This page explains the cookies and similar browser storage used on affiliate.nutrido.io and go.nutrido.io. A cookie is a small text file that a website stores in your browser. Local storage is a similar feature that keeps settings in your browser. We use only what the Portal needs to work securely and to remember your settings. We use nothing for analytics or advertising. It also explains when the iPhone invite page on go.nutrido.io copies an invite link to your device's clipboard (section 3).
1. Cookies
| Name | Set on | Purpose | Duration | Category |
|---|---|---|---|---|
nutrido-affiliate-session |
affiliate.nutrido.io | Identifies your session so that you stay signed in. The session data, including the security token for forms, is stored on our servers, not in the cookie. Encrypted, and not readable by page scripts | 120 minutes after your last activity | Strictly necessary |
XSRF-TOKEN |
affiliate.nutrido.io | Protects forms and actions against cross-site request forgery. Page scripts read it, for example to sign you in with a passkey | 120 minutes after your last activity | Strictly necessary |
remember_web_… (followed by a fixed string of letters and numbers) |
affiliate.nutrido.io | Keeps you signed in between visits. Set only if you tick "Remember me" when signing in | Up to 400 days, or until you sign out | Set at your request |
locale |
affiliate.nutrido.io | Remembers your display language. Set when you pick a language, or when you open a link with a language prefix, such as /pl/; the link's language is then remembered. Encrypted | 1 year | Functional (language preference) |
__cf_bm |
affiliate.nutrido.io and go.nutrido.io | Set by Cloudflare, which runs our hosting provider's network. It helps tell people from malicious bots | About 30 minutes | Strictly necessary (security) |
_cfuvid |
go.nutrido.io, and possibly affiliate.nutrido.io | Set by Cloudflare to apply request limits fairly when several visitors share one IP address | Until you close your browser | Strictly necessary (security) |
If Cloudflare's security protection asks your browser to complete a check, Cloudflare may also set the cf_clearance cookie. Cloudflare controls these cookies, and they are strictly necessary for security.
Our own cookies are sent only over encrypted connections (HTTPS). They are not shared with other websites.
2. Local storage in your browser
The affiliate portal also keeps a few display settings in your browser's local storage. These values stay in your browser. They are not sent to us and are not used to track you.
| Key | Purpose | Duration |
|---|---|---|
flux.appearance |
Remembers whether you chose the light, dark or system appearance | Until you clear it in your browser |
flux-sidebar-collapsed-desktop |
Remembers whether you collapsed the sidebar on a large screen | Until you clear it in your browser |
sidebar-groups: followed by your account number |
Remembers which sidebar sections (such as Analytics and Earnings) you opened or closed | Until you clear it in your browser |
3. Referral links on go.nutrido.io
Referral links set no cookies of ours and create no session. When you open a referral link, we record the click as described in our Privacy Notice and send you on. On referral links, the iPhone invite page, the download page and the go.nutrido.io home page, only Cloudflare's security cookies may appear.
Your device's clipboard (iPhone). If you open a referral link on an iPhone, we may show you an invite page. When you tap its button to get Nutrido on the App Store, your browser copies an invite link to your device's clipboard and then opens the App Store. The link contains a signed click token and nothing about you (see section 3.3 of our Privacy Notice). This is not a cookie. It is written only when you tap that button, and our website cannot read your clipboard. The Nutrido app reads the link at most once, when you first set up the app after installing it, and only if you allow it when iOS asks or you tap the paste button in the app yourself. The link stays on your clipboard until you copy something else.
4. No analytics, advertising or tracking
We do not use analytics, advertising, social-media or other third-party tracking cookies. We do not load tracking scripts, and our fonts are served from our own servers.
This is why we do not show a cookie consent banner. The cookies and storage on this page are either strictly necessary to provide the service you use, or remember settings for how the Portal is shown to you, such as your language, your appearance or "Remember me". The invite link is copied to your clipboard only at your explicit request, when you tap the button on the invite page. We consider that such storage does not require consent under Article 399 of the Polish Electronic Communications Law and Article 5(3) of the ePrivacy Directive.
Before we ever introduce a non-essential technology, such as analytics, we will ask for your consent first.
5. How to control cookies
You can view and delete cookies and local storage in your browser's settings. You can also block cookies for our websites. The help pages of your browser explain how.
If you block or delete the session cookie, you will not be able to sign in, and you will be signed out. If you delete the locale cookie while signed out, the Portal uses your browser's language again once your current session ends. When you are signed in, the Portal uses the language saved in your profile. Deleting the local storage keys resets your appearance and sidebar settings.
To remove the invite link from your clipboard, copy something else. If you do not want the Nutrido app to read it, do not allow pasting when iOS asks, and do not tap the paste button in the app: nothing is read then. On the invite page you can also use the second link, which opens the App Store without copying anything.
6. Contact
If you have questions about cookies, email us at hello@nutrido.io. For more about how we process personal data, see our Privacy Notice.