Cookies and tracking
Effective: May 9, 2026
This page explains every cookie, similar identifier, and tracking signal Restorae uses. The short version is: this website does not track you, and the mobile app does not run any third-party analytics or advertising SDK. Below is the long version.
On the marketing website (restorae.app)
The marketing site is a static export served by nginx. It does not set any cookie of its own. It does not embed Google Analytics, Meta Pixel, Hotjar, Mixpanel, Amplitude, Segment, or any other analytics, ad-tech, or session-replay SDK. It does not embed social-media widgets that load third-party tracking scripts.
The site does load self-hosted typefaces (Lora, Plus Jakarta Sans) as static font files from the same domain. The fonts do not call home and do not set cookies.
If you click an outbound link to Apple, Google, or another store, that destination has its own cookie and tracking policy and we have no control over it.
On the staff dashboard (admin.restorae.app)
The staff dashboard — used only by Restorae employees — sets two strictly necessary, HTTP-only, Secure, SameSite=Strict cookies on successful staff login: a short-lived access token and a long-lived refresh token. These are session cookies for staff and do not run on the marketing site or in the consumer app. There is no analytics or tracking cookie on the dashboard either.
In the mobile app
The mobile app does not use cookies; cookies are an HTTP/web concept. It does store the following on your device, listed here for transparency:
- Authentication tokens. Stored in the operating system's secure keystore (iOS Keychain, Android EncryptedSharedPreferences). Required to keep you signed in.
- An encrypted local database. Used so you can check in and journal while offline. Encrypted with SQLCipher using a per-install key. Cleared when you delete the app or your account.
- A per-installation device identifier. Generated locally, used to order offline check-ins so the server can de-duplicate them. It is not an advertising identifier and is not shared with anyone outside Restorae.
- A push notification token, if you grant permission. Issued by Apple Push Notification service or Firebase Cloud Messaging. Used only to deliver scheduled reminders and account-security alerts.
Telemetry (opt-in, off by default)
With your explicit consent, the app may send anonymous product-interaction events (for example, "check-in completed," "tool session started") to our own backend, so we can understand what features are being used. The toggle is at Settings → Share anonymous usage and error telemetry and is off until you switch it on. There is no third-party analytics processor; the data goes straight to our own server.
Crash traces (Firebase Crashlytics)
When the app crashes, we receive a stack trace and basic device metadata via Firebase Crashlytics so we can fix the bug. Crashlytics payloads are not linked to your user account in our systems, are not used for advertising, and expire from Firebase within 90 days. The privacy policy explains this in detail at restorae.app/privacy.
What we never do
- We do not run an advertising SDK in the app.
- We do not embed an analytics SDK in the app.
- We do not use IDFA, AAID, or any other cross-app advertising identifier.
- We do not fingerprint your browser.
- We do not load third-party tracking pixels on the marketing site.
- We do not sell, rent, or share your data with data brokers.
- We do not run server-side ad attribution or conversion tracking.
Changes
If we ever introduce a tracking technology that does not appear above, we will update this page and, if you are an active user, notify you in-app at least 14 days before the change takes effect. The effective date at the top of this page reflects the current version.
Contact
Questions about tracking practices: privacy@restorae.app.