Effective Date: August 31, 2026
This Cookie & Storage Policy explains how UpgradingYou, LLC, a Delaware limited liability company ("we," "us," or "our") uses cookies, local storage, and similar technologies when you use the UpgradingYou web application and website (the "Service"). This policy should be read alongside our Privacy Policy.
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently, remember your preferences, and provide analytics information.
Local storage (including localStorage and similar browser-based storage mechanisms) serves a similar purpose to cookies but can store larger amounts of data. It is used by web applications to persist data locally on your device.
The UpgradingYou web application uses localStorage for the authentication session and ordinary preferences, and tab-scoped sessionStorage for private offline caches. Here is what we store and why:
These are necessary for the Service to function. You cannot opt out of these without losing access to the Service.
| Storage Item | Type | Purpose | Duration |
|---|---|---|---|
| Authentication session | localStorage | Keeps you signed in to your account. Managed by Supabase Auth. Includes access tokens and refresh tokens. | Until you sign out or the session expires |
| Private offline cache | sessionStorage | Temporarily caches profile/onboarding data, activity and completion state (including notes), entitlement/momentum state, and queued offline completion changes so the current tab can recover from a brief network interruption. | Until sign-out, account switch, reset/deletion, or the browser tab is closed |
| Theme selection | localStorage (AsyncStorage) | Remembers your chosen visual theme so it loads immediately on app start. | Until changed |
This is not required for the Service to work. It is stored only if you open a page that includes a creator's referral code.
| Storage Item | Type | Purpose | Duration |
|---|---|---|---|
upgradingyou.referral |
localStorage | Remembers the referral code so a later signup can be attributed to that creator. Creators never see your identity. | 30 days from the click, or until a newer referral link replaces it |
We use two analytics tools on the website, and they work differently. PostHog is optional product analytics tied to your account. Cloudflare Web Analytics is a cookie-less site measurement that reports aggregate page views and performance. On the web, no PostHog client, identifier, queue, or event is created until you explicitly allow analytics.
| Technology | Type | Purpose | Duration |
|---|---|---|---|
| Analytics consent decision | localStorage | Records only whether you granted or denied optional web analytics. An unknown or missing value means analytics is off. | Until you change the choice or clear browser storage |
| PostHog client state (only after consent) | In-memory | Temporarily queues explicit product events and an account identifier. We do not send the contents of your conversations, memories, habits, health, or financial data to PostHog. | Current page session; cleared immediately when consent is revoked |
| Cloudflare Web Analytics beacon | JavaScript (no cookie or storage) | Reports aggregate page views, referring pages, and browser performance timings. It does not use cookies, localStorage, or sessionStorage, and it is not tied to your account. | Nothing stored on your device. Cloudflare processes the beacon and discards the visitor IP for this purpose. |
PostHog on the web is always default-off until an explicit grant, not only where consent is legally required. Cloudflare Web Analytics does not use cookies and is not controlled by that Settings toggle.
Some third-party services integrated into the web application may use their own storage technologies:
If you use the UpgradingYou mobile app (iOS or Android) instead of the web version:
Most web browsers allow you to control cookies and local storage through their settings. You can:
Please note that blocking or deleting essential storage items will sign you out and may prevent the Service from working correctly.
You can decline the first web prompt or turn “Optional product analytics” off in Settings at any time. That choice applies to PostHog. Revocation immediately stops new PostHog events, resets the browser-side analytics identity, clears queued or persisted SDK state, and stores a denied decision. Cloudflare Web Analytics does not use cookies and is not turned off by that setting. Browser controls and analytics-blocking extensions may also block the Cloudflare beacon. We do not use analytics for advertising and do not sell analytics data.
It's important to understand the distinction:
We may update this policy from time to time, particularly when we add analytics or other technologies. We will post the revised policy on this page and update the "Effective Date." Material changes (such as adding new tracking technologies) will be communicated through the Service.
If you have questions about this Cookie & Storage Policy, contact us at:
Email: [email protected]