaflet, so that we can credit you with the benefit you earned once your registration is complete. The code is an opaque value to us, which we do not interpret. | 7 days, after which it is deleted automatically; it is also deleted as soon as the benefit has been used | Functional |
| dp.register.draft | Session storage | Doktor Plus | A draft of the multi-step registration, so that refreshing the page does not erase what you have already entered. It contains the first name, last name, e-mail address and telephone number you have typed in, and the referral code if there is one. | Until you close the tab; it is deleted as soon as the registration is submitted | Necessary |
| dp.consents.draft | Session storage | Doktor Plus | Carries over the consents you ticked through the registration steps — consent to marketing messages and to receiving electronic copies of consultation reports — so that they are not lost by refreshing the page before you confirm them. | Until you close the tab; it is deleted once the consents have been recorded | Necessary |
| dp.pendingPhoneVerification | Session storage | Doktor Plus | Temporarily keeps the token from the login link you received by e-mail, in the short period between opening that link and confirming your telephone number. At that moment the session cookies do not yet exist, so this is the only way for us to let you request the code again. | Until you close the tab; it is deleted as soon as the number confirmation succeeds or finally fails | Necessary |
| dp.consultDraft.v2.[doctor id] | Session storage | Doktor Plus | A draft of a consultation you have started, separate for each doctor you contact. It contains the description of your symptoms that you wrote yourself, the type of consultation, the names of the attached files and the selected clinic. The description of symptoms is data about your health — see the note below the table. | Until you close the tab; it is deleted as soon as the consultation has been started successfully | Necessary |
| dp.cardSetupAttempt | Session storage | Doktor Plus | Records that the saving of a payment card is in progress, so that the confirmation can be completed even if the page is refreshed in the meantime or your bank redirects you to its own identity confirmation page. It contains only the identifier of the previously saved card and the start time, never card details. | 120 seconds, and at the latest until you close the tab | Necessary |
| dp_consent | Cookie | Doktor Plus (doktor-plus.com) | The same record of your answer to the cookie notice that is listed in the table for the informational site. It is set for the doktor-plus.com domain, so it applies here too: if you answered on one address, we do not ask you again on the other, and you can change your answer on either. It contains only the categories you allowed and the date of your answer — no identifier of any kind. | 1 year from your answer, after which we ask again | Necessary |
- The analytical entries in the table are created only after you give your consent. Until you do, Mixpanel is not loaded in the application at all and none of the listed records come into existence. If you withdraw your consent, we delete the device identifier and the events waiting to be delivered, and Mixpanel is no longer started from the next page load onwards.
- In the names of the Mixpanel records, the [token] placeholder is replaced by the public identifier of our Mixpanel project, so the actual name in your browser differs from the one given here in that part.
- Mixpanel processes data on servers in the European Union. Session recording and the automatic capture of all interactions are switched off. In the application we record: the start of a session and screen views, searching and filtering doctors, opening doctor and clinic profiles, adding and removing favourites, the steps and outcome of the form for starting a consultation, the steps of saving a payment card, language changes, logging out, and technical errors in communication with our server.
- Analytics never record who your doctor is, which clinic or specialty you are contacting, the description of your symptoms, the content of messages, or the names of attached files. That is data about your health, and cookie consent is not a valid legal basis for it. For the same reason, identifiers in the recorded page path are replaced by a placeholder — instead of the real address we record, for example, /consultations/[id] — so the analytics do not show which consultation you opened or whose profile you viewed. From a search we record only the length of the query and the number of results, never the query itself.
- Once you are logged in, we send your user identifier alongside the analytical events, together with basic account markers — your role, the interface language, whether your telephone number is confirmed and whether you have a profile picture. Your first name, last name, e-mail address, telephone number and address are not sent to Mixpanel.
- The draft of a consultation you have started contains the description of symptoms you wrote yourself, and is therefore health data. It stays solely in your browser's session storage, available only to our site and only to that tab, and is deleted as soon as you submit the consultation or close the tab. If you share the device with others, we recommend that you submit the consultation you have started or close the tab before handing the device over to someone else.
