Google Analytics and cookie preferences
The Google Analytics 4 tag (Google; G-13R1XE9ZTL) loads by default when a web page opens. Before an analytics cookie choice, or when declined, analytics_storage=denied permits cookieless measurement signals; this does not mean that no data is sent to Google. Google may process page URLs/titles, referrers, device/browser information and the connection IP address. The connection may involve processing abroad. Account identifiers, portfolio amounts and calculator inputs are not sent as custom analytics parameters. Advertising storage, advertising user data, ad personalization and Google Signals are disabled.
Cookie Preferences shows necessary cookies as always active. The analytics cookie switch in Settings and Accept All allow _ga and _ga_* cookies for at most 180 days; Reject or switching off clears accessible GA cookies while cookieless measurement continues. GPC/DNT disables measurement; the tag file may still load. metrilume:analytics-consent:v1 stores only the choice and timestamp; the choice is requested again after 180 days. If saving fails, analytics cookies stay off in this tab. Earlier accept/decline records are preserved as cookie choices. Cookie Preferences in the footer reopens the panel. Previously received Google data is not retroactively erased; report retention is managed in Google property settings. Native applications and standalone Lume Embed iframes do not load this web tag. External chart providers’ storage controls are subject to their policies and browser settings.
1. What are cookies and similar technologies?
A cookie is a small piece of text that a website stores in your browser. Local storage, a secure mobile vault, and application storage can perform similar remembering functions but are not browser cookies. This policy describes each separately.
A first-party cookie is set directly by metrilume.com; a third-party cookie is set by another domain or network provider that is called. A “necessary” technology is required to deliver a service expressly requested by the user or to maintain security.
2. Web cookie inventory
| Name / family | Provider | Purpose | Duration | Status |
|---|---|---|---|---|
| metrilume_locale | MetriLume (first party) | Remember the Turkish or English language preference | Up to 12 months | Necessary function; readable by browser script, Secure and SameSite=Lax in production |
| __Host-ml_auth_challenge | MetriLume (first party) | Keep a Google/Apple/phone sign-in step short-lived, bound, and resistant to replay | Up to 5 minutes | Only if authentication is enabled; HttpOnly, Secure, SameSite=Lax |
| __Host-ml_session | MetriLume (first party) | Maintain an authenticated account session and support secure rotation/revocation | In production, an absolute maximum of 30 days and 12-hour inactivity limit | Only if accounts are enabled; HttpOnly, Secure, SameSite=Lax |
| __Host-ml_csrf | MetriLume (first party) | Bind authenticated requests against cross-site request forgery | The same maximum as the linked session | Only if accounts are enabled; HttpOnly, Secure, SameSite=Lax |
| Cloudflare necessary security cookies (conditional; e.g., cf_clearance or __cf_bm) | Cloudflare | Detect bots/abuse, remember a security verification, and protect traffic | Short-lived depending on the cookie and risk event; determined by the provider | At the third-party network layer only when a security feature is triggered |
| TradingView hosted-chart and stock-screener technologies (provider cookies, local storage, and analytics identifiers may vary) | TradingView | Display the delayed chart for the selected US symbol or BIST end-of-day prices and daily percentage changes from the provider domain, provide widget security, and support the provider’s own measurement | Determined by the provider under its Cookie Policy | Activated automatically when the web or mobile US Markets Charts module or BIST equities page opens. Provider storage can be managed in browser or application settings |
3. Mobile and on-device storage
My watchlist and saved research views are held only on this device under metrilume:research-workspace:device:v1, using localStorage on the web and AsyncStorage in the mobile application. The store contains market type, fund code or US ticker, instrument name and time added, together with view identifiers, the view name you provide, supported research selections such as filters/search query, sorting and period, saved timestamps and the store version. Technical limits are up to 200 instrument references, 20 saved views and 256 KiB in total. Instrument references are not price histories or portfolio balances. These records have no MetriLume account or server synchronization, server backup or support recovery. Opening a saved view passes its supported filters and search query into the relevant page’s URL/query parameters and to the MetriLume API to retrieve results; on the web, the URL query string may reach the browser, network/edge layer and server. The view name you provide is not added to these queries and stays on the device. Records remain until you remove the relevant instrument/view in the product or clear browser site data or application storage. Losing or changing a device, changing browsers, uninstalling or reinstalling the application may cause record loss. Deleting an account does not automatically clear these local records.
