ReadMaxxerVISUAL PERFORMANCE TRAINING
DRAFT · NOT YET LAWYER-REVIEWED

This page describes what ReadMaxxer actually does today, in plain language, so it can be reviewed against the real mechanics rather than a boilerplate template. Per FR-168 (docs/02-prd.md) and docs/14-security-privacy-a11y-compliance.md §9.6, no policy text on this page is published for public beta until a qualified lawyer has reviewed it. Nothing here should be relied on as a finished legal document.

Cookie Policy

DRAFT · LAST UPDATED Phase 0 draft

Kept as its own page rather than folded into the Privacy Policy because the consent mechanism itself (what loads, when, and how to change your mind) is specific enough mechanically (docs/12-analytics-plan.md §8.1, docs/14-security-privacy-a11y-compliance.md §9.4) to deserve a page a visitor can find via a short, obvious link from the banner, rather than scrolling through the broader privacy policy to find it.

What we use

  • Strictly necessary (always on):a Firebase sign-in session, so you don’t have to sign in again on every page load, and a local record of your cookie choice itself (so we don’t show you the banner every visit). These are not optional. Declining analytics does not turn these off, because the app cannot function without them.
  • Analytics (only after you accept): PostHog (product analytics: which screens and exercises get used, where people drop off) and Google Analytics (GA4, marketing and acquisition measurement).

We do not use advertising or cross-site tracking cookies of any kind.

How the gate works, exactly

On your first visit, nothing but the strictly-necessary items above loads. A banner asks you to Accept or Decline: same-size buttons, one click either way, nothing pre-checked. Until you choose, the PostHog and GA4 script tags do not exist on the page at all (not merely “loaded but paused”). If you decline, they never load. If you accept, they load at that moment, not before.

Changing your mind

Withdrawing consent costs the same one click as granting it. Use the button below to withdraw immediately on this device.

Not yet built (Phase 0): This page currently changes only the local (this-device) record used to gate script loading. A first-party /api/consent beacon logs the decision server-side for audit purposes, but a queryable, re-offerable consent record tied to your account (users/{uid}/consents) is PRIV-001, not yet built.

CONTROL FIRST. SPEED FOLLOWS.READMAXXER