Cookies and device storage
Version dated 4 September 2026
This page explains what EatWell keeps on your device and reads back from it. It covers cookies and the similar things a browser provides — local storage and session storage — because the same rules apply to them.
Some of it exists to do something you asked EatWell to do. Some of it is convenience: it remembers a prompt you dismissed or a tip you have already seen, so it is not repeated. EatWell does not claim that everything on this page is strictly necessary, and the convenience items are still being assessed.
This page names what is stored and why. It never shows the value of a sign-in token, and nothing you have logged appears here.
Everything listed here is set by EatWell (first party). Nobody else sets or reads storage through EatWell: there is no advertising, no analytics product and no tracking pixel.
Cookies EatWell sets
These are set by the EatWell service when you sign in or start using it as a guest. Apart from the stay-signed-in preference they are HTTP-only, so the pages you see cannot read them, and in the hosted service they are marked Secure and travel only over HTTPS. A browser-level check of every attribute in the deployed service has not been completed yet; this page will be corrected if it finds anything different.
- ew_id_token — Proves who you are on each request once you have signed in. One hour, or 30 days if you chose to stay signed in.
- ew_access_token — Authorises the requests your session makes. One hour, or 30 days if you chose to stay signed in.
- ew_refresh_token — Lets a session be renewed without asking you to sign in again. 30 days.
- ew_session — Identifies the signed-in session on the server. 30 days.
- ew_remember_me — Records whether you asked to stay signed in, so a renewed session keeps the length you chose. It holds only a one or a zero. 30 days.
- ew_sid — The signed guest session, so entries you log before creating an account belong to you rather than to nobody. 30 days.
Storage that supports something you asked for
Each of these exists because of something you did — signing in, choosing to log as a guest, agreeing to the core data use, or starting a conversation. Unless it says otherwise, it stays on your device until you or your browser clear it.
- eatwell-consent-guest — The data choice you made as a guest, which version of the notice you were shown and when you made it. It is what lets EatWell act on your choice and show that you made it. Kept until you clear it.
- eatwell_anon_session_id — The identifier for your guest session, so what you log as a guest is not lost and can move with you if you create an account. Kept until you clear it or sign in.
- eatwell_anonymous_session — The record used to move guest entries into a new account at the moment you create one. Removed once you are signed in.
- eatwell_auth_token — Despite its name it holds only the marker “authenticated”, never a token value; the real sign-in tokens are in the HTTP-only cookies above. Removed when you sign out.
- eatwell_user — Your email address, account identifier and signed-in flag, so the app can show your account without asking the server on every page. Removed when you sign out.
- eatwell_login_flow — While a sign-in code is outstanding: the address it was sent to, whether you asked to stay signed in, and when it was sent. It stops a page refresh losing your place. Discarded after ten minutes.
- eatwell_is_new_user, eatwell_auth_success — Short-lived markers that decide where you land immediately after signing in. Removed once you have landed, and when you sign out.
- eatwell-chat-messages — Session storage. The messages in the logging conversation you are currently in, so switching page does not empty it. Gone when you close the tab.
Convenience storage still being assessed
These make EatWell faster or less repetitive. They are not obviously essential, so they are listed separately and are still being assessed. None of them is used for advertising, measurement or building a profile of you, and none of them is shared.
- eatwell-portion-control-seen — That you have seen the portion control once, so it is not explained again.
- eatwell-meal-estimate-received — That one meal estimate has come back on this device — nothing about the meal or the estimate itself. It is why the add-to-home-screen offer waits until you have had something useful before it appears at all.
- eatwell-add-to-home-screen-dismissed — That you chose “Don’t show again” for the add-to-home-screen offer, so it stops asking.
- eatwell-add-to-home-screen-snoozed — Session storage. That you chose “Not now” for the add-to-home-screen offer, so it stays away for the rest of this visit. Gone when you close the tab.
- eatwell:weight-log-banner-dismissed — Session storage. That you dismissed the weight reminder today. Gone when you close the tab.
What EatWell does not do
EatWell sets no advertising cookie, runs no analytics product, embeds no third-party tag or pixel, and does nothing to follow you across other websites.
Because nothing here is used for advertising or measurement, you are not being shown a consent banner for it. That is not the same as saying every item is strictly necessary: the convenience list above is under review, and this page will change if that review changes the answer.
Clearing it, and what stops working
Signing out clears the account items. Your browser's own settings clear all of it, including the cookies, and closing the tab clears the session-storage items on their own.
- Clear the sign-in cookies and you cannot stay signed in; you can still read the public pages and log as a guest.
- Clear the guest items and entries you logged as a guest can no longer be linked to you, so they cannot be moved into an account.
- Clear the consent record and EatWell has to ask for your data choice again before it can log anything.
- Clear the convenience items and nothing is lost — a prompt you already dismissed, or a tip you already saw, may simply appear again.
Questions about this
Email privacy@simplyeatwell.co.uk with anything about what EatWell keeps on your device.
The privacy notice explains what happens to your data once it reaches EatWell, and the beta terms set out the rest of the arrangement.