Cookie policy
Two necessary cookies keep you signed in. No advertising or profiling, and visits are counted only if you accept.
Last updated: 3 October 2026
Only for signing in
If you do not sign in, miaforo sets no cookies. Signing in creates two first-party cookies, needed to remember who you are. That is why they need no consent. The only thing we ask you is the visit count below.
The two cookies
- better-auth.session_token, 30 days: identifies your session, so you do not have to enter your password on every page.
- better-auth.session_data, 5 minutes: keeps a signed copy of the basic details of your session, including your role and gym.
Both are HttpOnly and SameSite=Lax. Page scripts cannot read them, and another website cannot use them to act in your name.
Maps
The Google map on a gym’s page only loads after you press the button to view it. Nothing is sent to Google before then.
Video
The video on miaforo’s front page only loads from YouTube after you press play, and then from youtube-nocookie.com. Nothing is sent to YouTube before then. Once it plays, YouTube may store data in your browser to play it.
Visit count on miaforo’s own website
On miaforo’s own pages at miaforo.com (the front page, features, pricing, help, the comparisons, signup and these legal documents) we ask whether we may count your visit with Cronitor. It never runs on a gym’s pages or inside the app. Nothing loads from Cronitor until you press Accept.
If you accept, your browser loads Cronitor’s script. For each page you open it sends Cronitor:
- your IP address, from which Cronitor can work out your country;
- the page address, without anything after the question mark;
- the name of the website you came from, if you followed a link;
- your browser and device: user agent, language, screen width and connection type;
- your time zone, and how long the page took to load.
It receives no name, email or account data. Cronitor’s script stores nothing in your browser, and it respects Do Not Track.
Cronitor is a company in the United States. It is not certified under the EU-US Data Privacy Framework, so no adequacy decision covers it, and it offers no other appropriate safeguard such as standard contractual clauses. US authorities could therefore access the data, and you may not have the same rights and remedies there as in the European Union. The legal basis is your explicit consent: Article 6(1)(a) GDPR for the count and Article 49(1)(a) GDPR for the transfer.
We keep your answer in localStorage under miaforo.visit-count, in this browser only, so we do not ask again on every page. It is never sent anywhere. If you reject, nothing loads. You can change your answer here at any time. Withdrawing stops the count from that moment and does not affect what was sent before.
What your browser keeps
Signing out removes both cookies. You can also delete or block them in your browser, but then you cannot sign in. If you choose the light or dark theme, we keep that choice in localStorage.
While you open your gym, the tab keeps what you typed in the form and the pending code step in sessionStorage, so a reload does not lose them. It stays in that tab only and is never sent anywhere. It is removed:
- when the gym opens;
- when you change the email;
- seventy minutes after the code was sent, if the page is still open;
- otherwise, the next time the signup page opens after that, or when you close the tab.
What we do not do
- There is no advertising, social-media pixel or profiling.
- We do not use Google Analytics. The only visit count is Cronitor’s, above, and only if you accept it.
- We do not sell or share data for advertising.
The privacy policy covers the data we handle and how long we keep it.