Cookie and Local Storage Policy
Last updated: August 3, 2026
1. Controller and scope
The controller is Roberto Diaz, Spanish Tax ID 71655922C, a self-employed professional at Calle Vázquez de Mella 75, 33012 Oviedo, Asturias, Spain. Contact: [email protected].
This policy covers browser cookies and equivalent technologies used by Verxion’s public site, authenticated web application, and web OAuth flows. It does not describe native-app SDK initialization or iOS storage, which are covered by the Privacy Policy.
2. Necessary or user-requested technologies
These technologies provide a function expressly requested by the user. They are not used for advertising.
| Key or family | Type | Purpose | Approximate duration |
|---|---|---|---|
better-auth.session_token / __Secure-better-auth.session_token and Better Auth auxiliary cookies | First-party HTTP cookie | Authenticate and renew the session and protect access | Up to 7 days, rolling; auxiliary cookies may last for the session |
vx_oauth_ctx_<identifier> | First-party HTTP cookie | Securely bind an OAuth/MCP authorization to sign-in | 10 minutes or until the flow is completed/cancelled |
vx_oauth_ctx | sessionStorage | Temporarily retain the OAuth bridge context and token in the tab | Maximum 10 minutes |
verxion:signin_pending | sessionStorage | Complete navigation after sign-in | Until the first authenticated load or the tab is closed |
verxion:pending_legal_receipt and verxion:pending_legal_receipt_attempt | sessionStorage | After sign-up, finalise the record of accepted Terms and acknowledged Privacy information. The receipt is random, single-use, and removed from the URL before the application loads | The server receipt is valid for 8 minutes. Its raw value remains in the tab session until the flow finishes/fails or the tab closes; sessionStorage has no independent timer |
sidebar_state | First-party cookie | Remember the selected sidebar state | 7 days |
vx-locale | First-party cookie | Remember the selected public-site language | 1 year |
verxion_language | localStorage | Remember the selected app language | Until deleted or changed |
vx_last_auth_provider | localStorage | Show which sign-in provider (Apple or Google) was last used | Until deleted or changed |
verxion.connect.lastAgent | localStorage | Remember the client/agent selected in the MCP connection guide | Until deleted or changed |
verxion:onboarding:celebrated | localStorage | Avoid replaying a completion animation | Until deleted |
verxion.onboarding.draft.v1.<userId> | localStorage | Store an onboarding draft on the device; it may contain fitness goals and health or condition data | Maximum 90 days; removed on completion, sign-out, consent-version expiry, or age expiry |
verxion.onboarding.startedAt.v1.<userId>.<version> | localStorage | Record, on the device, when onboarding began and bind it to the consent version | During the onboarding attempt; removed on completion or restart |
verxion.analytics.consent.v1 | localStorage | Store the versioned choice for the product_analytics purpose and synchronize withdrawal across tabs | Until the choice changes, its version becomes stale, or site data is deleted |
The identifier in the onboarding keys prevents one account’s draft from appearing to another account in the same browser. On shared devices, we recommend signing out; this removes all local onboarding drafts.
3. Optional analytics: PostHog
On the web application, when a current granted choice has been durably stored, PostHog may use a localStorage entry or cookie with a dynamic name similar to ph_<project-token>_posthog, together with auxiliary ph_* storage. Its purpose is to measure product actions in Verxion’s minimised internal event catalogue. The web SDK is neither downloaded nor initialised before that choice. Autocapture, automatic page views, automatic exception capture, and session recording are disabled.
PostHog is non-essential. Its legal basis is prior consent under Article 22.2 LSSI-CE and, where the context may reveal health, explicit consent under GDPR Article 9(2)(a). Rejecting or withdrawing consent does not limit access or product features. The exact lifetime depends on the current PostHog project setting and is reviewed as part of the release gate.
Sentry also receives technical error diagnostics from the browser and server. Verxion configures Sentry without an advertising purpose; if a future configuration stores non-essential identifiers on the device, it will be treated as non-essential.
4. Consent and controls
Non-essential technologies activate only after an affirmative action. Allow analytics and Reject analytics are shown at the same level, with no pre-ticked choice. A missing, corrupt, unreadable, or stale preference means analytics remains off. You can change your choice at any time through the permanent “Analytics preferences” control or the public-site link. Withdrawal converges across tabs, stops new captures, and resets local provider identity; it does not affect the lawfulness of earlier processing.
You can also delete or block storage through browser settings. Blocking necessary technologies may prevent sign-in, OAuth/MCP authorization, requested preferences, or recovery of an incomplete onboarding.
5. Third parties and external domains
When choosing Apple or Google for sign-in, or authorizing an MCP client, you may be redirected to that third party’s domain. Its cookies are governed by its own policy. Server-to-server transfers to Resend, OpenFoodFacts, BYOK AI providers, or other services described in the Privacy Policy do not themselves set cookies on the Verxion domain.
6. Changes and contact
We will update this policy when a technology, purpose, provider, or retention period changes. For questions or rights requests: [email protected].