1.What this policy covers

This Cookie Policy explains which cookies and similar technologies the amaina.health website uses, why, and how you can manage them. Amaina is a wellness tracker that helps you log migraine patterns and prepare for a doctor visit.

The website is where you learn about Amaina and get the app from the Apple App Store — you subscribe inside the app through Apple, not on the website (see our Terms of Use). The site is marketing and legal pages plus an optional email/waitlist sign-up; it does not host checkout or process payments. This policy covers cookies on that site.

It does not cover the Amaina iOS app. The app is a native mobile client and generally does not use browser cookies; it uses software development kits (SDKs) from providers like Apple, Google (Firebase), and RevenueCat to run. What data the app collects and how we use it is described in our Privacy Policy, with the full list of providers in our Subprocessors list.

For simplicity, we use "cookies" throughout to mean cookies and similar technologies — web beacons, pixels, tags, and local/session storage.

2.What are cookies?

A cookie is a small text file a website stores in your browser. Cookies remember things — your preferences, your sign-in session, which pages you've seen, whether an ad brought you to us.

3.Cookies we use

Cookies on amaina.health fall into four categories. Exact cookie names and lifespans can change as our providers update their tools; when that happens we update this list.

3.1 Strictly necessary (always on)

Required for the site to function — to remember your cookie choices, maintain your session, and protect against fraud and abuse. You can't reject these without breaking the site.

CookieSet byPurposeLifespan
cookie_consentamaina.healthStores your cookie preference choices1 year
session / session_idamaina.healthMaintains your session while you browse the siteSession
csrf_tokenamaina.healthSecurity — protects against cross-site request forgerySession

Note on payments. Amaina subscriptions are sold inside the iOS app through Apple's In-App Purchase — not on this website. The site does not host checkout or process payments, so it sets no payment-processor cookies. See our Privacy Policy and Subprocessors list.

3.2 Functional / preferences (optional)

Remember choices you make so the site behaves the way you expect — for example, your language or interface preferences. These aren't required, but turning them off may make the site less convenient.

CookieSet byPurposeLifespan
prefs / ui_settingsamaina.healthRemembers non-essential preferences (e.g., language)6 months

3.3 Analytics (optional)

Help us understand how visitors find and use the site so we can improve it. We use this data in aggregate — we don't try to identify individual visitors from it, and we don't put any health data into analytics.

CookieSet byPurposeLifespan
_gaGoogle Analytics 4Distinguishes unique visitors2 years
_ga_<container-id>Google Analytics 4GA4 session/state cookie — persists session and campaign data2 years
_gidGoogle Analytics 4Distinguishes unique visitors24 hours
GTM containerGoogle Analytics 4 (Tag Manager)Loads other tags (analytics, advertising)Session

Google Search Console, if used, doesn't set cookies — it verifies the site via a meta tag or file. We mention it only because it's part of our analytics stack.

HubSpot. We use HubSpot for website email / CRM (the sign-up form and product updates you opt into) — see our Subprocessors list. If a HubSpot form or tracking script runs on a marketing page, it may set HubSpot cookies (for example, __hstc, hubspotutk, __hssc) to remember your form session and how you found us. Where it does, those cookies sit in this analytics category and load only after you consent. HubSpot never receives your health data.

3.4 Advertising (optional)

Let us measure how our web ad funnel performs and, where you consent, show you relevant ads on Meta (Facebook, Instagram) and Google. On amaina.health these are used for aggregate conversion measurement of our marketing.

CookieSet byPurposeLifespan
_fbpMeta PixelIdentifies your browser for ad measurement90 days
_fbcMeta PixelStores last-click data for ad attribution90 days
_gcl_auGoogle AdsConversion measurement90 days
IDEGoogle DoubleClickAd targeting and measurement13 months
NIDGoogleUser preferences for Google ads6 months

Hard limit — no health data in advertising. Advertising cookies run only on the website and only for aggregate conversion measurement, and only if you consent. We never send your health data, HealthKit/Health Connect data, migraine logs, structured logs, or AI outputs to Meta, Google's ad products, or any advertising platform; we never use them to build custom, lookalike, or health-interest audiences; and we never sell your personal information. See our Privacy Policy and website privacy rights notice.

If we add new cookies in the future (such as heatmap, A/B testing, or session-recording tools), we'll update this list and ask for renewed consent where required.

4.Your choices

You're in control of every optional cookie.

4.1 Via our cookie banner

When you first visit amaina.health, you'll see a cookie banner. Optional cookies (functional, analytics, advertising) do not load until you consent. You can:

You can change your choice anytime by clicking "Cookie settings" in the site footer.

4.2 Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) signal. Where your browser sends GPC on amaina.health, we treat it as a valid request to opt out of the "sale"/"sharing" of your personal information for advertising, and we apply that to the advertising and analytics cookies on this site.

To be clear, GPC here affects only the web advertising/analytics cookies — there is no health-data "sale" or "share" to opt out of, because we never put health data into cookies and never sell or share health data for advertising (see Section 3.4 and Section 7). For how GPC fits with your other rights, see our website privacy rights notice and Regional Addenda.

4.3 Via your browser

You can also manage cookies in your browser settings:

Note that blocking strictly necessary cookies may break parts of the site.

4.4 Via the advertising platforms

You can also opt out of personalized advertising directly:

5.Do Not Track (DNT)

Some browsers can send a "Do Not Track" (DNT) signal. There's no industry-standard response to DNT, so we currently don't change our behavior based on it. You can still control cookies using the methods in Section 4 — and, unlike DNT, we do honor the Global Privacy Control (GPC) signal (see Section 4.2).

