Cookie Policy

Last updated: 19 September 2026

This Cookie Policy (the “Policy”) explains what cookies are, which cookies and similar technologies we place on your device when you visit Adaging, and why. It also covers similar technologies such as local storage and web beacons (pixels).

This Policy does not describe how we handle your personal data in general. For that, see our Privacy Policy. Adaging is operated by Xora Technologies S.L., Betera, Valencia, 46117, Spain, NIF B22975635. Questions: support@adaging.io.

What are cookies

Cookies are small text files that are sent to, or read from, your browser or your device’s memory. A cookie usually contains the name of the domain it came from, a lifetime, and a randomly generated identifier. It may also hold information about your settings or your activity while using Adaging.

Session cookies

Session cookies expire when you close your browser. We use them to keep a single visit working correctly — for example to hold your place in the quiz or during checkout.

Persistent cookies

Persistent cookies are not deleted when you close your browser. We use them so you stay signed in to your account and so your plan and progress are still there when you come back.

First-party cookies and local storage

These are set by Adaging itself. We use them for authentication and to store your quiz answers, selected plan and workout progress. Most of this is kept in your browser’s local storage rather than in classic cookies, but it works the same way from a privacy point of view: it stays on your device until you clear it or sign out.

Third-party cookies

These are set by the service providers we rely on to run payments, security and advertising measurement. We do not control cookies placed by third parties, and their use is governed by their own privacy policies. We do not allow these providers to use data collected on Adaging for their own unrelated purposes; they are bound by contract and by applicable law.

Service providers we actually use

Stripe (payments)

Stripe processes card, Apple Pay and Google Pay payments on our checkout screen. Stripe sets cookies to secure the payment form and to detect fraud. Card details are entered directly into Stripe’s fields and never reach our servers. See stripe.com/privacy.

Meta / Facebook Pixel (advertising measurement)

We run the Meta Pixel and its server-side counterpart (the Conversions API) to measure how our ads perform — for example, how many people who clicked an ad completed the quiz or subscribed. This uses cookies such as _fbp and the click identifier _fbc, plus a pixel (web beacon) that fires on key steps. Ad preferences can be managed at facebook.com/adpreferences/ad_settings.

Contentsquare (session analytics)

Contentsquare records how pages are used: clicks, scrolling, where people stop. All text on the page is masked before anything leaves your browser, so what you type or choose is not readable in these recordings. It sets the cookies _cs_id (recognises your browser across visits, about 13 months), _cs_s (the current visit) and _cs_c (Contentsquare's own record of its tracking state, 13 days). See contentsquare.com/privacy-policy.

Mixpanel (product analytics)

Mixpanel counts how the product is used: which screens are opened, which features are used, how far people get. It uses local storage rather than cookies, under keys beginning with mp_ and __mpq_. It receives no health-related answers (Privacy Policy, Section 8.2). See mixpanel.com/legal/privacy-policy.

Our hosting platform

Two cookies are set by the platform that serves the site, not by our code: session-id (the current visit) and __dpl (about one day). They let the platform serve your visit consistently and are essential to delivering pages.

Supabase (accounts and data)

Supabase powers our accounts and database. It stores an authentication token in your browser so you do not have to sign in on every visit. Removing it signs you out.

Cloudflare (security and delivery)

Cloudflare protects the site from bots and abuse and delivers pages quickly. It sets security cookies such as __cf_bm to distinguish real visitors from automated traffic.

We do not use Google Analytics, Zendesk, Microsoft advertising or Snap Pixel on Adaging. If that changes, we will update this Policy.

Similar technologies

Web beacons (pixels)

Web beacons are tiny images or scripts with a unique identifier that let us recognise that someone visited Adaging or opened an email we sent. We use them for advertising measurement and for email delivery diagnostics.

Local storage

Local storage holds your quiz answers, your generated plan and your progress on your own device, so the app keeps working smoothly and offline-tolerantly.

Why we need cookies

Without essential cookies and storage you could not sign in, pay, or keep your plan. The remaining ones help us understand which ads bring people who genuinely benefit from the program, so we do not waste money showing the wrong ads to the wrong people.

How we use cookies

As we improve the product, our use of cookies may change. Generally we use them for these purposes:

How can you manage cookies?

Most browsers let you control cookies in their settings. Blocking them may make Adaging work less well — and blocking essential cookies will prevent sign-in and payment from working at all. Clearing local storage will erase your saved quiz answers and plan on that device.

Cookies table

The cookies and storage keys we commonly use are listed below. The list is not exhaustive, but it covers the main reasons we set them.

NamePurposeType
sb-*-auth-tokenKeeps you signed in to your Adaging account (authentication).First-party, essential
sp_quiz_session_*, quiz_state_*, sp_anon_id (local storage); sp_funnel (cookie, 30 days)Saves your quiz answers and progress so you do not lose them on reload, and remembers which quiz you started.First-party, essential
__stripe_mid, __stripe_sidStripe payment processing and fraud prevention on the checkout screen.Third-party, essential
_fbpMeta Pixel — measures ad performance and attributes purchases to campaigns.Third-party, advertising
fbclid / _fbcStores the ad click identifier so a purchase can be matched to the ad you clicked.Third-party, advertising
__cf_bm, cf_clearanceCloudflare — distinguishes real visitors from bots and protects the site.Third-party, security
_cs_id, _cs_s, _cs_cContentsquare, session analytics: how pages are used, with all text masked. _cs_id about 13 months, _cs_s the current visit, _cs_c 13 days.Third-party, analytics
mp_*, __mpq_* (local storage)Mixpanel, product analytics: which screens and features are used and how far people get.Third-party, analytics
session-id, __dplSet by the platform that hosts the site to serve your visit consistently. session-id lasts the visit, __dpl about one day.Hosting platform, essential

Changes and contact

We may update this Policy when we add or remove a service provider. The current version is always available at this page. If you have questions about cookies on Adaging, write to support@adaging.io.