Skip to content

Cookie Policy

Last updated: August 18, 2026

What are Cookies?

Cookies are small text files that are stored on your device when you visit our website. They help us save your preferences and improve your experience on our website. In addition to standard cookies, we also use "Local Storage" to save settings directly in your browser without transmitting them to our servers.

Cookie Categories

Necessary Cookies & Local Storage

Always active

These technologies are essential for the basic functions of our website and cannot be disabled. They are set automatically and are required for the proper functioning of the website. The localStorage entries listed below are stored only in your browser and are never transmitted to our servers; they are used to remember your preferences (such as your selected city or dismissed notifications), prevent duplicate community actions, and recover unsaved content. The one exception is your cookie decision itself: we also keep a copy of it on our servers, together with its version and a pseudonymised (hashed, truncated) IP and browser identifier, as proof of your consent under Art. 7(1) GDPR.

Cookies:

  • __session (persistent login token, 180 days, HttpOnly/Secure/SameSite=Lax): keeps you signed in across visits without requiring repeated authentication
  • i18next (language preference, 365 days)
  • ll (daily-login marker, 24h, HttpOnly/SameSite=Lax, Secure in production): records that today's login XP was already awarded so it is not granted twice; set only when you are signed in
  • tz (time-zone marker, 1 year, SameSite=Lax, Secure in production, written by your browser): stores your device's IANA time zone (for example Europe/Berlin) so your daily login streak counts calendar days where you are rather than Berlin time; set only when you are signed in, readable by our server on each request
  • stamp_claim (deferred chapter-stamp claim, 24h, signed/HttpOnly/SameSite=Lax): remembers a chapter QR you scanned while signed out so you can claim the stamp after logging in
  • flagged_spots (anonymous flag tracking, 365 days, SameSite=Lax, Secure in production)
  • voted_spots (anonymous vote tracking, 365 days, SameSite=Lax, Secure in production)
  • liked_articles (anonymous like tracking, 365 days, SameSite=Lax, Secure in production)
  • liked_products (anonymous product-like tracking, 365 days, SameSite=Lax, Secure in production)
  • liked_recipes (anonymous recipe-like tracking, 365 days, SameSite=Lax, Secure in production)
  • copied_products (anonymous product-code tracking, 365 days, SameSite=Lax, Secure in production)
  • fascan_unlock (face-age result unlock, 7 days, HttpOnly/SameSite=Lax, Secure in production): carries the unlock key from your confirmation email to the result page, so the key never appears in the address bar
  • push_optin (push opt-in marker, 12 months, SameSite=Lax, Secure in production): remembers that this device switched push notifications on for your account, so the subscription survives a logout
  • lv_vid (anonymous poll voter id, 12 months, HttpOnly/SameSite=Lax, Secure in production): prevents the same browser from voting twice in a public poll; never linked to an account and never sent to analytics
  • iu_grant (event upload permission, 3 hours, HttpOnly/SameSite=Lax, Secure in production): lets you upload photos to one event after you entered that event's upload code
  • __cf_bm (Cloudflare Bot Management, 30 minutes, strictly necessary, set by Cloudflare as our reverse proxy to distinguish humans from bots)

localStorage (browser-only, never sent to our servers):

  • cookie_consent: records your consent decision so we don't prompt you again; your decision expires after 12 months at the latest and we then ask again
  • cookie_preferences: your granular category choices (necessary, analytics) with version and date of your decision
  • userPreciseLocation, locationPermissionGranted, userManuallySelectedCity, userIPDetectedLocation, longevity_selected_city, longevity_ip_location, longevity_precise_location: remember your chosen or detected city so pages are relevant
  • voted_<spotId>, flagged_<spotId>, spotSuggestionNotificationDismissed: prevent duplicate map votes/flags and suggestion spam
  • photoAgeCTA_dismissed: hide the photo age call-to-action after you close it
  • event-result-<sessionId>, event-result-claim-<sessionId>, event-completed-<sessionId>: keep your Longevity Games result on this device and let you claim it for your account after you sign in
  • lastArticlesVisit, lastEventsVisit: power the 'new' dot on nav items
  • logoHomeHintSeen: remembers that the logo-as-home-link hint has already been shown to you
  • wasLoggedIn, push:nativeEnabled: remember that this browser has signed in before (which lets us skip a loading state) and whether you switched push notifications on for this device
  • eventform.lumaHostEmail, eventform.createDraft.v1: remember an event host email address and an unfinished event draft on this device for organizers; clearing the field removes the stored address
  • recent map searches, sidebar layout choices and small interface flags (dismissed prompts and hints, one-time celebration markers, form drafts for organizers): purely local interface state that never leaves your browser

sessionStorage (browser-only, cleared when you close the tab):

