Skip to content
Back to home

Cookie and Local Storage Policy

Last updated: August 3, 2026

1. Controller and scope

The controller is Roberto Diaz, Spanish Tax ID 71655922C, a self-employed professional at Calle Vázquez de Mella 75, 33012 Oviedo, Asturias, Spain. Contact: [email protected].

This policy covers browser cookies and equivalent technologies used by Verxion’s public site, authenticated web application, and web OAuth flows. It does not describe native-app SDK initialization or iOS storage, which are covered by the Privacy Policy.

2. Necessary or user-requested technologies

These technologies provide a function expressly requested by the user. They are not used for advertising.

Key or familyTypePurposeApproximate duration
better-auth.session_token / __Secure-better-auth.session_token and Better Auth auxiliary cookiesFirst-party HTTP cookieAuthenticate and renew the session and protect accessUp to 7 days, rolling; auxiliary cookies may last for the session
vx_oauth_ctx_<identifier>First-party HTTP cookieSecurely bind an OAuth/MCP authorization to sign-in10 minutes or until the flow is completed/cancelled
vx_oauth_ctxsessionStorageTemporarily retain the OAuth bridge context and token in the tabMaximum 10 minutes
verxion:signin_pendingsessionStorageComplete navigation after sign-inUntil the first authenticated load or the tab is closed
verxion:pending_legal_receipt and verxion:pending_legal_receipt_attemptsessionStorageAfter sign-up, finalise the record of accepted Terms and acknowledged Privacy information. The receipt is random, single-use, and removed from the URL before the application loadsThe server receipt is valid for 8 minutes. Its raw value remains in the tab session until the flow finishes/fails or the tab closes; sessionStorage has no independent timer
sidebar_stateFirst-party cookieRemember the selected sidebar state7 days
vx-localeFirst-party cookieRemember the selected public-site language1 year
verxion_languagelocalStorageRemember the selected app languageUntil deleted or changed
vx_last_auth_providerlocalStorageShow which sign-in provider (Apple or Google) was last usedUntil deleted or changed
verxion.connect.lastAgentlocalStorageRemember the client/agent selected in the MCP connection guideUntil deleted or changed
verxion:onboarding:celebratedlocalStorageAvoid replaying a completion animationUntil deleted
verxion.onboarding.draft.v1.<userId>localStorageStore an onboarding draft on the device; it may contain fitness goals and health or condition dataMaximum 90 days; removed on completion, sign-out, consent-version expiry, or age expiry
verxion.onboarding.startedAt.v1.<userId>.<version>localStorageRecord, on the device, when onboarding began and bind it to the consent versionDuring the onboarding attempt; removed on completion or restart
verxion.analytics.consent.v1localStorageStore the versioned choice for the product_analytics purpose and synchronize withdrawal across tabsUntil the choice changes, its version becomes stale, or site data is deleted

The identifier in the onboarding keys prevents one account’s draft from appearing to another account in the same browser. On shared devices, we recommend signing out; this removes all local onboarding drafts.

3. Optional analytics: PostHog

On the web application, when a current granted choice has been durably stored, PostHog may use a localStorage entry or cookie with a dynamic name similar to ph_<project-token>_posthog, together with auxiliary ph_* storage. Its purpose is to measure product actions in Verxion’s minimised internal event catalogue. The web SDK is neither downloaded nor initialised before that choice. Autocapture, automatic page views, automatic exception capture, and session recording are disabled.

PostHog is non-essential. Its legal basis is prior consent under Article 22.2 LSSI-CE and, where the context may reveal health, explicit consent under GDPR Article 9(2)(a). Rejecting or withdrawing consent does not limit access or product features. The exact lifetime depends on the current PostHog project setting and is reviewed as part of the release gate.

Sentry also receives technical error diagnostics from the browser and server. Verxion configures Sentry without an advertising purpose; if a future configuration stores non-essential identifiers on the device, it will be treated as non-essential.

Non-essential technologies activate only after an affirmative action. Allow analytics and Reject analytics are shown at the same level, with no pre-ticked choice. A missing, corrupt, unreadable, or stale preference means analytics remains off. You can change your choice at any time through the permanent “Analytics preferences” control or the public-site link. Withdrawal converges across tabs, stops new captures, and resets local provider identity; it does not affect the lawfulness of earlier processing.

You can also delete or block storage through browser settings. Blocking necessary technologies may prevent sign-in, OAuth/MCP authorization, requested preferences, or recovery of an incomplete onboarding.

5. Third parties and external domains

When choosing Apple or Google for sign-in, or authorizing an MCP client, you may be redirected to that third party’s domain. Its cookies are governed by its own policy. Server-to-server transfers to Resend, OpenFoodFacts, BYOK AI providers, or other services described in the Privacy Policy do not themselves set cookies on the Verxion domain.

6. Changes and contact

We will update this policy when a technology, purpose, provider, or retention period changes. For questions or rights requests: [email protected].