Better Moose legal
Cookie & Storage Disclosure
Version: v1-launch-2 · Status: published_current · Effective: 2026-09-26
This disclosure is notice-only. Viewing it does not grant optional analytics, marketing, or preference consent, and it is not collected as an onboarding checkbox.
Status and scope
This Cookie & Storage Disclosure (version v1-launch-2) describes storage and access behavior identified in the audited Better Moose repository. It is notice-only and is not collected as an onboarding acceptance checkbox.
This disclosure describes storage and access behavior identified in the audited Better Moose repository. It does not describe planned cookies, vendors, analytics, advertising, or tracking as though they already exist.
Browser/device storage and server-side records are different concepts. This notice identifies the current browser-facing storage mechanisms and explains related server-side records where needed for accuracy; the Privacy Policy describes Better Moose's broader server-side data processing.
Strictly necessary storage currently used
Better Moose currently uses a first-party HttpOnly cookie named carrot_consent_preferences to remember the user's storage choices. It is classified as necessary preference-control infrastructure because Better Moose needs the saved decision to apply those choices on later requests. The cookie uses path /, SameSite=Lax, a 180-day maximum age, a 2,048-byte encoded-value limit, and Secure when the request uses HTTPS.
The consent-preference cookie contains normalized consent metadata only: schema and policy versions, decision status, timestamps for a recorded decision, and explicit category grants when customized. The C19 transport rejects unexpected payload fields rather than using this cookie for health, food, photo, or marketing data.
Signed-in Better Moose use also relies on Better Auth's session mechanism. Better Moose's current auth configuration is database-backed, uses email/password authentication, does not override Better Auth's default cookie prefix/name, and enables a short-lived 60-second session cookie cache to reduce latency on page navigation. Better Auth's documented default session-token cookie is better-auth.session_token. The server keeps the corresponding session record through Better Moose's database adapter.
Authentication and the consent-preference control are treated as necessary for their actual requested functions. This classification does not make analytics, advertising, marketing, attribution, or unrelated convenience storage necessary.
Optional acquisition continuity
The marketing_advertising category now has one implemented first-party browser-storage mechanism: the C18 better_moose_acquisition cookie used for acquisition-attribution continuity.
C18 sets this cookie only when current C19 marketing_advertising consent is explicitly allowed and the server finds eligible external acquisition evidence. Unknown, rejected, stale, invalid, or otherwise ungranted optional consent does not establish new durable acquisition continuity.
The cookie is first-party, HttpOnly, SameSite=Lax, Secure on HTTPS, and restricted to Path=/api/attribution. A normal set has no Max-Age or Expires, so the cookie is session-scoped.
The cookie stores only an opaque acquisition identity UUID. It does not contain UTM values, campaigns, referrer data, a user ID, email/name, health/profile information, or analytics payloads.
The browser cookie is only a continuity reference. Canonical acquisition evidence, derived first/last attribution, conversion snapshots, and user binding where applicable are separate first-party server-side records.
On a later C18 API interaction while marketing permission is not allowed, an active acquisition cookie is cleared with Max-Age=0. That browser-cookie cleanup does not itself state that historical server-side attribution evidence has been erased.
Optional analytics and preferences
C19 keeps analytics, marketing/advertising, and other optional categories separate from necessary storage and from functional storage that a feature needs to work.
Better Moose has a first-party server-side analytics sink. When (and only when) optional analytics is allowed, the analytics recorder keeps a single one-value marker in browser storage so a session is counted once. It is not created without that permission.
No configured Google Analytics, PostHog, Segment, Mixpanel, Meta/Facebook Pixel, advertising/remarketing SDK, or other third-party analytics or advertising browser integration was identified in the audited implementation.
Browser-storage census
Better Moose keeps some information in your browser or app storage (localStorage and sessionStorage) on your device. This replaces the earlier statement that no such use was identified; that statement was not accurate.
Screen copies: recent copies of screens such as Today, workouts, the food journal, recommendations, and the calendar month are kept so screens open faster. Some contain health-related information you entered, such as workouts, meals, and calendar entries. They stay on your device.
Drafts and hand-offs: an unsent workout draft, an in-progress food photo session, and short hand-offs between recipe screens are kept so you do not lose your place.
Choices and dismissals: choices you make in the app, such as your preferred workout location and equipment exclusions, dietary persona and filter presets, voice persona, and tips you dismissed, are remembered on your device. This includes your default grocery store and, for stores near you, the last Kroger store you used and the ZIP code you typed to search for it. That ZIP code is an approximate location you entered yourself; it stays on your device and is sent only to Kroger's store search when you search.
Grocery ordering: after you send your grocery list to a store or share it, your device keeps a note for up to 7 days so the app can ask whether your order arrived. It contains a time, a random identifier, a store name, and a kind of handoff, and nothing about what was on your list.
Better Moose treats these as functional storage: each item exists to provide a feature you are using or to remember a choice you made, and none is used for advertising or tracking or sent anywhere by itself. They do not depend on the optional preferences category, which is why they are listed here instead of being asked about separately.
Signing out or signing in clears this stored information from the device so the next person using the device does not see it. You can also remove it at any time by clearing this site's data in your browser or reinstalling the app.
The C19 consent-preference cookie and the C18 acquisition continuity cookie are set through server response-cookie behavior. The C18 HttpOnly cookie must not be confused with a direct document.cookie write.
The acquisition capture helper keeps its initial canonical landing snapshot in memory only. It does not use localStorage, sessionStorage, IndexedDB, fingerprinting, or URL decoration for continuity.
Your storage choices
Better Moose's globally mounted C19 controls let a user accept all optional categories, reject non-essential categories, or customize optional preferences. Necessary storage is not toggled through those optional controls.
Users can review or change optional choices at /consent/preferences. The withdrawal control records reject_optional for future C19 decisions instead of treating withdrawal as a new permission.
If the current preference is absent, unavailable, malformed, oversized, on an unsupported schema version, stale for the current policy version, rejected, or otherwise not granted, C19 does not silently enable optional storage.
For acquisition continuity specifically, a later C18 API interaction while marketing permission is unavailable clears an active better_moose_acquisition cookie. The current disclosure does not equate that browser cleanup with automatic deletion of historical server-side attribution records.
Legal acceptance is separate from optional consent
This disclosure is notice-only in the current legal registry. Viewing, acknowledging, or accepting Better Moose legal documents does not grant optional preferences/functionality, analytics, marketing, or advertising consent.
C20 legal acceptance records and C19 optional-consent preferences are separate systems with separate purposes. Neither Privacy Policy acceptance nor another legal acknowledgment substitutes for an optional C19 choice.
What is not currently claimed
This notice does not claim that Better Moose currently uses third-party analytics cookies, advertising networks, remarketing pixels, fingerprinting, social-media tracking, or provider-specific paid-click browser storage that was not identified in the audited implementation.
This notice does not call the C13 first-party server analytics sink third-party tracking, and it does not call the optional C18 acquisition cookie necessary storage.
This notice does not claim that the repository proves every cookie an infrastructure layer or future authentication flow could ever set. The audited source does not establish a complete Better Auth browser-cookie inventory. The active email/password session path, current C19 preference cookie, and current C18 acquisition continuity cookie are described from the present implementation; runtime inventory must be validated again when authentication, C19, analytics, attribution, or other storage behavior changes.
Changes to authentication configuration, C19 transport, optional storage consumers, analytics, attribution, advertising, plugins, or infrastructure-provided browser storage require a fresh inventory before a replacement version is published as current.
See the Privacy Policy for the broader audited data-flow disclosure.