Name
Purpose
Duration
Type
Legal Basis
CognitoIdentityServiceProvider.*
Authentication and session management
1 hour for access tokens; up to 30 days for refresh tokens
These are necessary for the website to function and cannot be disabled. They include authentication, security, payment, fraud prevention, consent records, and basic functionality required for the service you requested.
Contract necessity and legitimate interests in security and service delivery
PostHog analytics storage (ph_*_posthog on web where applicable)
Product analytics and masked session replay; may process user ID, IP/network data, device/app data, event metadata, and masked replay data depending on configuration
Up to 12 months
These help us understand how you use the app, which features you interact with, and how we can improve. Analytics may process identifiers such as user ID, IP/network data, device/app data, event metadata, and masked session replay data depending on configuration. EU/UK analytics require opt-in consent; outside the EU/UK, analytics may be enabled with an opt-out where permitted.
Consent in the EU/UK; legitimate interests with opt-out where permitted elsewhere
Service Worker Cache (Bae-i app cache)
Offline functionality and application performance
Persistent until cleared or replaced by a new app version
These are necessary for the website to function and cannot be disabled. They include authentication, security, payment, fraud prevention, consent records, and basic functionality required for the service you requested.
Contract necessity and legitimate interests in security and service delivery
IndexedDB / app storage (Bae-i preferences)
App preferences, settings, and local product state
Persistent until cleared, overwritten, or no longer needed
These remember your preferences and settings to provide a personalized experience. While helpful, they are not strictly necessary for the site to work.
Consent where required; otherwise legitimate interests in remembering requested preferences
__stripe_mid, __stripe_sid
Payment processing and fraud detection
Up to 1 year for __stripe_mid; about 30 minutes for __stripe_sid
These are necessary for the website to function and cannot be disabled. They include authentication, security, payment, fraud prevention, consent records, and basic functionality required for the service you requested.
Contract necessity and legitimate interests in payment security and fraud prevention
Cookie consent preference storage
Stores cookie choices and opt-out or consent records
Up to 12 months before refresh
cookiePolicy.types.consent
Legal obligation and legitimate interests in honoring and documenting privacy choices