™

Cookie Policy

Last updated September 17, 2026

This page describes the cookies and similar technologies nlaapp.com actually uses. It is based on the live codebase and hosting setup, not a generic template. If we add advertising or analytics cookies later, we will update this page and the banner choice will start gating those optional cookies.

Who this covers

This policy covers pages on nlaapp.com (and the same Next.js app on its Vercel host), including marketing pages, signup and login, the Coaching Hub, /client in a browser, and the separate 5-Week Reset funnel under /5-week-reset.

It does not rewrite the iPhone app Privacy Policy. The app uses its own local storage and purchase systems on the device and App Store / Google Play.

Related site policies: Privacy, Terms, Refunds. Questions: matt@nlaapp.com.

What we found on this site today

After reviewing the application code, auth middleware, and dependencies, here is what actually runs:

  • No advertising cookies. There is no ad network, retargeting pixel, or marketing tag manager in this project.
  • No third-party product analytics cookie. There is no Google Analytics, Meta Pixel, Mixpanel, Segment, PostHog, or Vercel Analytics package installed.
  • Essential auth cookies. When you sign in, Supabase Auth (via @supabase/ssr) writes first-party session cookies so the server and browser can keep you logged in across /login, /client, /coach, /coaching, and /account. Those cookies are required for authenticated product use.
  • Consent preference. When you Accept or Reject the cookie banner, we store that choice in your browser (localStorage and a small first-party cookie named nla_cookie_consent) so we do not keep asking every visit.
  • Stripe Checkout. Paying for an organization subscription or the 5-Week Reset opens Stripe's hosted checkout. Stripe may set its own cookies on stripe.com. That is Stripe's domain, not ours. Card data is handled by Stripe; we do not see full card numbers.
  • 5-Week Reset access. Program access after purchase is a private URL token (/reset/...), not a login cookie.
  • Hosting. The site is hosted on Vercel. Like most hosts, the edge may use technical cookies or headers needed to deliver the page securely. We do not use Vercel Analytics in this app today.

Cookie categories

Essential. Required to provide a service you ask for. On this site that means Supabase session cookies when you are signed in, and the consent preference itself after you choose. Rejecting optional cookies does not remove essential sign-in cookies if you log in; without them the hub cannot stay authenticated.

Optional (analytics / advertising). Not used on nlaapp.com today. If we add them later, Accept will allow them and Reject will keep them off. Until then, Accept and Reject both mean: no optional tracking cookies are set by us.

Your choices

On your first visit we show a banner with Accept and Reject, plus a link to this page. You can change your mind by clearing site data for nlaapp.com in your browser (that clears the consent preference and shows the banner again), or by emailing matt@nlaapp.com.

You can also block or delete cookies in your browser settings. Blocking all cookies may prevent sign-in and signed-in features from working.

How long things last

Supabase session cookies follow Supabase Auth's session and refresh lifetimes (they renew while you keep using the site signed in, and expire after logout or idle expiry).

The consent preference cookie is set for about one year, or until you clear it.

Updates

If we start using optional analytics or advertising cookies, we will update this Cookie Policy, update the Privacy Policy cookies section, and make the banner choice control those optional cookies for real. The date at the top of this page will change when we do.