Cookie Policy

Effective date: March 1, 2026 · Last updated: April 2026

This Cookie Policy explains what cookies BeneFill uses, why we use them, and how you can control them.

1. Essential Cookies

CookiePurposeDuration
sb-*-auth-tokenSupabase authentication session. Required to keep you signed in.Session
sb-*-auth-token-code-verifierPKCE code verifier for secure OAuth flows.Session
fhir_sessionTemporary clinical data summary from MyChart connection. Contains only counts and display names (e.g., medication names), not full medical records. httpOnly — cannot be read by JavaScript.1 hour
fhir_verifier / fhir_statePKCE code verifier and CSRF state for MyChart OAuth flow. httpOnly — automatically cleared after connection completes.10 min

Essential cookies cannot be disabled because they are required for the site to function.

2. Analytics Cookies

CookiePurposeDuration
ph_*PostHog product analytics. Helps us understand how people use BeneFill so we can improve the service. No advertising or cross-site tracking.1 year

Analytics cookies can be opted out (see below).

3. Browser Storage (localStorage)

In addition to cookies, BeneFill stores data in your browser's localStorage. This data never leaves your device unless you create an account and choose to sync it.

KeyPurpose
benefill_profileYour profile data (name, address, medical info) used for form auto-fill.
benefill_ai_consentRecords whether you have consented to AI-assisted form drafting.
benefill_ai_optoutRecords whether you have opted out of AI features entirely.
benefill_free_fill_usedTracks whether you have used your free form fill.

You can clear all browser storage at any time in Settings → Clear browser data, or through your browser's developer tools.

4. No Advertising Cookies

BeneFill does not use advertising cookies, retargeting pixels, or third-party tracking scripts. We do not participate in ad networks or share browsing data with advertisers. Your activity on BeneFill stays on BeneFill.

5. How to Opt Out

Opt out of PostHog analytics

You can opt out of PostHog analytics at any time by enabling the “Do Not Track” setting in your browser. PostHog respects this signal automatically. You can also block the ph_* cookies directly in your browser settings.

Browser cookie settings

Most browsers allow you to block or delete cookies through their settings. Note that blocking essential cookies will prevent you from signing in to BeneFill. Consult your browser's help documentation for instructions on managing cookies.

6. Changes to This Policy

If we add new cookie categories or change our analytics provider, we will update this page and note the revision date above. Material changes will be communicated via email or a notice on our website.

7. Contact Us

Questions about our use of cookies? Contact us at privacy@benefill.ai.