This website loads no analytics until you consent to it. Before you choose, no analytics script is downloaded and no request is sent to any analytics server — not one. If you decline, or simply ignore the banner, the site works exactly the same and nothing is tracked.
This notice explains the little that is stored, and how to change your decision at any time.
1. Cookies and similar technologies#
A cookie is a small piece of text a website asks your browser to keep and send back on later visits. localStorage does something similar: it stores a value in your browser for a site, but the browser does not attach it to requests automatically — the site’s own code reads it.
Both are “storage on your device”, and under EU rules both are treated the same way: with narrow exceptions, we need your consent before storing anything or reading anything back.
2. Strictly necessary storage — your consent choice#
We store one thing without asking, because storing it is the only way to honour what you asked for: your cookie choice itself.
| What | Where | Contains | Lifetime |
|---|---|---|---|
| Consent decision | localStorage (shindo_cookie_consent) | Whether you accepted or declined analytics, the notice version, and the timestamp | 12 months, then we ask again. Removed immediately if you clear site data. |
Why no consent is needed for this: ePrivacy rules exempt storage that is strictly necessary to provide a service the user explicitly requested. Remembering “this person said no” is exactly that — without it, we would have to show you the banner on every single page load, and we would have no record that you declined.
It contains no identifier, no profile, and nothing that describes you. It never leaves your browser.
3. Analytics — PostHog, only after you say yes#
If (and only if) you accept analytics, we load PostHog, a product-analytics service, to understand how the site is used — which pages people read, where they arrive from, and which buttons actually get clicked.
Where it runs: the EU. All requests go to https://eu.i.posthog.com, and the data is processed and stored on PostHog’s EU infrastructure.
What is collected:
- Page views — which pages you open, and in what order
- Referrer — the site or search engine you came from, if any
- Approximate country, derived from your IP address
- Device and browser type — operating system, browser, screen size class
- Clicks on the site’s main buttons and links (App Store link, navigation, support links) — these are individually instrumented events
What is deliberately switched off:
- Autocapture — PostHog’s mode that records every click, input, and interaction across the whole interface. Disabled.
- Session replay — recording and replaying what you did on the page. Disabled. We do not record sessions.
- Advertising, remarketing, and cross-site profiling — not used at all (see §7).
What PostHog stores on your device, once you have accepted:
| Entry | Where | Purpose | Lifetime |
|---|---|---|---|
ph_<project-key>_posthog | Cookie | Anonymous visitor identifier, so repeat page views in a visit are not counted as separate visitors | 12 months |
ph_<project-key>_posthog | localStorage | The same identifier, plus session state — the current session id, the referrer you arrived by, and a cap on how many events one page may send | Until you turn analytics off or clear site data |
ph_<project-key>_posthog | sessionStorage | The referrer for this browser tab specifically | Until you close the tab |
ph_<project-key>_window_id | sessionStorage | A random id for this browser tab, so two tabs are not mistaken for two people | Until you close the tab |
ph_<project-key>_primary_window_exists | sessionStorage | A flag marking which tab is the active one | Until you close the tab |
ph_<project-key>_session_registered_properties | sessionStorage | The names of the properties attached to events in this session | Until you close the tab |
The identifier is a random value generated in your browser. It is not linked to your name, email, or any account.
Everything in the table above shares the ph_ prefix, and all of it is deleted the moment you turn analytics off (§5) — the cookie, the localStorage entry and every sessionStorage entry alike.
4. Before consent: zero requests#
This is worth stating plainly, because it is stronger than what most cookie banners describe:
- Until you accept, the PostHog script is never loaded — not deferred, not queued, not loaded-but-idle. It is not fetched at all.
- Consequently, no network request reaches any analytics domain, so no IP address of yours is seen by an analytics provider, and no cookie is set by one.
- If you decline, that stays true permanently, and the site remains fully functional. Declining breaks nothing.
This is the rule the site is built to, not a description of intent, and it is meant to be checkable: with analytics declined, a browser’s network inspector should show no request to any analytics domain. If you ever observe otherwise, please tell us at support@shindo-app.com — we would treat that as a defect.
5. Changing your mind#
Your decision is reversible in both directions, and you do not need to go digging through browser settings to do it.
- In the consent banner — accept or decline when it is shown to you.
- From the site footer — a “Cookie settings” link is available on every page of this site, including this one, and reopens the same control so you can switch analytics on or off at any time.
If you turn analytics off after having turned it on, the PostHog script stops running and its cookies are cleared. If you turn it on later, it starts again.
6. Do Not Track and Global Privacy Control#
If your browser sends a Do Not Track (DNT) header or a Global Privacy Control (GPC) signal, we treat it as a decline. Analytics stays off and the script stays unloaded, without you having to interact with the banner at all. You can still override it by explicitly accepting.
7. No third-party advertising or social trackers#
This site carries no advertising pixels, no remarketing tags, no social-network trackers, no A/B-testing third parties, and no data brokers. PostHog is the only third-party service that ever receives anything from your browser, and only with your consent.
8. The website’s analytics are separate from the app’s#
Shindo the iOS app and this website are analytically unconnected, deliberately. The app does use the same analytics vendor — PostHog, also on the EU host — but as a separate data set with a separate identifier that we never join to this one:
- The app’s identifier is a random UUID generated on the device at install time, held in the iOS Keychain. It is not your name, email, Apple ID, or any account identifier — and the app never sends your name, email or Apple ID to analytics, only that random UUID.
- The website’s identifier is a different random value generated in your browser.
- We do not match, join, merge, or otherwise reconcile a website visitor with an app user. There is no shared key, no login on this site, and no mechanism by which “this browser” becomes “that app installation”.
- Accepting analytics here changes nothing about what happens inside the app, and vice versa. The app’s analytics behaviour is described in the Privacy Policy.
- Being separate also means the choice you make here is not the choice you make there. The app asks its own consent questions on its own first screen, and its analytics is likewise off until you allow it — but the two answers are independent records and neither carries over. Accepting here does not switch anything on in the app; declining here does not switch anything off in it. The app’s questions, and what turning each one off actually does, are described in the Privacy Policy.
How the app itself handles your health and training data is a separate matter, described in the Privacy Policy.
9. Legal basis#
- Storage and access on your device (cookies, localStorage) — under the ePrivacy Directive and its national implementations, we rely on your consent for everything that is not strictly necessary. The consent record described in §2 is the strictly-necessary exception.
- Processing the resulting analytics data — under the GDPR, our legal basis is your consent (Art. 6(1)(a)). You may withdraw it at any time, as described in §5; withdrawal does not affect the lawfulness of processing carried out before it.
Full detail on what we process and why, including retention periods and your rights of access, rectification, erasure, and portability, is in the Privacy Policy.
10. Contact and complaints#
Questions about this notice, or about anything stored on your device by this site:
- Email: support@shindo-app.com
- Aleksandr Kolesnikov, Dimitri Nikolaou 7, Limassol, Cyprus, 4006
If you are in the EEA or the UK and you believe your data has been handled unlawfully, you have the right to lodge a complaint with your national data protection supervisory authority. We would appreciate the chance to put it right first, but that right is yours regardless.
11. Changes to this notice#
If we add a service that stores anything on your device, or change what is collected, we will update this notice, revise the date at the top, and — where the change concerns non-essential storage — ask for your consent again before anything new is loaded.
See also: Privacy Policy · Terms of Use · Health & Safety Disclaimer · Support
Cookie settings
Analytics on this site is currently off.