Cookie Policy
Most cookie policies describe a tracking operation. This one mostly describes an absence, because at the time of writing the athlea.ai marketing site runs no analytics, no advertising pixels and no cross-site tracking of any kind.
That will probably change as the product launches. When it does, this page changes first and a consent banner goes up before a single tracking cookie is set.
The short version
- We set no analytics cookies, no advertising cookies, and no cross-site tracking identifiers on athlea.ai.
- The only device storage in play is what is strictly necessary to serve the site and stop bots abusing the forms.
- There is no cookie banner because there is currently nothing to consent to. A banner that asks permission for cookies you do not set is theatre.
- Some third parties see your IP address simply because your browser fetches things from them. That is not a cookie, but you should know about it, so it is listed below.
What cookies are
A cookie is a small file a website asks your browser to keep and hand back on your next request. Related technologies — local storage, session storage, pixels, SDK identifiers — do much the same job by different means, and the law treats them the same way. Where this page says “cookies”, it means all of them.
The distinction that matters is not technical. It is whether the storage is strictly necessary to deliver something you asked for, or whether it exists for our benefit — measurement, marketing, profiling. The first kind does not need your permission. The second kind always does, before it is set.
What we currently set
This table was written from the site’s source code, not from a browser inspection of the deployed site. Third-party scripts can set storage the source does not mention. Before this page is treated as accurate, open athlea.ai in a clean browser profile and list every cookie and storage entry actually created, then fill in the names and lifetimes above.
Third-party requests
Even without cookies, loading a page makes your browser fetch things from other companies’ servers, and those companies necessarily see your IP address and browser details.
Storage in the apps
The Athlea iOS and web apps store data on your device so you can stay signed in and use the app offline — a session token, cached plans and sessions, and your preferences. That is strictly necessary to run an app you have signed into, and is deleted when you sign out or remove the app.
The apps do not use advertising identifiers and do not carry advertising SDKs. On iOS the app does not request the advertising identifier (IDFA) and shows no App Tracking Transparency prompt, because there is nothing to track you with.
Two third-party components in the apps send us technical data. Sentry records crashes, errors and performance traces so we can fix what breaks; it is not used to build a profile of you or to target anything at you. Google Firebase provides sign-in, our database and push notifications — it is how your account works, not an analytics product for us. Sign in with Apple and Sign in with Google are also present, and are used only if you choose them.
If we add analytics
We will almost certainly want to measure how the site is used. When that happens, this is the commitment:
- Nothing non-essential is set before you have opted in. Not on page load, not “pending consent”.
- Rejecting is as easy as accepting — same prominence, same number of clicks. No pre-ticked boxes, no “legitimate interests” toggle buried two screens deep.
- You can change your mind later, from a link that stays on the site.
- This page is updated to list every cookie, its purpose and its lifetime, before the first one is set.
- Health data never feeds advertising or marketing analytics. That is not a preference, it is a hard line.
Controlling cookies yourself
Every major browser lets you see, block and delete cookies from its settings, and most have a private browsing mode that discards them when you close the window. Blocking strictly necessary cookies may stop the forms working, but nothing on this site depends on you accepting tracking, because there is none to accept.
The law we are following
Cookies in the UK are governed by the Privacy and Electronic Communications Regulations (PECR), which require prior consent for any storage that is not strictly necessary, alongside the UK GDPR, which sets the standard that consent has to meet — freely given, specific, informed, and as easy to withdraw as to give.
The Information Commissioner’s Office publishes guidance on cookies and has been enforcing against consent banners that make refusing harder than accepting. If you think this site is getting it wrong, tell us at privacy@athlea.ai, and you can also complain to the ICO at ico.org.uk.
Changes
This page is updated whenever what we store changes — and before the change ships, not after. How we use the data behind it is covered in the Privacy Policy.
Contact
Questions or corrections about this document go to privacy@athlea.ai. Athlea Ltd is registered in England & Wales with company number 15171507, at 86-90 Paul Street, London EC2A 4NE, United Kingdom.