Skip to content
Back to home

Cookie and Local Storage Policy

Last updated: August 3, 2026

1. Controller and scope

The controller is Roberto Diaz, Spanish Tax ID 71655922C, a self-employed professional at Calle Vázquez de Mella 75, 33012 Oviedo, Asturias, Spain. Contact: [email protected].

This policy covers browser cookies and equivalent technologies used by Verxion’s public site, authenticated web application, and web OAuth flows. It does not describe native-app SDK initialization or iOS storage, which are covered by the Privacy Policy.

2. Necessary or user-requested technologies

These technologies provide a function expressly requested by the user. They are not used for advertising.

Key or family Type Purpose Approximate duration
better-auth.session_token / __Secure-better-auth.session_token and Better Auth auxiliary cookies First-party HTTP cookie Authenticate and renew the session and protect access Up to 7 days, rolling; auxiliary cookies may last for the session
vx_oauth_ctx_<identifier> First-party HTTP cookie Securely bind an OAuth/MCP authorization to sign-in 10 minutes or until the flow is completed/cancelled
vx_oauth_ctx sessionStorage Temporarily retain the OAuth bridge context and token in the tab Maximum 10 minutes
verxion:signin_pending sessionStorage Complete navigation after sign-in Until the first authenticated load or the tab is closed
verxion:pending_legal_receipt and verxion:pending_legal_receipt_attempt sessionStorage After sign-up, finalise the record of accepted Terms and acknowledged Privacy information. The receipt is random, single-use, and removed from the URL before the application loads The server receipt is valid for 8 minutes. Its raw value remains in the tab session until the flow finishes/fails or the tab closes; sessionStorage has no independent timer
sidebar_state First-party cookie Remember the selected sidebar state 7 days
vx-locale First-party cookie Remember the selected public-site language 1 year
verxion_language localStorage Remember the selected app language Until deleted or changed
vx_last_auth_provider localStorage Show which sign-in provider (Apple or Google) was last used Until deleted or changed
verxion.connect.lastAgent localStorage Remember the client/agent selected in the MCP connection guide Until deleted or changed
verxion:onboarding:celebrated localStorage Avoid replaying a completion animation Until deleted
verxion.onboarding.draft.v1.<userId> localStorage Store an onboarding draft on the device; it may contain fitness goals and health or condition data Maximum 90 days; removed on completion, sign-out, consent-version expiry, or age expiry
verxion.onboarding.startedAt.v1.<userId>.<version> localStorage Record, on the device, when onboarding began and bind it to the consent version During the onboarding attempt; removed on completion or restart
verxion.analytics.consent.v1 localStorage Store the versioned choice for the product_analytics purpose and synchronize withdrawal across tabs Until the choice changes, its version becomes stale, or site data is deleted

The identifier in the onboarding keys prevents one account’s draft from appearing to another account in the same browser. On shared devices, we recommend signing out; this removes all local onboarding drafts.

3. Optional analytics: PostHog

On the web application, when a current granted choice has been durably stored, PostHog may use a localStorage entry or cookie with a dynamic name similar to ph_<project-token>_posthog, together with auxiliary ph_* storage. Its purpose is to measure product actions in Verxion’s minimised internal event catalogue. The web SDK is neither downloaded nor initialised before that choice. Autocapture, automatic page views, automatic exception capture, and session recording are disabled.

PostHog is non-essential. Its legal basis is prior consent under Article 22.2 LSSI-CE and, where the context may reveal health, explicit consent under GDPR Article 9(2)(a). Rejecting or withdrawing consent does not limit access or product features. The exact lifetime depends on the current PostHog project setting and is reviewed as part of the release gate.

Sentry also receives technical error diagnostics from the browser and server. Verxion configures Sentry without an advertising purpose; if a future configuration stores non-essential identifiers on the device, it will be treated as non-essential.

Non-essential technologies activate only after an affirmative action. Allow analytics and Reject analytics are shown at the same level, with no pre-ticked choice. A missing, corrupt, unreadable, or stale preference means analytics remains off. You can change your choice at any time through the permanent “Analytics preferences” control or the public-site link. Withdrawal converges across tabs, stops new captures, and resets local provider identity; it does not affect the lawfulness of earlier processing.

You can also delete or block storage through browser settings. Blocking necessary technologies may prevent sign-in, OAuth/MCP authorization, requested preferences, or recovery of an incomplete onboarding.

5. Third parties and external domains

When choosing Apple or Google for sign-in, or authorizing an MCP client, you may be redirected to that third party’s domain. Its cookies are governed by its own policy. Server-to-server transfers to Resend, OpenFoodFacts, BYOK AI providers, or other services described in the Privacy Policy do not themselves set cookies on the Verxion domain.

6. Changes and contact

We will update this policy when a technology, purpose, provider, or retention period changes. For questions or rights requests: [email protected].