Legal

Cookie Notice

Effective Fitness is in public beta. There is no cookie banner on this site, and this page explains why: the only cookies we set are the ones that keep you signed in, plus one that protects the Discord connect flow. There is no analytics package, no advertising pixel and no third-party tracker in this application.

Last updated: 29 August 2026

Not finished - do not launch with this page as it stands

The amber [OWNER: ...] markers below are details only the operator of this site can supply: the legal entity, a working contact email, and confirmation for your jurisdiction that strictly necessary cookies alone do not require a consent banner.

What a cookie is doing here at all

A cookie is a small piece of text your browser stores for a site and sends back on the next request. The web has no memory otherwise, so without one you would be signed out on every page you opened. That is the entire reason we use them.

The cookies we set

All of these are strictly necessary: remove them and signing in, or connecting Discord, stops working. None of them are used to profile you, and none of them are shared with anyone for advertising.

__sessionset by Clerk, our authentication provider

Holds your signed-in session so the server knows who you are on each request. Set when you sign in, cleared when you sign out.

Lasts: Until you sign out, or the session expires

__client_uatset by Clerk

A timestamp telling the app whether a signed-in session exists, so pages can render the right state without a round trip. It contains no personal information.

Lasts: Until you sign out

__clerk_db_jwtset by Clerk, development builds only

Carries the development session when the app is run locally, where cookies cannot be shared across ports the way they are in production. It is not set on the live site.

Lasts: Session

discord_oauth_stateset by Effective Fitness

Set only at the moment you click Connect on Discord, and only for the trip out to Discord and back. It holds one random value that the return leg has to match, which is what stops somebody else's Discord account being attached to your profile. It is deleted as soon as the connection finishes, succeeds or fails.

Lasts: 10 minutes, or until the connection finishes

Clerk manages the sign-in cookies, not us, and it can set additional short-lived cookies of its own while it hands a session between its domain and ours. They exist for the same reason as the ones above: to know that you are signed in. Clerk's own documentation is the authoritative list.

Other things stored in your browser

Your light or dark theme choice is saved in your browser's local storage, not in a cookie. It never leaves your device and is never sent to us. Clearing your site data resets it to the default dark theme.

Cookies set by other sites

When you pay, you leave Effective Fitness for Stripe's own checkout and billing pages. Stripe sets its own cookies there, on its own domain, mostly for fraud prevention. The same is true of Clerk's sign-in pages and of Discord if you go through the connect flow. Those cookies are governed by those companies' policies, not this one. We do not set cookies on their behalf, and they do not set tracking cookies on ours.

The fonts on this site are served from our own domain, not from Google's, so loading a page does not call out to a third party.

Why there is no cookie banner

Consent rules generally apply to cookies that are not strictly necessary: analytics, advertising, personalisation. We do not set any of those, so there is nothing to ask you to consent to, and a banner would be theatre. [OWNER: confirm this reasoning for your jurisdiction before launch]

If we ever add analytics or anything else that tracks you, we will add a real consent banner at the same time and update this page. We will not quietly start tracking and leave this text as it is.

Turning them off

Every browser lets you block or delete cookies, usually under privacy settings. You are welcome to. Be aware that blocking cookies for this site means you cannot stay signed in, so tracking workouts, posting and Premium will not work. Browsing the wiki, plans and public profiles signed out is unaffected.

Contact

Questions about cookies go to [OWNER: contact email] at [OWNER: legal entity name]. For the wider picture of what we collect and why, read the privacy policy, and the terms of service for the rules of the service.