Legal
Cookie policy
Last updated 7 October 2026
Draft: this page still needs review by a lawyer and is not final legal advice. A clinic’s signed agreement takes precedence over it.
This policy lists every cookie and browser storage item Wareed uses, what each one is for and how long it lasts, and how you control the optional ones.
The short version
- We use essential cookies to sign you in and keep your account secure. They are always on because Wareed cannot work without them.
- We remember preferences you choose, such as language and light or dark mode.
- Analytics cookies (PostHog) run in the clinic workspace only if you accept them. They never include patient information, and you can change your mind at any time.
- We use no advertising cookies and do not track you across other sites. A clinic’s booking page only loads that clinic’s analytics if the patient opts in.
What cookies and local storage are
Cookies are small text files a website stores in your browser. Local storage and session storage do a similar job but stay in your browser and are not sent to our servers. This policy covers all three, on our website, the clinic workspace (app.wareed.io), the platform console, and the pages patients open from a clinic.
Essential: always on
These are needed to sign in, keep your session secure and remember your cookie choice. Under data protection rules they do not need consent.
| Name | What it does | How long |
|---|---|---|
| wareed.session_token | Keeps clinic staff signed in. HttpOnly, so page scripts cannot read it. Set by our API. | Up to 30 days, renewed while you use Wareed |
| wareed.dont_remember | Signs you out when the browser closes if you did not choose to stay signed in. | Until the browser closes |
| wareed-platform.session_token | The same, for Wareed team members in the platform console. | Up to 30 days |
| wareed-consent | Remembers whether you accepted or refused analytics cookies. | 6 months |
In production, the session cookies’ names start with __Secure- and are only sent over HTTPS.
Preferences: set when you choose
These remember choices you make and features you use. Most stay in your browser’s local storage and are never sent to us.
| Name | What it does | How long |
|---|---|---|
| wareed-locale (cookie) | The language you chose on the website, so the right version opens next time. | 1 year |
| wareed-locale, theme | Your language and light or dark mode in the workspace (local storage). | Until you clear it |
| wareed-booking-locale | The language a patient chose on a booking page (local storage). | Until you clear it |
| wareed-pv-locale | The language a patient chose on a pre-visit form (session storage). | Until the tab closes |
| wareed:command-center:*, wareed:home-notes:* | Your recent searches and personal notes on the home page, kept on this device (local storage). | Until you clear it |
| wareed-onboarding-* | Progress through clinic setup and the getting-started checklist (local and session storage). | Until setup ends or the tab closes |
Analytics: only with your consent
In the clinic workspace, the sign-in pages and the platform console, we ask before anything below is set. If you accept, PostHog records which pages and features are used and errors that happen, with your user ID, role and language. It is set up not to collect the text on screen, what you type, or web address details after the page path, and screen recording is turned off, so patient information is not sent. If you refuse, PostHog does not load at all.
| Name | What it does | How long |
|---|---|---|
| ph_<project>_posthog | PostHog product analytics: an anonymous ID and the current session, as a cookie and in local storage. | 1 year |
Pages patients open from a clinic
- Booking pages: a clinic can connect its own Google Analytics or Meta Pixel. They load only if the patient ticks the optional analytics box. Google and Meta then set their own cookies (such as
_ga, up to 2 years, and_fbp, 90 days) under their policies, on the clinic’s behalf. The booking assistant’s conversation stays in session storage until the tab closes. - Pre-visit forms: after the patient confirms their identity, a short-lived access key is kept in session storage so the form stays open. It is deleted when the tab closes or the key expires.
- Patient portal: keeps the patient signed in on that device (local storage) until they sign out.
- None of these pages use Wareed’s product analytics.
Changing your choice
Essential
Keep you signed in, protect your account and remember this choice.
Helps us see which features get used and where errors happen. Never includes patient information.
You have not chosen yet, so analytics is off.
- Use the switch above, or in the clinic workspace open your account menu and choose Cookie settings (Settings → Personalization). Turning analytics off stops it immediately and deletes what PostHog stored in your browser.
- We ask again after 6 months, or sooner if we add a new kind of optional cookie.
- You can also delete or block cookies in your browser settings. Blocking essential cookies will stop you from signing in.
- On a booking page, leave the optional analytics box unticked.
More information
Our privacy policy explains how we handle personal information more broadly. Questions about cookies: privacy@wareed.io. We update this page when the cookies we use change, and change the date at the top.