6.The Amaina app (not covered by cookies)

The Amaina iOS app is a native mobile client and generally does not use browser cookies. Instead it relies on provider SDKs — for example, Apple (Sign in with Apple, Speech-to-text, HealthKit, and In-App Purchase for subscriptions), Google Firebase (Auth, Firestore storage, and Crashlytics crash diagnostics), RevenueCat (managing your App Store subscription and unlocking paid features, and forwarding subscription-lifecycle events server-side to Amplitude), Amplitude (product analytics — anonymous usage events are sent only if you turn on "Usage analytics"; separately, subscription/billing events reach Amplitude through a server-side RevenueCat integration regardless of that setting, as contractual billing data — see our Privacy Policy), and Anthropic (Claude), which is called only from our backend to structure your logged text.

Crucially, advertising pixels run only on the website — not in the app. The app itself does use in-app product-analytics (Amplitude) and crash-diagnostics (Firebase Crashlytics) SDKs, described in our Privacy Policy — but these carry no health data and no ad targeting, and neither feeds advertising. No health data, HealthKit/Health Connect data, structured logs, or AI outputs are ever used for advertising, in the app or on the web. For everything the app collects and how we use it — including AI processing, your consent for it, and your rights — see our Privacy Policy, AI Processing Disclosure, HealthKit Data Use, and Subprocessors list.

7.Cookies and your privacy rights

Some cookies — especially advertising cookies — can count as personal information under US state privacy laws (such as the California CPRA and, where relevant, Washington's My Health My Data Act) and, if it ever applied to us, EU/UK data-protection law. How we handle that data, and the rights you have (to opt out of "sale"/"sharing," to limit use of sensitive information, and more), is covered in our Privacy Policy and Regional Addenda. To be clear: we do not classify or use any health data through website cookies, and we never put health data into advertising.

8.Note for EEA / UK visitors (secondary)

We do not currently target the EEA or UK at launch (Amaina is US-only). We include this note only in case that changes.

If we begin offering Amaina in the EEA or UK, we would load non-essential cookies (functional, analytics, advertising) only after you give prior opt-in consent through the banner, consistent with the ePrivacy rules and GDPR/UK GDPR, and you could withdraw consent as easily as you gave it. Strictly necessary cookies would remain exempt from consent. Any personal data collected through cookies would be handled as described in our Privacy Policy and Regional Addenda, with international transfers covered by Standard Contractual Clauses (SCCs) or the UK IDTA.

9.Changes to this policy

When we add, remove, or change cookies, we'll update this Cookie Policy and change the "Effective Date" at the top. For material changes we may re-prompt for consent. The current version is always available at amaina.health/cookies.

10.Contact us

Questions about cookies on amaina.health:

Email: legal@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA

This page is written in plain English. If anything is unclear, email legal@smart-it.io — we'll explain.

<!-- INTERNAL — NOT FOR PUBLICATION. Remove this block before the page goes live.

Pre-publication checklist / open items for the site build + health-tech lawyer:

  1. LINK PLACEHOLDERS (site build). The bracketed cross-references in this doc — Privacy Policy, Terms of Use, Subprocessors, AI Processing Disclosure, HealthKit Data Use, Regional Addenda — are TEMPLATED LINK TARGETS, not live links. Wire each to its real amaina.health URL at publish (e.g. /privacy, /terms, /subprocessors, /ai-disclosure, /healthkit, /regional). Keep the visible target names IDENTICAL to the published document titles so nothing 404s. The Privacy Policy link in particular MUST resolve and stay consistent (Apple 5.1.2 — reviewers compare the privacy policy, this cookie policy, and the App Privacy answers line-by-line). Confirm no bracketed placeholder remains before submission.
  1. VENDOR SET CONSISTENCY (lawyer + build). The cookie vendor set here must match subprocessors.md and privacy_policy.md exactly: Anthropic (Claude), OpenWeatherMap, Google (Firebase Auth + Firestore + Crashlytics; GA4/Tag Manager; Google Ads/DoubleClick), Amplitude (in-app product analytics, US data region — anonymous usage events gated on the "Usage analytics" toggle, off by default; PLUS server-side RevenueCat->Amplitude subscription-lifecycle events (rc_*), keyed by the Firebase uid, that are NOT gated on the analytics opt-out — contractual/billing; self-assessed, not routed to counsel — Anton 2026-07-24), Apple (Speech / HealthKit / App Store / In-App Purchase), RevenueCat (subscription/entitlement management — receipt + app user id + subscription status, which now also flows server-side to Amplitude; no card data, no health data), and web-only HubSpot + Meta pixels. Amplitude and Firebase Crashlytics are in-app SDKs (build 1.0.0(22)) and MUST appear as subprocessors in subprocessors.md AND privacy_policy.md before publish (Apple 5.1.2 cross-check); the Firebase entry there must read "Auth + Firestore + Crashlytics", not just "Auth + Firestore". Stripe was REMOVED entirely — monetization is now Apple In-App Purchase via StoreKit, managed with RevenueCat; there is no web checkout, so the site sets no payment-processor cookies. Cloudflare was REMOVED (not in the canonical subprocessor set / not disclosed elsewhere) — if a CDN/WAF is in fact used, add it to subprocessors.md AND privacy_policy.md first, then re-add its cookie row here so all three docs match.
  1. HUBSPOT COOKIES (build). Confirm whether HubSpot forms/tracking actually run on amaina.health marketing pages. If yes, the __hstc / hubspotutk / __hssc rows belong in the analytics category (added as a note in 3.3) and must be consent-gated. If HubSpot is email/CRM only with no on-site script, replace the note with a one-line "HubSpot does not set cookies on this site" (like the Google Search Console note).
  1. GA4 NAMING. _ga, _ga_<container-id>, _gid, and the GTM container are all labeled a single vendor ("Google Analytics 4") to avoid reading as two vendors; keep this consistent with how Google is named in subprocessors.md.

-->