Cookie Policy
How we use cookies and how you can control them.
v1.3 · Last updated: 24-09-2026
This Cookie Policy explains how the NoteFit website (notefit.app) uses cookies and similar technologies, and how you can control them. The NoteFit mobile app does not use browser cookies — it uses secure on-device storage for authentication tokens and your preferences.
1. What cookies are
Cookies are small text files that a website places on your browser to remember information about your visit. Similar technologies include local storage, session storage, and pixel tags. We refer to all of these collectively as “cookies” in this policy.
2. Strictly necessary cookies (always on)
These are required to deliver the Service you have requested and do not require consent under EU ePrivacy:
sb-access-token/sb-refresh-token(Supabase) — authentication sessionnotefit-locale,notefit-theme— language and theme preferences- Anti-CSRF token — form-submission security
3. Functional cookies (always on, first-party only)
notefit-units— your metric/imperial preferencenotefit-pending-onboarding— persists onboarding progress
One more first-party item belongs here rather than under analytics: nf_session_id, held in session storage and discarded when you close the tab. It groups the events of a single visit so one visit is not counted many times. Because the reliability signal in section 6a is recorded whatever you choose, this identifier exists even if you decline analytics. It is first-party, short-lived, and never shared.
4. Analytics cookies (opt-in)
We do not load analytics cookies until you accept them via the cookie banner. If you do not accept, none are set. When accepted, analytics cookies record aggregated metrics (pages visited, features used, session duration); they do not identify you to advertisers.
- _ga, _ga_* (Google Analytics 4) — aggregated product-usage metrics. Up to 2 years.
- nf_anon_id (first-party) — a random visitor identifier, so that a returning visit is counted once rather than twice. It is written only after you accept, never if you decline, and it is never sent to a third party. 2 years.
Neither is used for advertising, and neither is read by anyone but us.
5. Marketing / advertising
We do not currently use advertising cookies. If that changes, this Policy will be updated and consent will be re-requested.
6. Managing your choice
- When you first visit, a banner offers Accept and Reject as equal choices. Nothing optional loads until you pick one, and neither option is preselected.
- Web app — Account → Analytics. You can turn analytics off or back on at any time.
- Mobile app — Settings → Analytics. The same choice, stored on your device.
- In your browser — most browsers allow you to refuse or delete cookies in their settings; blocking strictly-necessary cookies will break the Service.
- Browser opt-out tools — the EDAA Your Online Choices site at youronlinechoices.eu.
Turning analytics off stops any further optional collection immediately. Data already collected while analytics were on cannot be un-sent, but you can ask us to delete it — see the Privacy Policy.
6a. What we keep regardless of your choice
One reliability signal is not covered by this choice, because we need it to know when a release is broken for people who declined analytics. It relies on our legitimate interests rather than consent, and it is limited to:
- errors shown to you in the app — what failed and where, with emails, identifiers, quoted values and long digit sequences removed before the record leaves your device.
That list covers what is recorded from your device, which is what this Policy is about. Two further records are made on our servers, without storing or reading anything on your device and therefore without cookies: each tool call an AI assistant makes on your behalf, if you connect one; and your daily presence — that your account was active on a given day, on which platform, and how many times it was opened. Neither depends on your analytics choice, both rely on our legitimate interests, and both are described in full in the Privacy Policy, section 7, where you will also find how to object to them.
Failed sign-ins, failed sign-ups and failed saves were listed here until September 2026. Those paths now report through the error signal above, so we withdrew the exemption. Records collected under the older exemption, including any still sent by an app version you have not yet updated, are retained under section 10 of the Privacy Policy and can be erased on request.
It names the screen you were on and the action that failed, because an error with no location in the app is not actionable. It is not product analytics: it is written only when something fails, never as you move around, so it cannot describe how you use the app.
7. Do Not Track / Global Privacy Control
We respect the Global Privacy Control (GPC) signal as a consent withdrawal under US state privacy laws where applicable. We do not currently act on the legacy Do Not Track header.
8. Changes
We may update this Cookie Policy. The “Last updated” date at the top reflects the latest revision. Material changes will trigger a renewed cookie banner.
9. Contact
Operated by SMVMC, LDA. For privacy questions, email admin@notefit.app.