CandyFit

Cookies and storage on your device

Which cookies and browser storage candyfit.me and the Candy Fit app use. In short: only what the site and the app need to work.

In short

candyfit.me has no advertising or analytics cookies, counters, social media pixels or embedded third-party video. Fonts are served from our own server, not loaded from Google. We only use strictly necessary cookies and browser storage needed to provide the service you asked for. Under Spanish law (LSSI-CE, art. 22.2) and the AEPD guidance these do not require consent. We still show a short banner on your first visit with equal "Accept" and "Reject" buttons: "Reject" breaks nothing, because we have no non-essential cookies. You can change your choice with "Cookie settings" at the bottom of the site or in the app's Profile tab.

What we store in your browser

NameTypePurposeDurationCategory
cf_sessioncookie (httpOnly, /api/ only)keeps you signed inup to 180 days or until you sign outstrictly necessary
cf_gstatecookie (httpOnly)protects Google sign-in against tampering10 minutes, only during sign-instrictly necessary
candyfit.langlocalStorageremembers your site and app languageuntil you clear site datafunctional, requested by you
candyfit.app.v1localStorageyour program: questionnaire, plan, check-ins, weight, badges (on this device only)until you tap "Start over" or clear site datafunctional, requested by you
candyfit.pro.v1localStorageaccount and sync state in the app, plan pricesuntil you clear site datafunctional, requested by you
candyfit.cookieslocalStorageremembers your choice in the cookie banner12 months or until you clear site datastrictly necessary
candy-entersessionStorageshows the app intro only once per visituntil you close the tabfunctional
candy-app-…app cache (service worker)lets the app open offlineuntil the next app updatefunctional

localStorage entries are not sent to our server by themselves. Your progress reaches us only if you sign in (see the privacy policy).

Third-party services on their own sites

These services set no cookies on candyfit.me. They work on their own pages when you go there:

  • Stripe (checkout.stripe.com): the card payment page. Stripe uses its own cookies for payment security and fraud prevention. Stripe policy
  • Google (accounts.google.com): if you choose "Continue with Google", sign-in happens on Google's page. Google policy
  • Telegram (t.me): if you open our bot or channel. Telegram policy

How to delete

  • Sign out in the app: the cf_session cookie is deleted immediately.
  • "Start over" in the app's Profile tab deletes your program and check-ins on this device.
  • You can delete everything from candyfit.me in your browser settings: "Site data" / "Cookies and site data" → candyfit.me → delete.

If we ever add analytics or anything else non-essential, we will ask for consent first, with equal "Accept" and "Reject" buttons and a way to change your choice. Questions: support@candyfit.me. Version of 2 October 2026.