Current website storage summary
Wings does not set first-party cookies during ordinary browsing. The website uses one localStorage record when a trainer signs in or when a successful password reset establishes a session. No advertising, analytics, or social-media tracking storage is active.
About This Policy
This policy describes the cookies and similar browser-storage technologies actually used by wingsapp.fit. It is based on the website implementation reviewed in June 2026. It does not describe technologies that merely could be added in the future.
Cookies are small text records sent by a website and returned by the browser with later requests. localStorage is a separate browser feature that lets a website retain data on a device without sending that data automatically with every request.
First-Party Cookies
Wings does not deliberately set a first-party cookie on wingsapp.fit. The audited production pages return noSet-Cookie header, and the application contains no cookie-setting code.
Authentication is not implemented with a Wings session cookie. It uses Supabase Auth and localStorage as described below.
Supabase Authentication Storage
sb-btvjimmubdgjxbfxeyxg-auth-token
- Technology
- Browser localStorage
- Provider
- Wings and Supabase
- Purpose
- Keeps a trainer signed in on the website and authorises access to trainer pricing, billing information, Stripe Checkout creation, and the Stripe Customer Portal. The same record can be created after a successful password reset when the reset flow establishes a Supabase session.
- Contents
- Supabase session information, including an access token, refresh token, token expiry information, and associated user/session metadata.
- Retention
- The localStorage record has no independent browser expiry date. Supabase refreshes it while the session remains valid. It is removed when the user signs out, and it can stop working when Supabase invalidates the session, after a password or security change, or when the user clears site data.
This storage is required only for authenticated trainer features. Public pages and the waitlist can be viewed and used without signing in. Blocking or deleting this record signs the browser out and prevents authenticated billing features from working until the trainer signs in again.
Supabase API requests use the stored access token in an Authorization header. Wings does not convert that token into a cookie.
Stripe Hosted Checkout and Billing
Wings does not embed Stripe.js, Stripe Elements, or a card form on wingsapp.fit. When a trainer starts a new subscription, the website redirects the browser to Stripe-hosted Checkout. When a trainer manages an existing subscription, the website redirects to Stripe's hosted Customer Portal.
On Stripe's domains, such as checkout.stripe.com and billing.stripe.com, Stripe may use temporary and longer-lived cookies, local storage, device characteristics, and activity signals. Stripe uses these technologies to operate its pages, maintain secure sessions, remember relevant preferences, process payments, and detect or prevent fraud. Stripe's policy also describes functional and, where permitted and selected through Stripe's controls, advertising cookies across Stripe's services.
Stripe controls that storage on its own domains. Wings does not set, read, or choose the names and expiry periods of Stripe cookies. Current details and controls are available in the Stripe Cookies Policy.
Vercel Hosting
Vercel hosts and delivers wingsapp.fit. The current website does not include the Vercel Web Analytics package, Vercel Speed Insights, or a Vercel tracking script. Normal audited production responses did not set a Vercel cookie in the visitor's browser.
Vercel still processes ordinary server and network information needed to deliver and protect the website, such as request addresses, timestamps, user-agent information, and operational logs. That server-side processing is not a cookie or browser storage technology controlled by the Wings page.
Forms and Temporary Page State
Waitlist form entries, password fields, validation messages, loading states, and waitlist progress values are held only in page memory while the relevant page is open. Wings does not save those values to cookies, localStorage, sessionStorage, or IndexedDB.
When a waitlist form is submitted, its contents are sent to the Wings server and stored in Supabase. That database storage is covered by the Privacy Policy; it is not browser storage.
Your Choices
You can remove the Wings Supabase session by using Sign out on the trainer billing page. You can also clear cookies and site data for wingsapp.fit in your browser settings. Clearing localStorage signs you out of the website but does not delete your Wings account.
Browser controls for blocking all site storage may prevent trainer login and billing features from working. Stripe provides its own cookie controls on Stripe-hosted pages where required.
Changes to This Policy
If Wings adds analytics, advertising, embedded payment scripts, or another browser-storage technology, this policy will be updated before or when that technology is enabled. Where the law requires consent for a future non-essential technology, Wings will request that consent before using it.
Contact
For questions about this policy or the use of browser storage, contact wings.app@yahoo.com.
Legal entity
POENAR REMUS PERSOANĂ FIZICĂ AUTORIZATĂ
B-dul Bucureștii Noi, 136, et. Parter, ap. 5, Sector 1, București, România