  • pending_biometrics: temporary holding of rPPG scan results before you save them
  • event-test-<sessionId>: your in-progress test answers within the tab
  • scan_resting_hr: your measured resting heart rate, kept in the tab only so the VO2max calculator can reuse it after the scan; cleared when you close the tab
  • scan_real_age: the age you entered yourself, kept in the tab so the result can compare it with the estimate

Analytics Cookies

With consent

These technologies help us understand how visitors interact with our website. They are only activated after your explicit consent via the cookie banner (legal basis: § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act) in conjunction with Art. 6(1)(a) GDPR). Before you grant consent, no analytics cookies are set; the Google Consent Mode v2 default is configured as "denied".

Services used:

  • Google Tag Manager (GTM)
  • Google Analytics 4 (loaded via GTM)

Data transfer: USA. Google is certified under the EU-US Data Privacy Framework. Standard Contractual Clauses apply.

Retention: Google Analytics 4 is configured with a 14-month user/event retention. This 14-month period is how long Google keeps the analytics data. It is separate from the lifetime of the _ga cookies in your browser, which is about two years.

Cookies (set only after you consent):

  • _ga (Google Analytics, ~2 years): distinguishes users
  • _ga_<measurement-id> (Google Analytics, ~2 years): persists the session state for the relevant property

Consent Record & Versioning

We store your cookie decision together with its version (current version: 2026-04-18), the date, and a pseudonymised (hashed, truncated) IP and browser identifier solely as evidence of your consent (Art. 7(1) GDPR / § 25 TDDDG). If the scope of consent-requiring processing changes, we obtain your consent again.

No Advertising or Marketing Trackers

We use no advertising or cross-site marketing trackers (no Meta/Facebook pixel, no LinkedIn, TikTok or comparable pixel). Google's advertising features stay disabled – ad_storage, ad_user_data and ad_personalization are kept set to "denied".

Third-Party Services

We use various third-party services to enhance the functionality of our website. These services may collect data such as your IP address and browser information.

Google Services

Google Analytics 4 (loaded via Google Tag Manager). Resources are loaded only after your consent.

Data transfer: USA (EU-US Data Privacy Framework + Standard Contractual Clauses)

Cloudflare (CDN, reverse proxy, DDoS and bot protection)

Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA

Purpose: Cloudflare sits in front of our website as a CDN, reverse proxy and DDoS-protection layer. EEA traffic is primarily terminated at EU edges (Frankfurt/Amsterdam) and then forwarded via HTTPS re-encryption to our Hetzner server in Nuremberg. Cloudflare sets the __cf_bm cookie (30 minutes, strictly necessary) to distinguish humans from bots.

Legal basis: Legitimate interest in security, availability and DDoS protection (Art. 6(1)(f) GDPR) and § 25(2) no. 2 TDDDG for the strictly necessary __cf_bm cookie.

Data transfer: USA (corporate seat). EEA traffic is primarily terminated at EU edges; any onward transfers are safeguarded by EU Standard Contractual Clauses (SCCs) and the Cloudflare Data Processing Addendum (DPA).

Map Tile Providers

Our maps use Leaflet to display tiles from the following providers:

  • CartoDB Voyager (standard view): provided by CARTO (USA / Global CDN). When tiles are loaded, your IP address and standard technical request data are transmitted.
  • Esri ArcGIS World Imagery (satellite view): provided by Esri (USA). Loaded only when you actively switch to satellite mode.

Purpose: Delivery of map tiles for location-based features. Tiles are loaded on the map page and wherever a small map is shown, for example in the navigation menu and on your home page. Map tiles are also stored in your browser's cache by our service worker so the map stays usable offline. This cache holds only map imagery, no personal data, and is cleared when you clear your browser data.

Legal basis: Legitimate interest in providing functional, performant maps (Art. 6(1)(f) GDPR).

Data transfer: USA. Standard Contractual Clauses apply.

