Tonic Cookie Policy
Last update: April 2026
This Cookie Policy explains how Tonic Easy Medical S.A. (“Tonic“, “we“, “us“) uses cookies and similar tracking technologies across the Tonic platform. It is part of, and should be read together with, the Tonic Privacy Policy – Individual Edition.
- Scope
1.1. This Cookie Policy applies to all Tonic surfaces:
- the Tonic website at tonicapp.io and its subpages;
- the Tonic web application;
- the Tonic mobile applications (iOS and Android);
- the Tonic browser extension for Google Chrome; and
- emails and other communications sent by Tonic that may contain tracking pixels or links.
1.2. Throughout this policy, “cookies” is used as a shorthand for cookies and other similar technologies that store information on, or access information from, Your device. These include browser cookies, local storage, sessionStorage, IndexedDB, mobile-app SDK identifiers, advertising identifiers, and tracking pixels in emails. The legal framework that applies to these technologies (in particular, ePrivacy Directive Article 5(3) and the GDPR) is the same regardless of the technical implementation.
1.3. This Cookie Policy applies to users in the European Economic Area and the United Kingdom.
- What cookies are and why we use them
2.1. Cookies are small files placed on Your device when You visit a website or use an app. They serve a range of purposes, from making the Platform work properly, to remembering Your preferences, to helping us understand how the Platform is used, to enabling marketing and engagement activities.
2.2. We classify cookies and similar technologies into four categories:
- Strictly necessary – required for the Platform to function (login, security, load balancing). These do not require Your consent.
- Functional – improve usability and remember Your preferences. Require Your consent.
- Analytics – help us understand how the Platform is used so we can improve it. Some analytics cookies may be placed under our legitimate interest where the data is anonymised; others require Your consent.
- Marketing – support our sponsored content, customer engagement, and advertising activities. Always require Your explicit consent.
- Legal basis and Your consent
3.1. Strictly necessary cookies are placed under Article 5(3) of the ePrivacy Directive, which permits storage strictly necessary for the provision of a service explicitly requested by the user.
3.2. Functional, analytics, and marketing cookies are placed only after You have given consent, except for analytics cookies that have been demonstrably anonymised, where Tonic may rely on legitimate interest under Article 6(1)(f) GDPR.
3.3. You can give, refuse, or withdraw consent at any time through the cookie banner displayed when You first access the Platform, and at any time afterwards through the “Manage cookies” link in the Platform footer. You can also block cookies through Your browser settings, although this may affect Platform functionality.
3.4. Withdrawal of consent does not affect the lawfulness of cookie use carried out before withdrawal.
- Cookies and tracking technologies we use – website and web application
4.1. The following table summarises the categories of cookies and tracking technologies used on the Tonic website and web application. Specific cookie names and lifetimes are made available through the cookie banner and the “Manage cookies” panel.
| Category | Provider | Purpose | Typical retention |
|---|---|---|---|
| Strictly necessary | Tonic (first-party) | Authentication, session management, security, load balancing, and fraud prevention. | Session or up to 12 months. |
| Functional | Tonic (first-party) | Remembering Your language, display preferences, and similar settings. | Up to 12 months. |
| Analytics | Google Analytics 4 (Google Ireland Ltd.) | Measuring overall traffic, user journeys, and Platform performance. IP addresses are truncated and identifiers are configured to limit retention. | Up to 14 months. |
| Analytics (product) | Mixpanel (Mixpanel Inc., EU data residency where available) | Measuring feature usage and product engagement to improve the Platform. | Up to 14 months. |
| Performance and error monitoring | Datadog (Datadog Inc.) | Detecting errors, performance issues, and security incidents. Limited to operational telemetry. | Up to 13 months. |
| Customer support | Zendesk (Zendesk Inc.) | Supporting the in-app help and ticketing functionality. | Session or up to 12 months. |
| Customer engagement and email/SMS | Braze (Braze Inc.) | Delivering email, SMS, in-app messages, and push notifications, and measuring engagement with these communications. | Up to 24 months. |
| Marketing | Meta Pixel (Meta Platforms Ireland Ltd.) | Measuring the effectiveness of marketing campaigns on Meta platforms and supporting audience-building. | Up to 13 months. |
| Marketing | Google Ads / Google Tag Manager (Google Ireland Ltd.) | Measuring the effectiveness of marketing campaigns on Google services and managing tag deployment. | Up to 13 months. |
4.2. Marketing cookies are placed only after You have given Your explicit, granular consent through the cookie banner. Until You consent, no Meta Pixel, Google Ads, or other marketing tag is loaded.
