Cookie Policy
Document version: 2026-08-14-analytics-v5
What are cookies?
Cookies are small files a website stores in your browser. Among other things, they allow the website to preserve your session between requests.
Storage we use
Trakiafit uses strictly necessary first-party storage. Firebase Analytics, available only on Android/iOS, is enabled only with your consent. Google Ads conversion on the production web, Google Ads/Firebase measurement on Android and Apple Ads/AdServices on iOS require separate permission. We do not use remarketing, advertising personalisation or IDFA on iOS.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| session | First party · Necessary | Keeps the session secure; contains the CSRF token and session ID in a signed cookie. If you ask to continue a Premium purchase, it may temporarily retain the period and allowlisted source/feature required to preserve that journey across sign-in, registration and checkout. | 14 days or until sign-out; Premium context is deleted earlier when consumed by the flow |
| cookies_ok | First party · Preference | Remembers that you closed the notice (localStorage). | Indefinite |
| analytics_cookies_ok | First party · Preference | Stores the optional analytics choice. If signed in, the choice is also reflected in the account to allow or block verified app trial and purchase measurement. | Until withdrawal, browser/app data deletion or account deletion |
| _tf_measurement_consent_owner | First party · Preference | Links the local measurement preference to the current account or anonymous browsing so another account on the same device cannot inherit it. The current account preference prevails across devices. | Until account or choice changes, or browser/app data deletion |
| _tf_firebase_reset_pending | First party · Necessary · localStorage | Identifier-free marker ensuring that the SDK completes the requested local data reset after consent withdrawal or an account change, even across navigation. It is removed automatically after a successful reset. | Only until the next successful local reset completes |
| tk_onboarding_draft_v1:* | First party · Necessary · sessionStorage | Restores the onboarding step and entered data in the same tab; it is isolated per account and not sent to third parties. | Tab session; removed earlier on completion or sign-out |
| advertising_measurement_ok | First party · Preference | Stores permission for campaign measurement on the web or app; it does not enable personalised advertising. | Until withdrawal or browser/app data deletion |
| x-tz | First party · Necessary | IANA time zone used to calculate your day correctly. | 1 year |
| x-local-date | First party · Necessary | Local date used as the reference for “today”. | Session |
| Google tag / _gcl_* | Third party · Optional measurement · Production web | Attributes completed registration to a Google Ads campaign. It may use click and conversion identifiers; Trakiafit does not send email, name or nutrition data. | _gcl_* cookies: up to 90 days |
| Firebase app instance | Third party · Optional analytics · App | Measures installation, sessions and conversions. Trakiafit does not send email, name, photos, meals, calories, weight or measurements. GA4 automatically processes the app-instance ID, session statistics, approximate location derived from the connection IP (country/region) and basic platform or device-category data. Granular collection is disabled globally, so city, user-agent string, device brand/model/name, minor versions and screen resolution are not collected. On Android, advertising signals are used only with “Analytics and campaigns”; personalisation remains denied. On iOS it does not use IDFA. | Up to 14 months; the local identifier is reset on withdrawal |
| TrakiaAttribution capture state | First party · Optional measurement · iOS | With “Analytics and campaigns”, it requests a temporary token from Apple AdServices. The token is not retained; the minimised result may remain in the signed session until linked to the account. | Result: up to 14 days; local UUID: until linking, withdrawal or app removal |
Cloudflare Turnstile protects forms against bots. It does not set persistent tracking cookies; it processes IP and browser characteristics only during verification. See the Privacy Policy.
The first-party Premium journey measurement described in the Privacy Policy records minimised stages on the server and reuses only the necessary session to preserve the context of a requested purchase. It does not set analytics cookies, does not access Firebase/GA4 or Google Ads, and does not share those stages with third parties.
Privacy preferences
Choose your measurement level. You can change it at any time; rejecting does not limit any Trakiafit feature.
Essential: session, security and required preferences. Always active.
Analytics only: optionally measures usage and conversions with Firebase Analytics in the apps.
Analytics and campaigns: measures Google Ads registrations on web, installs and conversions on Android, and Apple Ads attribution on iOS. It does not enable remarketing or personalisation.
Is consent required?
Strictly necessary storage does not require prior consent. Firebase Analytics, Google Ads and Apple AdServices remain disabled until you choose an option. You can change it in the preferences panel. If signed in, the analytics preference is reflected in the account to allow or block verified app trial and purchase measurement. Withdrawal is recorded in the account, stops the relevant collection and signals, resets local Firebase data and removes pending Apple Ads attribution. Campaign measurement depends on analytics and never enables personalisation or remarketing.
How can I delete cookies?
You can delete or block cookies in your browser settings. If you delete the session cookie, you will need to sign in again.
- Google Chrome
- Mozilla Firefox
- Safari
- Microsoft Edge