| Key / storage | Content and purpose | Control |
|---|---|---|
| metrilume.mobile.locale / AsyncStorage | The application’s Turkish or English preference | Until application data is cleared or the preference changes |
| On-device portfolio / AsyncStorage or browser localStorage | Fund transactions, quantity, and cost, to display the portfolio only on the device | Delete within the portfolio, or clear application/browser data |
| Saved comparisons / browser localStorage | Fund codes, period, and save time for up to five comparisons | Delete comparison records or clear browser data |
| metrilume:lume-scenario:device:v1 / browser localStorage | Saved Lume Scenario name, initial and recurring amounts, rates, duration, and calculation/methodology, to reopen the scenario only on this device | Up to 12 scenarios on this device; until you delete the scenario or clear metrilume.com site data. Delete it through the in-product control or by clearing browser localStorage/site data. There is no server sync or support recovery |
| metrilume:lume-journal:device:v1 / browser localStorage | Lume Journal title, thesis/decision, expectation/assumption, and risk/signal; planned review time; review notes, outcome, and time; open/reviewed/archived status; record identifiers and created, decided, updated, and store-saved timestamps; schema fields for tags and portfolio/scenario references for which the current interface provides no input control, to display the journal only on this device | Up to 250 decision entries on this device; until you delete the record or clear metrilume.com site data. Delete it through the in-product control or by clearing browser localStorage/site data. There is no server sync or support recovery |
| metrilume:lume-learn:progress:v1 / browser localStorage | Lume Learn lesson identifier, progress/completion status, score, and timestamps, to remember learning progress only on this device | Until you reset progress or clear metrilume.com site data; delete it through the in-product reset control or by clearing browser localStorage/site data. There is no server sync or support recovery |
| Mobile installation identifier / SecureStore | A random UUID generated by the application on the device, used to bind the secure session vault to the installation | There is no separate in-app reset control. Uninstallation or operating-system clearing varies by platform; an iOS Keychain entry may persist after reinstallation. It is not by itself an account or advertising identifier |
| Session vault / SecureStore | Access/refresh session information and device-lock preference only if accounts are enabled | Signing out or deleting the account clears the session family; the mobile installation identifier may remain separately. Biometric templates do not reach MetriLume |
localStorage is not a cookie. Unsaved inputs in general calculators and initial-public-offering and dividend tools are not written to persistent device storage; Lume Scenario inputs are written to the key above only when you select “Save.” Fund codes in the on-device portfolio may be sent to the server for a current-price query; quantity and cost remain on the device in the default flow. Lume Embed creates no cookie or device storage: loading the iframe is an ordinary technical request, and IP/protocol headers, the referring origin if sent by the browser, and visible title/locale/appearance configuration in the URL may reach the network/edge layer. Financial inputs in the widget remain only in iframe memory and are not sent to MetriLume, the website publishing the Embed, or analytics. The URL title and other visible configuration must not contain personal, special-category, or confidential information.
4. Legal basis
Language, session, and security technologies are used only to the extent necessary to provide a service expressly requested by the user, carry out communications, and maintain security, relying on contractual performance/legitimate interests under the KVKK and, where applicable, GDPR Art. 6(1)(b) or 6(1)(f). Non-essential cookies operate only after prior, freely given, specific opt-in consent.
Continuing to use the website does not by itself constitute consent. For optional analytics, “accept,” “reject,” and granular preference choices will be equally accessible; necessary cookies will continue to load while optional cookies remain off by default.
5. Preference and deletion controls
- You may change your preference with the language switcher and delete metrilume.com cookies through browser settings.
- If the browser blocks all cookies, language recall, sessions, or security verification may not work.
- You may delete or reset Lume Scenario, Lume Journal, and Lume Learn records in the product or clear metrilume.com localStorage/site data through browser settings. Deleting an account does not automatically clear these browser records; support cannot restore them after a device/browser change, reinstallation, or clearing.
- On mobile, you may clear application data through operating-system settings or uninstall the application; the on-device portfolio may not be recoverable. SecureStore/Keychain persistence after uninstallation varies by platform, and the application has no separate installation-identifier reset control.
- When a Global Privacy Control or Do Not Track signal is detected, limited first-party product telemetry is not sent.
- Opening the US Markets Charts module or BIST equities page starts the TradingView connection automatically. You can clear or block provider cookies or storage in browser or application settings; these settings may affect chart or stock-screener functionality.
- You may disable optional analytics cookies through Cookie Preferences at the bottom of the page; cookieless measurement continues. Earlier processing is not retroactively affected.
6. Third parties and international transfers
Cloudflare may process direct-page and Lume Embed technical request data over global infrastructure for security and networking functions; a conditional necessary Cloudflare cookie listed in the inventory may be set if a risk-based security feature is triggered. Lume Embed itself uses no storage or cookies and does not add financial widget inputs to a network request. Opening the US Markets Charts module or BIST equities page automatically connects the browser or mobile in-app WebView directly to TradingView domains and the provider applies its own cookie, privacy, and use policies.
The duration and technical name of a third-party cookie may vary based on the provider’s security risk assessment. The policy is updated when a material inventory change is identified; no advertising or analytics category is enabled silently.
7. Audit, updates, and contact
Before publication and material releases, the client, response headers, and third-party requests are scanned. A new cookie reaches production only after its owner, purpose, duration, category, legal basis, and deletion control are recorded.
For questions about cookies or device storage, contact [email protected].
Contact and data controller
- AxelVira Teknoloji A.Ş.
- İzmir Trade Registry 271455
- Address
- Adalet Mah. Manas Blv. No:47/B Folkart Plaza D:3509, Bayraklı/İzmir, Türkiye
- Tax identification number
- 0991410303
- MERSİS
- 0099141030300001
- Support
- [email protected] · +90 (850) 840 20 83
- Privacy and data requests
- [email protected] · [email protected]