Storage
8. Cookies & Session Storage
FXOptimize uses only strictly necessary cookies and session storage required for the Service to function. No consent banner is required because no optional tracking cookies are used.
fxo_anon_session — HttpOnly, Secure, 1-year Max-Age. A pseudonymous per-device identifier (non-PII) used to enforce the free-tier monthly analysis quota. Legal basis: ePrivacy Directive Art. 5(3) "strictly necessary for a service the user has explicitly requested."- Supabase authentication tokens — Stored in the browser's sessionStorage (cleared when you close the tab). Required to keep you signed in during a session.
- Stripe cookies — Set by Stripe during checkout, governed by Stripe's privacy policy.
We do not use any advertising, cross-site tracking, or third-party marketing cookies. Our analytics — Cloudflare (pageviews, server-side) and self-hosted Umami (in-app usage) — set no advertising or cross-site cookies; Umami stores only a single first-party localStorage value to count unique visitors, and is loaded only after you consent.
Cookies & analytics consent
FXOptimize uses two privacy-first analytics layers, both free of advertising and cross-site tracking. Cloudflare measures aggregated pageviews and traffic server-side — no client-side script, cookies, or fingerprinting. Umami, which we self-host on our own server (no third-party analytics vendor), measures how the in-app tool is used — which features and funnel steps people reach — so we can improve it. It never receives your backtest data.
Umami is cookieless and does not fingerprint. It stores a single first-party localStorage value to count unique visitors without a cookie. Because that touches client-side storage, we load Umami only after you accept analytics in the cookie banner, and you can withdraw consent any time via Manage cookies, which stops it immediately. Cloudflare, being server-side and identifier-free, needs no consent.
What we collect: aggregated pageviews, country (from IP, not stored), browser + OS family, the referrer URL, and — once you consent — aggregated in-app events (which features and funnel steps were reached, never your backtest data). What we do NOT collect: your email, name, raw IP address (Cloudflare anonymizes it at ingest), specific URLs of authenticated app pages (those are blocked from analytics in robots.txt), device fingerprints, or behavioral profiles.
We also receive minimal HTTP server logs (IP + URL + timestamp) for security and rate-limiting purposes — these are deleted after 14 days and never linked to user identity.