- The registration draft contains your name, e-mail address and telephone number, and the record for telephone number confirmation contains the login token. Both exist only until you close the tab and are deleted as soon as the step they serve is complete.
- If you allow notifications in the browser, the Firebase Cloud Messaging service (Google) additionally creates its own databases in your browser and registers a service worker, so that notifications about consultations can reach you even when the application is not open. All of that disappears when you disallow notifications or clear the site data.
Third parties that do not store data on your device
Some of the services our pages load do not set cookies, but by the very nature of the web they receive your IP address and basic browser data when their content is fetched. We list them for completeness, and note which of the two addresses each one applies to.
Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
Delivers the icons and part of the typography in the application at app.doktor-plus.com. On the informational site the typography is served from our own servers. It sets no cookies and stores nothing on your device, but it receives your IP address when loading.
Monri Payments (ipg.monri.com)
The form for entering payment card details. It is loaded only at the payment step and only when card payment is enabled. Under the security rules of the card organisations, that form must not be served from our servers. Any cookies Monri may set are governed by the rules of Monri Payments.
Firebase Cloud Messaging (Google, gstatic.com)
Delivers notifications about consultations to the browser. It is loaded only if you explicitly allow notifications.
There is no other third-party content on our sites — no advertising networks, social networks or embedded videos.
Managing your choice
The cookie notice, on which you choose whether to allow analytical cookies, is shown on your first visit — both on the informational site doktor-plus.com and in the application at app.doktor-plus.com. Until you decide, the analytical tools are not loaded and nothing from the analytical category is stored on your device.
Consent is voluntary. If you decline analytical cookies, the site and the application work exactly the same — no content or service is made conditional on consent.
You can change or withdraw your choice at any time: on the informational site through the "Cookie settings" link in the footer, and in the application in your account settings, in the consents section. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out before it. After withdrawal we stop loading the analytical tools, and in the application we also delete the device identifier and the events waiting to be delivered. The remaining records that Google Analytics and Mixpanel have already written we cannot delete for you, because those records are managed by their scripts — the browser settings described below remove them.
Your choice itself is stored on your device as the dp_consent cookie, listed in both tables above under the necessary category, so that we do not have to ask you on every visit. If you clear the site data, that record is deleted as well and we will ask you again.
The same record is read on both addresses, so your answer applies to the whole platform: if you answered on the informational site, we do not ask you again in the application, and vice versa. A change in one place applies immediately in the other.
Browser settings
Regardless of our settings, you can review, block or delete all cookies and stored data in the browser itself. The procedure differs from browser to browser, and is most often found here:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and site permissions → Manage cookies and site data
Deleting or blocking all cookies will also remove the necessary and functional records: logging in to the application will then not be possible, and the selected language, text size and the forms you have started will not be saved.
Our sites do not set analytical cookies before you consent, so we do not process "Do Not Track" and "Global Privacy Control" signals separately.
Changes to this policy
We update this Cookie Policy when we introduce, change or remove a cookie, as well as when changes in regulations require it. We update the tables in this document before the change takes effect.
If we introduce a new purpose for which your consent is required, we will ask for it again — consent given earlier does not carry over to a new purpose. We notify you of material changes by publishing the updated policy and changing the date below.
Date of last version: August 13, 2026
Contact
For questions about cookies, about this policy or about exercising your rights, please contact us:
Privacy inquiries: dpo@doktor-plus.com
General support: support@doktor-plus.com
Postal address: BBlab Duško Bajić S.P., Nikole Pašića 40, 78000 Banja Luka, Bosnia and Herzegovina
Supervisory authority: Personal Data Protection Agency of BiH, Dubrovačka 6, 71000 Sarajevo, azlpinfo@azlp.ba
This Cookie Policy forms an integral part of the Doktor Plus Privacy Policy.