For the complete documentation index, see llms.txt. This page is also available as Markdown.

List of Cookies and Similar Technologies

This List supplements the Cookies Policy and describes the cookies and similar technologies confirmed as currently used in the website eu.backpack.exchange and support flows. It distinguishes the lifetime of a cookie from the shorter lifetime of any token stored inside it.

The website eu.backpack.exchange does not currently deploy Google Analytics, advertising or targeting cookies.

1. Strictly necessary cookies and security technologies

These technologies are used only to operate, secure or provide a service requested by the user. They are not used for advertising or audience measurement.

Provider
Name / technology
Storage and scope
Purpose and trigger
Retention

Backpack EU

accessKey

HttpOnly, Secure cookie, host-only on api.eu.backpack.exchange

Maintains the authenticated user session. The access token contained in the cookie is valid for 10 minutes and is automatically refreshed.

Session cookie, deleted when the browser is closed. Token lifetime: 10 minutes.

Backpack EU

refreshKey

HttpOnly, Secure cookie, host-only on api.eu.backpack.exchange

Renews the authenticated web session without requiring the user to log in again.

2 days on the web.

Amazon Web Services / Backpack EU

aws-waf-token

Cookie scoped to .backpack.exchange

Supports bot detection and protects the signup and password-reset pages from automated abuse. The login page does not load the WAF SDK.

4 days.

Backpack EU / GitBook

gitbook-visitor-token

Cookie scoped to .backpack.exchange; issued by the Backpack EU API

Enables the support site to recognise a support session opened through the mobile application. It is not set during an ordinary visit to eu.backpack.exchange and is currently triggered only by the mobile app’s “open support” flow.

2 hours.

Cloudflare

__cf_bm

Third-party cookie set only on protected *.workers.madlads.com origins

Distinguishes legitimate traffic from automated traffic and supports bot management when a relevant protected origin is invoked.

Expires after 30 minutes of continuous inactivity.

Backpack EU

Login browser-security check

Browser/device information processed in memory and transmitted in a request header, no fingerprint identifier is stored in cookies, local storage or session storage

Supports fraud prevention and account security during login. It is not used for analytics, advertising or persistent cross-session tracking.

Not retained on the device; used for the login request only. Any server-side retention is governed by the Data Privacy Policy and security retention rules.

2. User-requested settings and application state

These local-storage entries provide settings or application functions selected or used by the user. They are not used for analytics, advertising or cross-site tracking.

Provider
Name / technology
Storage and scope
Purpose and trigger
Retention

Backpack EU

UI preference entries

Local storage, exact entry names may vary by application version

Remembers settings actively selected by the user, including theme, language and chart layouts. Not used for analytics or advertising.

Until replaced or deleted by the Website or the user through browser settings.

Backpack EU

Encrypted application-state entries

Encrypted local-storage entries, may include the active subaccount identifier

Maintains the application interface and account context selected by the user. Not used for advertising or cross-site tracking.

Until replaced or deleted by the Website or the user through browser settings.

3. Analytics, advertising and targeting technologies

None currently deployed on the website eu.backpack.exchange. If such technologies are introduced, this List and the Cookies Policy will be updated and the relevant technologies will be blocked until any consent required by applicable law has been obtained.

4. Managing technologies

Users can delete cookies and browser storage through their browser or device settings. Deleting authentication or security technologies may log the user out or interrupt a protected flow. Deleting local-storage entries may reset user preferences, chart layouts or the selected application context.

Last update: August 2026

Last updated