Cookies and similar technologies
Evidence Based Change Builder cookies policy
This policy applies to the Evidence Based Change Builder website at evidencebasedchange.com, and to related app and Studio services where they are used to deliver Evidence Based Change Builder projects.
Last updated: July 2, 2026
What we use today
The public website at evidencebasedchange.com does not currently set optional analytics, marketing, advertising, social media, or tracking cookies.
If you access related app or Studio services, strictly necessary cookies and browser storage may be used on app.lifemaxxr.com or studio.lifemaxxr.com to provide sign-in, route protection, secure session handling, and requested app state.
Strictly necessary cookies for related app services
These cookies are not set by the public website at evidencebasedchange.com. They are used on related app and Studio services to provide the secure sign-in and protected-app experience the user has asked for.
| Name |
Used on |
Purpose |
Duration |
| __Secure-better-auth.session_token / better-auth.session_token |
app.lifemaxxr.com |
Keeps a signed-in NavHub session secure and allows the participant app to recognize the user. |
Up to 7 days from issue, refreshed during active use. |
| __Secure-better-auth.session_data / better-auth.session_data |
app.lifemaxxr.com |
Caches a short-lived, non-secret session snapshot so the app can restore signed-in state quickly. |
Up to 5 minutes. |
| activity_runtime_auth_handoff |
studio.lifemaxxr.com and protected runtime routes |
Stores a verified first-party runtime handoff after sign-in so Studio and protected runtime areas can continue without relying on a URL token. |
Until token expiry, currently about 5 minutes by default. |
Similar technologies for related app services
EU and UK rules also cover browser storage such as localStorage and sessionStorage when it stores or accesses information on a user device. The storage listed below is used on related app and Studio services, not by the public website at evidencebasedchange.com.
| Technology |
Used on |
Purpose |
Duration |
| localStorage keys used by NavHub and Activity Runtime |
app.lifemaxxr.com and studio.lifemaxxr.com |
Preserves in-progress work, selected context, user-requested settings, and app state such as drafts, onboarding status, and session snapshots. |
Varies by key. Some items last until cleared, others are replaced as the user continues. |
| sessionStorage keys used for runtime handoff and route state |
app.lifemaxxr.com |
Keeps short-lived route and handoff data available only for the current browser session. |
Usually until the browser tab or session ends. |
Consent position
At launch, our intent is to limit cookies and similar technologies to those that are strictly necessary for authentication, security, routing, and preserving user-requested app state where app or Studio services are used. The public website does not currently rely on optional analytics or marketing cookies.
If we later introduce non-essential analytics, advertising, social media tags, cross-site tracking, or optional personalization storage for EU or UK users, we will ask for consent before those technologies are set or read.
What we do not use today
- We do not currently use advertising cookies.
- We do not currently use social media pixels.
- We do not currently use optional analytics or tracking cookies.
- We do not currently use third-party cross-site profiling tools.
Managing your choices
- You can block or delete cookies in your browser settings. If you block necessary cookies, some parts of the service may not work properly.
- You can clear local storage and session storage from your browser site-data controls.
- Signing out of the participant app clears the active server-backed sign-in state.
- If blocking necessary cookies or storage breaks sign-in or protected routes, some parts of the service will not work correctly.
Policy updates
We will update this page if the cookies or similar technologies we use materially change, especially if we add optional analytics, marketing, or third-party integrations for EU or UK users.
Return to the Evidence Based Change Builder site or read the GDPR and data handling page.