Cookie policy
This policy explains how TriageFit uses cookies and similar technologies when you visit our site or use our app. It sits alongside our Privacy Policy and Terms of Service.
What is a cookie?
A cookie is a small text file stored on your device by the websites you visit. We also use similar technologies such as localStorage, sessionStorage and IndexedDB. Collectively we refer to these as “cookies” in this policy, and the table below lists every one of them that we set.
Categories we use
- Strictly necessary, required for the site to work: authentication, CSRF, your consent record, and the display choices you set yourself (light or dark, collapsed navigation). You cannot opt out of these; disabling them will break sign-in.
- Functional, save your progress through the longer forms and remember who is signed in on this device, so you can pick up where you left off. Opt-in via the cookie banner, and turning it off clears what is already saved here.
- Analytics, help us understand aggregate usage. Privacy-preserving and opt-in.
- Marketing, remembers the referral or affiliate link that brought you here, so whoever recommended TriageFit is credited if you subscribe. First-party only: we set no advertising or retargeting pixels, and we share nothing with ad networks. Opt-in.
Cookies we currently set
| Name | Purpose | Category | Retention | Provider |
|---|---|---|---|---|
| __Secure-authjs.session-token | Keeps you signed in after authentication (named authjs.session-token in development). | strictly necessary | Up to 30 days | TriageFit |
| __Host-authjs.csrf-token | Prevents cross-site request forgery on auth routes. | strictly necessary | Session | TriageFit |
| __Secure-authjs.callback-url | Returns you to the intended page after sign-in. | strictly necessary | Session | TriageFit |
| tf_affiliate_session | Keeps an affiliate partner signed in to the partner portal at /affiliate. It is set only when a partner signs in there, never on a member or visitor page. | strictly necessary | 24 hours | TriageFit |
| tf_provisioning | Marks that you have just come back from the payment page, so the screen that says we are finalising your membership is shown to the person who was actually sent there. It holds nothing but that mark: no name, no payment details, no order number. The mark expires after 15 minutes. | strictly necessary | 15 minutes | TriageFit |
| triage_cookie_consent (and triage_cookie_consent_pending_sync) | Remembers your cookie-banner choices so we don't re-ask. The second is a short-lived queue holding a choice you made while offline, until it reaches us. | strictly necessary | 13 months | TriageFit |
| triage_theme (localStorage) | Remembers the light or dark appearance you chose. It is set only when you change it yourself. It holds nothing but that one choice and is never sent to our servers, so it needs no consent. | strictly necessary | Until you clear it | TriageFit |
| tf_sidebar_collapsed | Remembers whether you collapsed the navigation rail, so a page loads the way you left it instead of visibly re-arranging as it opens. Set only when you click the toggle yourself, and holds nothing but that one choice. | strictly necessary | 1 year | TriageFit |
| Preference and dismissal flags (localStorage / sessionStorage) | Small yes/no records of choices you have already made in the app: which banners you dismissed, which sections you left open, whether you hid the monthly photo reminder. Each holds a flag or a date and none holds health information. | strictly necessary | Until you clear them | TriageFit |
| auth-storage (localStorage) | Holds your name and email so the app can show who is signed in before the server replies. Set only after you accept functional cookies, and removed when you sign out or withdraw that consent. | functional | Until you sign out | TriageFit |
| In-progress drafts and on-device logs (localStorage / sessionStorage) | Anything you are part-way through: your intake answers, a weekly review, a block check-in, the quarterly reset, your hydration log and your notification list. It is held so that a reload, a lost connection or a closed tab does not lose what you wrote, which means it can contain health information. Alongside it we keep a one-way stamp of whose data it is, so it can be purged if this browser changes hands. All of it is cleared when you sign out, and also if you withdraw functional consent. | strictly necessary | Until you submit the form or sign out | TriageFit |
| triage_ai_chat_messages, triage_ai_coaching_context (sessionStorage) | Holds the coach conversation on screen so moving between pages in the same tab does not lose it. It is your conversation, which means it can contain health information you wrote. It never leaves this tab, is gone when you close it, and is also cleared when you sign out or withdraw functional consent. | strictly necessary | Until you close the tab | TriageFit |
| triagefit-offline (IndexedDB) | Holds a progress photo you took while offline until it can upload. It is a photo of you, so it stays on your own device until the upload succeeds and is deleted when you sign out or withdraw functional consent. | strictly necessary | Until the photo uploads or you sign out | TriageFit |
| _ga, _ga_* | Google Analytics: distinguishes visitors to measure aggregate usage. IP-anonymised, and set only after you accept analytics cookies. | analytics | Up to 13 months | |
| tf_aid (localStorage) | A random id with no link to your name or email, used to count returning visits in our own analytics. Set only after you accept analytics cookies, and replaced with a fresh one when you sign out. | analytics | Until you clear it or sign out | TriageFit |
| tf_sid (sessionStorage) | Groups your activity into a single visit for our own analytics. Set only after you accept analytics cookies. | analytics | Until you close the tab | TriageFit |
| tf_ref (localStorage) | Remembers the member referral code you arrived with (?ref=), so the member who recommended us is credited if you subscribe. Set only after you accept marketing cookies. | marketing | Until you clear it or withdraw marketing consent | TriageFit |
| tf_aff (localStorage) | Remembers the affiliate code you arrived with (?aff=), so the partner who referred you is paid their commission if you subscribe. Set only after you accept marketing cookies. | marketing | Until you clear it or withdraw marketing consent | TriageFit |
Managing your choices
You can change or withdraw your consent at any time, and it is as easy to withdraw as it was to give. Use the button below to reopen your cookie choices, or (if you are signed in) visit Settings → Privacy. Most browsers also let you clear or block cookies through their own settings panels; note that doing so may sign you out of TriageFit.
Contact
Questions about this policy? Email info@triagemethod.com.