Privacy Policy
What we collect, why, who else sees it, how long we keep it, and how to make us delete it.
Every cookie and every piece of browser storage this site uses, and what each one is for.
This site does not run advertising pixels, it does not build a profile of you across other websites, and it does not share anything with an ad network. What follows is the complete list of what it does store, which is short enough to print in full.
`token` — your signed-in session. Stored in your browser and sent with each request so that the server knows who you are. Without it you cannot stay signed in. It is removed when you sign out.
`settings` — your interface preferences: language, theme, which panels are open. Stored locally so the page does not flicker back to its defaults on every load.
`frko_visitor` — a random identifier, created by your browser the first time you arrive, used to count visits and to know which campaign brought them. It contains no personal information and does not identify you; it identifies a browser, and it is replaced if you clear your storage.
`frko.theme` and `frko.pendingPrompt` — remembered for the length of your visit only. The first records which campaign page you arrived on so that the coaching matches it; the second holds the question you typed before you had an account, so that signing up does not lose it.
`frko_referral_code` — set only if you arrived through a friend's invitation link, so that the invitation is still known when you register.
Our network edge provider sets a short-lived security cookie (typically `__cf_bm`) to tell human visitors from automated ones. It is required for the site to serve you safely and expires within half an hour.
When you pay, you are taken to the payment provider's own checkout, which sets its own cookies under its own policy. We do not control them and cannot read them.
Blocking cookies and site storage in your browser settings will stop the measurement described above, and the marketing pages will continue to work exactly as before. Signing in requires the session token, so blocking everything will prevent you from using the product itself — that is a limit of how sign-in works, not a choice we have made.