Cookie and Local Storage Policy
Last updated: August 3, 2026
1. Controller and scope
The controller is Roberto Diaz, Spanish Tax ID 71655922C, a self-employed professional at Calle Vázquez de Mella 75, 33012 Oviedo, Asturias, Spain. Contact: [email protected].
This policy covers cookies and equivalent technologies used by Verxion’s public site, authenticated application, and OAuth flows. It supplements the Privacy Policy.
2. Necessary or user-requested technologies
These technologies provide a function expressly requested by the user. They are not used for advertising.
| Key or family | Type | Purpose | Approximate duration |
|---|---|---|---|
better-auth.session_token / __Secure-better-auth.session_token and Better Auth auxiliary cookies | First-party HTTP cookie | Authenticate and renew the session and protect access | Up to 7 days, rolling; auxiliary cookies may last for the session |
vx_oauth_ctx_<identifier> | First-party HTTP cookie | Securely bind an OAuth/MCP authorization to sign-in | 10 minutes or until the flow is completed/cancelled |
vx_oauth_ctx | sessionStorage | Temporarily retain the OAuth bridge context and token in the tab | Maximum 10 minutes |
verxion:signin_pending | sessionStorage | Complete navigation after sign-in | Until the first authenticated load or the tab is closed |
sidebar_state | First-party cookie | Remember the selected sidebar state | 7 days |
vx-locale | First-party cookie | Remember the selected public-site language | 1 year |
verxion_language | localStorage | Remember the selected app language | Until deleted or changed |
vx_last_auth_provider | localStorage | Show which sign-in provider (Apple or Google) was last used | Until deleted or changed |
verxion.connect.lastAgent | localStorage | Remember the client/agent selected in the MCP connection guide | Until deleted or changed |
verxion:onboarding:celebrated | localStorage | Avoid replaying a completion animation | Until deleted |
verxion.onboarding.draft.v1.<userId> | localStorage | Store an onboarding draft on the device; it may contain fitness goals and health or condition data | Maximum 90 days; removed on completion, sign-out, consent-version expiry, or age expiry |
verxion.onboarding.startedAt.v1.<userId>.<version> | localStorage | Record, on the device, when onboarding began and bind it to the consent version | During the onboarding attempt; removed on completion or restart |
The identifier in the onboarding keys prevents one account’s draft from appearing to another account in the same browser. On shared devices, we recommend signing out; this removes all local onboarding drafts.
3. Optional analytics: PostHog
When configured in the application, PostHog may use a localStorage entry or cookie with a dynamic name similar to ph_<project-token>_posthog, together with auxiliary ph_* storage. Its purpose is to measure product usage, interface errors, and aggregate journeys. Session recording is disabled.
PostHog is non-essential. Its legal basis is prior consent under Article 22.2 LSSI-CE and, where attributes may reveal health, explicit consent under GDPR Article 9(2)(a). Rejecting or withdrawing consent does not limit essential features. The exact lifetime depends on the current PostHog configuration and must never exceed the period shown in the preference panel.
Sentry also receives technical error diagnostics from the browser and server. Verxion configures Sentry without an advertising purpose; if a future configuration stores non-essential identifiers on the device, it will be treated as non-essential.
4. Consent and controls
Non-essential technologies must only be activated after an affirmative action. Accept and reject must be equally easy, with no pre-ticked choices. You can change your choice at any time through the “Cookie preferences” link on the site or in the app. Withdrawal does not affect the lawfulness of earlier processing.
You can also delete or block storage through browser settings. Blocking necessary technologies may prevent sign-in, OAuth/MCP authorization, requested preferences, or recovery of an incomplete onboarding.
5. Third parties and external domains
When choosing Apple or Google for sign-in, or authorizing an MCP client, you may be redirected to that third party’s domain. Its cookies are governed by its own policy. Server-to-server transfers to Resend, OpenFoodFacts, BYOK AI providers, or other services described in the Privacy Policy do not themselves set cookies on the Verxion domain.
6. Changes and contact
We will update this policy when a technology, purpose, provider, or retention period changes. For questions or rights requests: [email protected].