1.What this policy covers
This Cookie Policy explains which cookies and similar technologies the amaina.health website uses, why, and how you can manage them. Amaina is a wellness tracker that helps you log migraine patterns and prepare for a doctor visit.
The website is where you learn about Amaina and get the app from the Apple App Store — you subscribe inside the app through Apple, not on the website (see our Terms of Use). The site is marketing and legal pages plus an optional email/waitlist sign-up; it does not host checkout or process payments. This policy covers cookies on that site.
It does not cover the Amaina iOS app. The app is a native mobile client and generally does not use browser cookies; it uses software development kits (SDKs) from providers like Apple, Google (Firebase), and RevenueCat to run. What data the app collects and how we use it is described in our Privacy Policy, with the full list of providers in our Subprocessors list.
For simplicity, we use "cookies" throughout to mean cookies and similar technologies — web beacons, pixels, tags, and local/session storage.
4.Your choices
You're in control of every optional cookie.
4.1 Via our cookie banner
When you first visit amaina.health, you'll see a cookie banner. Optional cookies (functional, analytics, advertising) do not load until you consent. You can:
- Accept all — turn on all cookie categories.
- Reject optional — only strictly necessary cookies will load.
- Customize — choose by category (functional / analytics / advertising).
You can change your choice anytime by clicking "Cookie settings" in the site footer.
4.2 Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal. Where your browser sends GPC on amaina.health, we treat it as a valid request to opt out of the "sale"/"sharing" of your personal information for advertising, and we apply that to the advertising and analytics cookies on this site.
To be clear, GPC here affects only the web advertising/analytics cookies — there is no health-data "sale" or "share" to opt out of, because we never put health data into cookies and never sell or share health data for advertising (see Section 3.4 and Section 7). For how GPC fits with your other rights, see our website privacy rights notice and Regional Addenda.
4.3 Via your browser
You can also manage cookies in your browser settings:
- Chrome: Settings → Privacy and security → Cookies
- Safari: Settings → Privacy → Manage Website Data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Edge: Settings → Cookies and site permissions → Cookies
Note that blocking strictly necessary cookies may break parts of the site.
4.4 Via the advertising platforms
You can also opt out of personalized advertising directly:
- Meta (Facebook, Instagram): https://www.facebook.com/help/568137493302217
- Google: https://adssettings.google.com
- General opt-out (US): http://optout.aboutads.info or http://optout.networkadvertising.org
5.Do Not Track (DNT)
Some browsers can send a "Do Not Track" (DNT) signal. There's no industry-standard response to DNT, so we currently don't change our behavior based on it. You can still control cookies using the methods in Section 4 — and, unlike DNT, we do honor the Global Privacy Control (GPC) signal (see Section 4.2).
8.Note for EEA / UK visitors (secondary)
We do not currently target the EEA or UK at launch (Amaina is US-only). We include this note only in case that changes.
If we begin offering Amaina in the EEA or UK, we would load non-essential cookies (functional, analytics, advertising) only after you give prior opt-in consent through the banner, consistent with the ePrivacy rules and GDPR/UK GDPR, and you could withdraw consent as easily as you gave it. Strictly necessary cookies would remain exempt from consent. Any personal data collected through cookies would be handled as described in our Privacy Policy and Regional Addenda, with international transfers covered by Standard Contractual Clauses (SCCs) or the UK IDTA.
9.Changes to this policy
When we add, remove, or change cookies, we'll update this Cookie Policy and change the "Effective Date" at the top. For material changes we may re-prompt for consent. The current version is always available at amaina.health/cookies.
10.Contact us
Questions about cookies on amaina.health:
Email: legal@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
This page is written in plain English. If anything is unclear, email legal@smart-it.io — we'll explain.
<!-- INTERNAL — NOT FOR PUBLICATION. Remove this block before the page goes live.
Pre-publication checklist / open items for the site build + health-tech lawyer:
- LINK PLACEHOLDERS (site build). The bracketed cross-references in this doc — Privacy Policy, Terms of Use, Subprocessors, AI Processing Disclosure, HealthKit Data Use, Regional Addenda — are TEMPLATED LINK TARGETS, not live links. Wire each to its real amaina.health URL at publish (e.g. /privacy, /terms, /subprocessors, /ai-disclosure, /healthkit, /regional). Keep the visible target names IDENTICAL to the published document titles so nothing 404s. The Privacy Policy link in particular MUST resolve and stay consistent (Apple 5.1.2 — reviewers compare the privacy policy, this cookie policy, and the App Privacy answers line-by-line). Confirm no bracketed placeholder remains before submission.
- VENDOR SET CONSISTENCY (lawyer + build). The cookie vendor set here must match subprocessors.md and privacy_policy.md exactly: Anthropic (Claude), OpenWeatherMap, Google (Firebase Auth + Firestore + Crashlytics; GA4/Tag Manager; Google Ads/DoubleClick), Amplitude (in-app product analytics, US data region — anonymous usage events gated on the "Usage analytics" toggle, off by default; PLUS server-side RevenueCat->Amplitude subscription-lifecycle events (rc_*), keyed by the Firebase uid, that are NOT gated on the analytics opt-out — contractual/billing; self-assessed, not routed to counsel — Anton 2026-07-24), Apple (Speech / HealthKit / App Store / In-App Purchase), RevenueCat (subscription/entitlement management — receipt + app user id + subscription status, which now also flows server-side to Amplitude; no card data, no health data), and web-only HubSpot + Meta pixels. Amplitude and Firebase Crashlytics are in-app SDKs (build 1.0.0(22)) and MUST appear as subprocessors in subprocessors.md AND privacy_policy.md before publish (Apple 5.1.2 cross-check); the Firebase entry there must read "Auth + Firestore + Crashlytics", not just "Auth + Firestore". Stripe was REMOVED entirely — monetization is now Apple In-App Purchase via StoreKit, managed with RevenueCat; there is no web checkout, so the site sets no payment-processor cookies. Cloudflare was REMOVED (not in the canonical subprocessor set / not disclosed elsewhere) — if a CDN/WAF is in fact used, add it to subprocessors.md AND privacy_policy.md first, then re-add its cookie row here so all three docs match.
- HUBSPOT COOKIES (build). Confirm whether HubSpot forms/tracking actually run on amaina.health marketing pages. If yes, the __hstc / hubspotutk / __hssc rows belong in the analytics category (added as a note in 3.3) and must be consent-gated. If HubSpot is email/CRM only with no on-site script, replace the note with a one-line "HubSpot does not set cookies on this site" (like the Google Search Console note).
- GA4 NAMING.
_ga,_ga_<container-id>,_gid, and the GTM container are all labeled a single vendor ("Google Analytics 4") to avoid reading as two vendors; keep this consistent with how Google is named in subprocessors.md.
-->