Cookies
Last updated 19 August 2026 · version 2026-08-19
1. What cookies are and which ones we use
Cookies are small files a website stores in your browser so it can recognise your session on the next request. We use strictly necessary cookies and — only if you opt in via the consent banner — analytics cookies. Your choice is stored in the kc_consent cookie for 12 months and can be changed at any time via the "Cookie settings" link in the page footer.
Strictly necessary cookies keep you signed in and remember a device you deliberately marked as trusted. They require no consent, because Kneecap.care cannot work without them. We do not set any advertising or cross-site tracking cookies of our own, and none of our own cookies are readable by third parties.
2. Cookies in detail
| Name | Purpose | Duration | Category | Set by |
|---|---|---|---|---|
sb-<project-ref>-auth-token (plus the .0 / .1 chunks used for long tokens) | Supabase Auth session (keeps you signed in, carries the MFA level) | Session / up to 1 year refresh | Strictly necessary | Kneecap.care (Supabase) |
sb-<project-ref>-auth-token-code-verifier | One-time security value that ties a sign-up confirmation or password-reset link back to the browser that asked for it (PKCE) | Until the link is used (short-lived) | Strictly necessary | Kneecap.care (Supabase) |
kc_device | Remembers a device you marked as trusted so it skips the 2FA code | 30 days | Strictly necessary (set only when you tick "Remember this device") | Kneecap.care |
kc_consent | Stores your cookie choice | 12 months | Strictly necessary (stores the choice you made in the consent banner) | Kneecap.care |
_ga, _ga_* | Google Analytics 4 usage statistics | Up to 2 years | Analytics — only after consent | |
ph_* | PostHog product analytics (EU) | Up to 1 year | Analytics — only after consent | PostHog |
The <project-ref> placeholder is the identifier of our Supabase project; your browser shows the full name in its cookie settings.
Analytics cookies are set by Google / PostHog only after you click "Accept all" or switch Analytics on under "Cookie settings"; withdrawing deletes the ones we can reach. Page addresses are stripped before they reach either provider: document and client identifiers in the path are replaced with a placeholder and query strings are dropped, so neither Google nor PostHog receives a URL that identifies a specific document or client.
3. How to change your choice
A "Cookie settings" link in the page footer reopens the consent dialog so you can grant or withdraw consent for analytics cookies at any time — withdrawing is as easy as giving. On withdrawal we switch both tools off, delete the analytics cookies and local-storage entries we can reach, and send nothing further; data already collected is pseudonymous and is deleted by the providers under the retention periods in section 6 of the Privacy Policy.
Independently of that, every browser lets you view, block and delete cookies in its settings. Deleting the strictly necessary cookies signs you out and makes a trusted device ask for the 2FA code again; the service otherwise keeps working.
4. Local storage
Beyond what the Supabase Auth client keeps for the signed-in session, Kneecap.care stores nothing in localStorage or sessionStorage until you accept analytics. After consent, PostHog keeps its pseudonymous identifiers in localStorage (keys starting with ph_) as well as in its cookie, plus a per-tab ph_…_window_id entry in sessionStorage. If you reject outright, PostHog is never loaded and stores nothing. If you withdraw after having consented, PostHog keeps a single opt-out flag (__ph_opt_in_out_…) in localStorage so it stays silent, and we remove its other ph_ entries, including the per-tab window_id in sessionStorage. No fingerprints or advertising IDs are stored.
5. Contact
Questions about cookies? Write to hello@kneecap.care. See also the Privacy Policy for how we handle personal data.