Coheart home

Cookie policy

Last updated: 21 August 2026

Which cookies we set

The coheart.io website uses Google Analytics, which sets cookies in your browser to measure how the site is used. It only runs if you accept it — if you reject analytics cookies, or have not chosen yet, Google Analytics is not loaded at all. We also use Plausible Analytics, which is fully cookieless and sets nothing on your device. The only cookies we set without asking are the strictly necessary ones: the cookie that keeps you signed in, and the one that records your cookie choice.

1. What are cookies?

Cookies are small text files placed on your device by a website when you visit it. They are widely used to make websites work efficiently and to provide information to the site owners.

Cookies can be “session cookies” (deleted when you close your browser) or “persistent cookies” (stored for a set period or until you delete them).

2. Cookies and local storage we use

Our cookie footprint is small. We set one cookie to record your cookie choice and one to keep you signed in, and Google Analytics sets analytics cookies on the marketing site once you accept them. Everything else Coheart stores in your browser uses localStorage.

How signing in works. The Coheart application (app.coheart.io) keeps you signed in two ways. It stores an opaque session token in your browser's localStorage under the key coheart_session, which the application sends explicitly on each API request, and our server also sets a session cookie. That cookie is HttpOnly, so scripts running in your browser cannot read it, and SameSite=Strict, so your browser does not send it when another site links to or embeds ours — which is what protects you against cross-site request forgery.

The coheart_session localStorage item contains no personal data — it is an opaque reference to a server-side session record.

What we store in your browser:

KeyPurposeStorageType
coheart_sessionKeeps you signed in. Opaque reference to a server-side session — contains no personal data.localStorage (not a cookie)Strictly necessary
coheart_consentRecords your cookie choice so we do not ask again. Set on .coheart.io so one choice covers coheart.io and app.coheart.io. Expires after 12 months.CookieStrictly necessary
sessionKeeps you signed in to app.coheart.io. Set by our server, cannot be read by JavaScript, and expires after 24 hours — or after 30 days if you chose to stay signed in.CookieStrictly necessary
_ga, _ga_*Set by Google Analytics to distinguish visitors and measure how the site is used. Expires after 2 years.CookieAnalytics

The rules on cookies in UK law apply to anything stored on your device, including localStorage — not only to cookies. The items above are exempt from asking for consent because they are strictly necessary: without them you could not sign in, and we could not honour the cookie choice you have made. The Google Analytics cookies are not strictly necessary, so they are set only if you accept them. You can clear any of these through your browser, though clearing the sign-in items will sign you out.

3. Analytics

coheart.io uses two analytics tools. Google Analytics, operated by Google LLC, sets cookies in your browser (_ga and _ga_*) to distinguish visitors and measure how the site is used. These are analytics cookies, not strictly necessary ones, so they are only set if you accept them. Google Analytics runs on the marketing site only. Plausible runs on both the marketing site and the Coheart application, and because it is cookieless it needs no consent.

We also use Plausible Analytics, an open-source, privacy-friendly tool:

  • Plausible does not store your IP address, and sets no cookie or other identifier on your device.
  • No cross-site or cross-device tracking occurs.
  • Aggregate traffic statistics only (page views, referrers, device types).
  • Data is processed in the EU and not shared with third parties.

For more information, see Plausible's data policy.

4. Transactional emails and Mailchimp

Coheart uses Mailchimp Transactional (Mandrill) to deliver service emails such as password reset links, account invitations, and session reminders. When you receive one of these emails, Mailchimp acts as our data processor and handles delivery of the message.

No email tracking. Open tracking (tracking pixels) and click tracking are disabled for all emails sent by Coheart. This means:

  • No tracking pixel is embedded in our emails — opening an email does not send any data back to Mailchimp or Coheart.
  • Links in our emails are not wrapped through Mailchimp redirect servers — clicking a link takes you directly to the destination.
  • No cookies are set on your device as a result of receiving or opening our emails.

For full details on how we use Mailchimp and how your email address is protected, see the Privacy policy — section 7.

5. How to control cookies

You can control and delete cookies through your browser settings. Note that disabling the strictly necessary cookies listed above may prevent you from signing in to the Coheart application.

You can change your analytics choice at any time: .

Browser cookie controls:

6. Changes to this policy

We may update this policy from time to time. Any changes will be posted on this page with an updated “last updated” date.

Questions? Contact us at privacy@coheart.io.