Location Detection

We use two methods to determine your location:

1. Server-side IP geolocation (default)

Provider: IPinfo (operated by Kloudend Inc., USA)

Purpose: When you visit our site, we resolve your IP address to a city-level location to show you geographically relevant content (e.g., your nearest chapter). The lookup is performed server-side; we do not store IP-to-location records.

Legal basis: Legitimate interest in providing geographically relevant content (Art. 6(1)(f) GDPR).

Data transfer: USA. Standard Contractual Clauses apply.

2. Browser-based precise geolocation (opt-in)

When you actively click the location button, your browser will ask for your permission to share your precise GPS location with our website. Your location is then stored locally in your browser (localStorage) and is never transmitted to our servers.

Legal basis: Consent (Art. 6(1)(a) GDPR), revocable at any time via your browser settings.

MediaPipe Face Landmarker (rPPG Heart Rate Scanner)

Provider: Google LLC (model file via storage.googleapis.com) and jsDelivr / Prospectone Sp. z o.o. (WASM runtime via cdn.jsdelivr.net)

Purpose: Face region detection for the webcam-based heart rate (rPPG) scanner. Resources are loaded only when you actively start the heart rate scan; no video data is transmitted off your device.

Legal basis: Our legitimate interest in delivering the scanner you actively started (Art. 6(1)(f) GDPR); these are static asset downloads that set no cookies, transmitting only your IP address and browser metadata. The biometric heart-rate analysis itself runs entirely in your browser and is processed only with your separate explicit consent (Art. 9(2)(a) GDPR).

Data transfer: USA (Google Cloud Storage) and Poland / Global CDN (jsDelivr). Only your IP address and browser metadata are transmitted when downloading the library files. Standard Contractual Clauses apply.

Opt-out: Do not use the heart rate scanner feature. No resources are loaded unless you actively start a scan.

Lu.ma (Event Registration)

Provider: Lu.ma Inc. (USA)

Purpose: Embedded event registration and ticketing button on event pages. The Lu.ma script (embed.lu.ma/checkout-button.js) loads automatically when a page with Lu.ma event registration is displayed, so the sign-up window opens instantly. Lu.ma may set its own cookies on your device.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) in the fast, reliable provision of the event registration you request; the script is loaded when the page is displayed.

Data transfer: USA. Lu.ma processes registration and payment data as an independent controller; the relevant data processing is governed by Lu.ma's privacy policy.

Image storage & delivery (AWS S3, EU region Frankfurt)

Provider: Amazon Web Services (AWS S3, EU region Frankfurt)

Purpose: We store and serve user-uploaded images (avatars, banners, article cover images, event photos) via Amazon S3 in the EU. No cookies are set. AWS Inc. (USA) is the corporate parent; an AWS Data Processing Addendum applies and any US-parent access is safeguarded by the EU-US Data Privacy Framework and Standard Contractual Clauses.

Legal basis: Legitimate interest in performant, reliable image delivery (Art. 6(1)(f) GDPR).

Data transfer: Storage and delivery are in the EU (Frankfurt). AWS Inc. (USA) is the corporate parent; any US-parent access is safeguarded by the EU-US Data Privacy Framework and EU Standard Contractual Clauses under the AWS Data Processing Addendum.

Photo Age Test (External AI Service)

When you actively use the Photo Age Test feature, your image is transmitted to an external AI service for age estimation. The image is processed in memory only and is not stored after the response is returned. No cookies are set in connection with this feature.

Legal basis: Consent (Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR for health-related processing).

Full details on data handling are described in our Privacy Policy.

Fonts (Self-Hosted)

All fonts used on our website (Inter, Poppins, Source Serif 4, DM Mono) are self-hosted on our infrastructure in Nuremberg, Germany (Hetzner data center). No connection to Google Fonts servers, Google CDN, or other third-party font providers is made. No data is transmitted for font delivery.

Cookie Management

You can adjust or revoke your cookie settings at any time. Click the button below to reopen the cookie consent banner and update your preferences.

You can also disable cookies entirely in your browser settings. Note that disabling necessary cookies may affect the functionality of our website.

Questions?

If you have questions about our use of cookies and similar technologies, please contact us at info@longevity-germany.com.

For full details on how we process personal data, your rights under the GDPR, and our data processors, please refer to our Privacy Policy.