Cookies and storage on your device
Which cookies and browser storage candyfit.me and the Candy Fit app use. In short: only what the site and the app need to work.
In short
candyfit.me has no advertising or analytics cookies, counters, social media pixels or embedded third-party video. Fonts are served from our own server, not loaded from Google. We only use strictly necessary cookies and browser storage needed to provide the service you asked for. Under Spanish law (LSSI-CE, art. 22.2) and the AEPD guidance these do not require consent. We still show a short banner on your first visit with equal "Accept" and "Reject" buttons: "Reject" breaks nothing, because we have no non-essential cookies. You can change your choice with "Cookie settings" at the bottom of the site or in the app's Profile tab.
What we store in your browser
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
| cf_session | cookie (httpOnly, /api/ only) | keeps you signed in | up to 180 days or until you sign out | strictly necessary |
| cf_gstate | cookie (httpOnly) | protects Google sign-in against tampering | 10 minutes, only during sign-in | strictly necessary |
| candyfit.lang | localStorage | remembers your site and app language | until you clear site data | functional, requested by you |
| candyfit.app.v1 | localStorage | your program: questionnaire, plan, check-ins, weight, badges (on this device only) | until you tap "Start over" or clear site data | functional, requested by you |
| candyfit.pro.v1 | localStorage | account and sync state in the app, plan prices | until you clear site data | functional, requested by you |
| candyfit.cookies | localStorage | remembers your choice in the cookie banner | 12 months or until you clear site data | strictly necessary |
| candy-enter | sessionStorage | shows the app intro only once per visit | until you close the tab | functional |
| candy-app-… | app cache (service worker) | lets the app open offline | until the next app update | functional |
localStorage entries are not sent to our server by themselves. Your progress reaches us only if you sign in (see the privacy policy).
Third-party services on their own sites
These services set no cookies on candyfit.me. They work on their own pages when you go there:
- Stripe (checkout.stripe.com): the card payment page. Stripe uses its own cookies for payment security and fraud prevention. Stripe policy
- Google (accounts.google.com): if you choose "Continue with Google", sign-in happens on Google's page. Google policy
- Telegram (t.me): if you open our bot or channel. Telegram policy
How to delete
- Sign out in the app: the cf_session cookie is deleted immediately.
- "Start over" in the app's Profile tab deletes your program and check-ins on this device.
- You can delete everything from candyfit.me in your browser settings: "Site data" / "Cookies and site data" → candyfit.me → delete.
If we ever add analytics or anything else non-essential, we will ask for consent first, with equal "Accept" and "Reject" buttons and a way to change your choice. Questions: support@candyfit.me. Version of 2 October 2026.