Cookie Policy
Last Updated: April 30, 2026
Jump to section…
Last Updated: April 30, 2026 Effective Date: May 1, 2026
This Cookie Policy explains how FORMD APP LLC ("FORMD," "we," "us") uses cookies and similar tracking technologies on the FORMD website (tryformd.com), the Coach Platform (coach.tryformd.com), and other FORMD-operated web properties (collectively, the "Sites"). The FORMD iOS Mobile App does not use browser cookies; the Mobile App uses the SDK identifiers and device-storage mechanisms described in our Privacy Policy.
This Cookie Policy is incorporated into and forms part of the Privacy Policy. Capitalized terms not defined here have the meanings given in the Privacy Policy.
1. What Are Cookies?
A cookie is a small text file that a website places on your device (computer, tablet, or phone) when you visit it. Cookies allow the website to recognize your device on subsequent visits, remember your preferences, keep you signed in, and gather information about how you use the site.
We also use similar technologies that perform comparable functions, including:
- Local Storage and Session Storage — key-value data stored in your browser;
- IndexedDB — a browser-based database used by some applications for offline support;
- Pixels and tracking beacons — small images or scripts that record when content is viewed.
For convenience, this Policy refers to all of these as "Cookies."
2. How We Categorize Cookies
We classify Cookies into four categories:
| Category | What it does | Can you opt out? |
|---|---|---|
| Strictly Necessary | Required for the Sites to function (e.g., authentication, security, load balancing). The Sites cannot operate without these. | No. Disabling these will break the Sites. |
| Functional | Remember your preferences (e.g., theme, language, last-visited page). | Yes, but the Sites may be less convenient to use. |
| Analytics / Performance | Help us understand how the Sites are used so we can improve them. | Yes, in jurisdictions where consent is required (e.g., EU/UK), we will not set Analytics Cookies until you opt in via our cookie banner. |
| Support / Operational | Power the in-product support widget and customer support features. | Yes, but you will not be able to use the chat-support feature. |
We do not use advertising cookies. We do not run targeted advertising on the Sites and we do not share Cookie data with third parties for cross-context behavioral advertising.
3. Cookies and Similar Technologies We Use
The following table lists every Cookie or similar technology set on the Sites as of the Last Updated date above. We update this list when our use changes. If you find a Cookie on the Sites that is not on this list, please email privacy@tryformd.com — we want to know.
3.1 Strictly Necessary
| Name / Pattern | Set By | Purpose | Storage Type | Duration |
|---|---|---|---|---|
sb-*-auth-token, sb-*-auth-token-code-verifier | Supabase (supabase.co) | Authentication and session management for the FORMD Web App, athlete portal, and Coach Platform. Stores the signed JWT and refresh token used to keep you signed in. | Local Storage | Until session expiry, sign-out, or browser data clear. Refresh tokens up to 30 days. |
__cf_bm, cf_clearance | Cloudflare (set via Vercel / Supabase edge) | Bot protection, request anti-fraud, and DDoS mitigation. | Cookie (HttpOnly) | 30 minutes (__cf_bm) / up to 1 year (cf_clearance). |
formd_csrf (if present in your deployment) | FORMD | CSRF protection for state-changing requests to the Coach Platform. | Cookie (HttpOnly, SameSite=Lax) | Session. |
__stripe_mid, __stripe_sid | Stripe (stripe.com) | Fraud prevention and payment processing for Coach Plan checkout and Customer Portal. Set only on pages that load Stripe.js. | Cookie | __stripe_mid: 1 year; __stripe_sid: 30 minutes. |
sentry-trace, baggage (request headers, not cookies) | Sentry (sentry.io) | Error monitoring and crash reporting. Captures error events, stack traces, and request-correlation identifiers so we can diagnose and fix bugs that affect the Sites. Treated as Strictly Necessary for security, fraud-prevention, and platform integrity. | Request header / minimal local-storage trace ID | Session. |
3.2 Functional
| Name / Pattern | Set By | Purpose | Storage Type | Duration |
|---|---|---|---|---|
formd_consent | FORMD | Records your cookie-banner choices so we don't ask again on every page load. | Local Storage | 12 months. |
formd_theme | FORMD | Remembers your light/dark theme preference. | Local Storage | Persistent until you clear browser data. |
formd_lastSeenAnnouncement | FORMD | Hides marketing announcements you've already dismissed. | Local Storage | Persistent until you clear browser data. |
3.3 Analytics / Performance (consent required in EU/UK)
| Name / Pattern | Set By | Purpose | Storage Type | Duration |
|---|---|---|---|---|
mp_*_mixpanel | Mixpanel (mixpanel.com) | Product analytics — page views, feature usage, conversion funnels. Helps us understand which features are valuable and which need improvement. | Cookie + Local Storage | 1 year. |
__mpid | Mixpanel | Distinct user identifier (pseudonymous) used to stitch analytics events for a single device or signed-in user. | Local Storage | 1 year. |
sentryReplaySession (only when session-replay is enabled for a given session) | Sentry (sentry.io) | Session-replay snippets captured at the moment an error occurs. Session-replay reconstructs the user-facing screen state around an error so engineers can reproduce the bug. Engaged only for diagnosing errors, never for general UX monitoring. Only set after user opts in to Analytics cookies. | Session Storage | Session. Replay payloads retained server-side per Privacy Policy retention schedule. |
3.4 Support / Operational
| Name / Pattern | Set By | Purpose | Storage Type | Duration |
|---|---|---|---|---|
intercom-id-*, intercom-session-*, intercom-device-id-* | Intercom (intercom.io) | Powers the in-product customer support widget. Identifies your conversation across page loads and stores chat history so you can pick up a conversation where you left off. | Cookie + Local Storage | intercom-id-* and intercom-device-id-*: 9 months. intercom-session-*: 1 week. |
intercom-state-* | Intercom | Stores the open/closed state of the support widget. | Cookie | Session. |
4. How to Control Cookies
4.1 Cookie Banner (EU, UK, EEA, and other consent-required jurisdictions)
When you first visit the Sites from a jurisdiction where consent is required (including the EU, UK, EEA, Switzerland, and certain U.S. states with opt-in regimes for sensitive data), we display a cookie banner that lets you (a) accept all Cookies, (b) reject all non-essential Cookies, or (c) customize your choices by category. Strictly Necessary Cookies are set regardless because they are required for the Sites to function. Your choices are recorded in formd_consent and are honored until you change them.
