Cookies & storage
Cookie Policy
What Food Info and our analytics partners place on your device, why, and how to control it. This page covers HTTP cookies, browser localStorage, and any similar identifiers used under UK PECR / UK GDPR.
Last updated:
Categories of storage we use
We group the things that are stored on your device into the categories below. Strictly necessary is always on because the site cannot work without it. First-party usage statistics run by default but you can switch them off at any time. Analytics is off until you agree. All of these are controlled from the button in the page footer.
First-party usage statistics
Separately from Google Analytics, we run our own lightweight, cookieless measurement so we can see which pages people reach and which key actions (search, comparing foods, signing up) they use, and therefore where the site is confusing or broken. This is first-party only: the data stays with us and is never shared with advertisers or used to build a marketing profile of you.
Analytics cookies
If you allow analytics, Google Analytics 4 sets the following cookies. Processor: Google Ireland Limited (Gordon House, Dublin 4, Ireland), with Google LLC as a subprocessor in the United States under the UK International Data Transfer Addendum.
_ga- Distinguishes individual visitors so visit counts aren't double-counted. Set on the Food Info domain. Retention: 2 years from last activity.
_ga_<container-id>- Persists session state for Google Analytics 4 (replaces the older
_gid). Retention: 2 years from last activity.
While analytics consent is denied (the default), Google's tag operates in "Consent Mode v2" and the cookies above are not set. We may still receive anonymous, aggregate pings without identifiers; those are used only to estimate total traffic.
Browser local storage (strictly necessary)
The site stores a few small items in your browser's localStorage. These are readable only by Food Info and never sent to advertisers or analytics services. They stay on your device until you clear them or sign out.
- fi-theme
- Your light / dark theme preference, so the page doesn't flash the wrong colours on reload.
Necessary (user preference, exempt from consent under PECR). - foodinfo:auth-v1
- Your access and refresh tokens after you sign in, so you don't have to log in again on every page. Cleared automatically when you sign out.
Strictly necessary (authentication, exempt from consent under PECR). - foodinfo:dropdown-clicks-v1
- A short list of foods you've opened from the search dropdown, so the homepage can offer them as quick chips. Anonymous users keep this on their device only; signed-in users have it synced to their account so the chips follow them between browsers.
Functional, used only to personalise the home page; not shared. - foodinfo:tracker-v1
- Your food-diary entries, the foods you've logged, by date, with serving size in grams and a snapshot of the nutrient values. While signed out this lives only on your device; when you sign in, it is merged into your account so the diary follows you between browsers. Cleared when you sign out and clear browser storage, or by deleting entries from the Tracker page.
Functional (necessary for the Tracker feature you explicitly chose to use; covered by the PECR reg. 6(4) "service explicitly requested" exemption). - foodinfo:consent-v1
- Records the choices you made on the consent banner, whether you allowed analytics, plus the date you decided. We need this so we can keep honouring your choice on later visits without re-asking. Cleared by re-opening the banner and rejecting all, or by clearing browser storage.
Strictly necessary (consent record; PECR reg. 6 exemption, we cannot prove your choice without it).
Third-party storage on Google domains
If you allow analytics, the Google scripts described above set cookies on Google-controlled domains (googletagmanager.com, google.com), not on Food Info's own domain. Those cookies are governed by Google's cookie policy and you can manage them in Google's My Activity dashboard.
If you choose "Sign in with Google", Google additionally sets cookies on accounts.google.com as part of its authentication flow. Those are separate from the analytics cookies and are loaded only when you click Sign in.
Changing your choices
- Click (or the matching link in the site footer) to re-open the consent banner and accept, reject or change individual categories.
- Your decision is stored for 12 months. After that we'll ask again on your next visit.
- Sign out, this removes the auth token immediately. Your consent record survives sign-out so you don't have to re-decide.
- Use your browser's "Clear site data" / privacy controls to wipe everything Food Info has stored (including the consent record, the banner will re-appear on next visit).
- If you have an account and want server-side data deleted too, see the Privacy Policy for how to request erasure.