Cookie Policy

Last updated: May 25, 2026

Wellness & AI is EU-built and GDPR-first. We use the bare minimum of cookies and local storage. No advertising trackers, no third-party pixels, no fingerprinting. You can grant or withdraw your consent at any time using the button below.

1. What we mean by 'cookies'

We use the word loosely to cover three storage mechanisms in your browser: HTTP cookies, localStorage, and sessionStorage. The ePrivacy Directive treats all three the same way for consent purposes.

2. Categories we use

Strictly necessary (always on)

Legal basis: Legitimate interest — required to deliver the service

  • wa.consent.v1 (localStorage)

    Records your cookie consent decision so the banner doesn't reappear.

  • sb-* (cookie)

    Supabase auth session — keeps you signed in.

  • wa.audience (localStorage)

    Remembers Individual vs Practitioner choice you make in the audience pill.

  • wa.utm.v1 (sessionStorage)

    Remembers which UTM-tagged link brought you here so we know which content works.

  • wa.referral.v1 (localStorage + cookie)

    Remembers a referral code from a friend's link so they get credit when you buy.

  • user_content_signals (server)

    What you've read so 'For You' suggests better next reads. This personalisation is the core product — without it the site can't function as designed.

  • wa-geo-banner-dismissed (localStorage)

    Hides the regional-page suggestion once you've seen it.

Analytics (consent required)

Legal basis: Consent (Art. 6(1)(a) GDPR + Art. 5(3) ePrivacy)

  • wa_session_id (localStorage)

    A random ID so we can count unique visits without using your IP.

  • analytics_events (server)

    Anonymous page views, CTA clicks, FAQ opens. No IP, no fingerprinting.

3. What we don't use

  • No Google Analytics, no Facebook Pixel, no TikTok Pixel.
  • No third-party advertising networks.
  • No cross-site tracking, no device fingerprinting.
  • No selling, renting, or sharing of your data.

4. Your rights (GDPR + ePrivacy)

You can, at any time:

  • Withdraw consent for analytics via the .
  • Request a full export of the data we hold about you.
  • Request deletion of your account and all associated data ("right to erasure").
  • Lodge a complaint with your national data protection authority.

Submit a data request from your account page or email us via the contact page. We respond within 30 days as required by Art. 12 GDPR.

5. Changes

If we materially change which cookies we use, we will re-prompt you for consent and bump the banner version above.