4.2 In-Product Settings
Once signed in, you can change your cookie preferences at any time from Settings → Privacy → Cookie Preferences. Changes take effect immediately for the current session and on subsequent visits.
4.3 Browser Controls
Most browsers let you view, delete, and block Cookies on a site-by-site or global basis. The exact controls vary by browser:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Safari: Settings → Privacy → Manage Website Data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Blocking Strictly Necessary Cookies will break authentication and certain core features.
4.4 Do Not Track and Global Privacy Control (GPC)
The Sites do not respond to traditional "Do Not Track" browser signals because the standard has not been finalized.
The Sites do honor Global Privacy Control (GPC) signals. When we detect a GPC signal, we treat it as an opt-out of analytics cookies and (for U.S. residents in jurisdictions where applicable) as a request to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising — even though we do not engage in such sale or sharing in the first place. See our Privacy Policy for more on how GPC interacts with state-level privacy rights.
4.5 Opting Out of Specific Sub-processors
- Mixpanel: You may opt out of Mixpanel analytics globally at https://mixpanel.com/optout/.
- Sentry: Core Sentry error monitoring (request-trace headers, stack-trace capture) is classified as Strictly Necessary under §3.1 and is required to operate the Sites securely. Sentry session-replay (which captures screen content around an error) is a separate Analytics feature; you can opt out of session-replay by rejecting Analytics/Performance Cookies in our cookie banner. Disabling core Sentry at the browser level (e.g., via script blocking) is technically possible but will reduce our ability to diagnose and fix errors that affect you.
- Intercom: If you do not want to use the in-product support widget, you can close it. To prevent Intercom from setting Cookies entirely, reject Support/Operational Cookies in our cookie banner; in-product chat support will not be available, and you should email support@tryformd.com instead.
- Stripe: Stripe cookies are set only on pages that load Stripe.js (e.g., the Coach Plan checkout and billing pages). If you do not load those pages, Stripe cookies are not set.
5. Third-Party Sub-processors and Their Privacy Policies
Some Cookies are set by third-party sub-processors that perform services on our behalf. The full list of FORMD sub-processors and their roles is in the Privacy Policy and the Data Processing Agreement. Each sub-processor's cookie/privacy practices are also governed by their own policies, which we link here for transparency:
- Supabase — https://supabase.com/privacy
- Stripe — https://stripe.com/privacy and https://stripe.com/cookies-policy/legal
- Mixpanel — https://mixpanel.com/legal/privacy-policy/
- Sentry — https://sentry.io/privacy/ and https://sentry.io/cookies/
- Intercom — https://www.intercom.com/legal/privacy and https://www.intercom.com/legal/cookie-policy
- Cloudflare — https://www.cloudflare.com/privacypolicy/ and https://www.cloudflare.com/cookie-policy/
- Vercel — https://vercel.com/legal/privacy-policy
6. International Transfers
Cookies set by us and our sub-processors may result in your data being transferred to and stored in the United States or other jurisdictions. We rely on Standard Contractual Clauses ("SCCs") and other lawful transfer mechanisms with each sub-processor as described in the Privacy Policy and DPA.
7. Children
The Sites are not intended for children under thirteen (13). We do not knowingly set Cookies on devices used by children under thirteen (13). If you believe a child under thirteen (13) has used the Sites, please contact privacy@tryformd.com.
8. Changes to This Cookie Policy
We update this Cookie Policy whenever our use of Cookies changes. The "Last Updated" date at the top reflects the most recent change. For material changes (e.g., adding a new analytics provider, a new category of tracking), we will re-prompt the cookie banner so you can review and update your choices.
9. Contact
Questions about cookies, the cookie banner, or how to exercise your rights:
FORMD APP LLC Email (privacy): privacy@tryformd.com Email (general): support@tryformd.com Mailing: Mailing address available upon written request to legal@tryformd.com, State of Florida, United States