4.3. Some of the providers above are established outside the European Economic Area or transfer data outside the EEA. Such transfers are made under Chapter V GDPR safeguards (in particular, Standard Contractual Clauses), as further described in the Privacy Policy.
- Tracking technologies in our mobile apps
5.1. The Tonic mobile apps (iOS and Android) do not use browser cookies. Instead, they use software development kits (SDKs), local storage, and platform-level identifiers (such as Apple’s IDFA and Google’s GAID) to provide and improve the apps.
5.2. The following technologies are used in the mobile apps:
| SDK / technology | Provider | Purpose |
|---|---|---|
| Firebase Analytics | Google LLC | Measuring overall app usage, retention, and feature adoption. |
| Mixpanel SDK | Mixpanel Inc. | Measuring feature usage and product engagement to improve the apps. |
| Braze SDK | Braze Inc. | Delivering push notifications, in-app messages, and personalised content; measuring engagement. |
| Datadog mobile SDK | Datadog Inc. | Detecting performance issues, crashes, and security incidents. |
| Apple IDFA / Google GAID | Apple Inc. / Google LLC | Platform-level advertising identifiers controlled by the operating system. |
5.3. On iOS, the use of identifiers is governed by Apple’s App Tracking Transparency (ATT) framework. You will be asked to grant or refuse permission when first using the app.
5.4. On Android, You can control advertising identifiers through Google’s privacy settings on Your device.
5.5. You can control optional analytics and engagement SDKs through the Platform’s in-app privacy settings.
- Tracking technologies in the Chrome extension
6.1. The Tonic Chrome extension uses browser storage (chrome.storage and local storage) to keep You signed in, remember Your preferences, and operate the extension’s features. It does not load third-party marketing or advertising tags.
6.2. Where analytics is used in the extension to measure usage, this is done on the basis of Your consent obtained at first use, in accordance with the same principles set out in clause 3.
- Email and SMS communications
7.1. Emails sent through Tonic’s Braze integration may include tracking pixels and tracked links. These allow us to measure whether emails are opened and which links are clicked, so we can improve the relevance of communications.
7.2. Email tracking pixels are used only for emails that You have consented to receive (such as newsletters or sponsored communications). Transactional and service-related emails (security alerts, account notifications, Privacy Policy updates) may include minimal delivery confirmation but no marketing-related tracking.
7.3. You can prevent email tracking pixels from loading by configuring Your email client to block external images, and You can stop receiving non-essential email communications at any time through the unsubscribe link or Your account settings.
7.4. SMS communications are sent through Braze where applicable. SMS does not contain tracking technologies; only delivery and click-through metadata is captured for tracked links.
- How to manage cookies
8.1. When You first access the Platform, You will see a cookie banner offering: “Accept all”, “Reject all”, and “Manage preferences”. The “Reject all” button is as accessible as the “Accept all” button. By default, no non-essential cookies are placed before You make an active choice.
8.2. You can change Your cookie choices at any time through the “Manage cookies” link available in the Platform footer.
8.3. Most browsers allow You to view, manage, and delete cookies through their settings. Detailed instructions are available from each browser provider:
- Google Chrome – through Settings > Privacy and Security > Cookies and other site data.
- Mozilla Firefox – through Settings > Privacy & Security.
- Apple Safari – through Settings > Privacy.
- Microsoft Edge – through Settings > Cookies and site permissions.
8.4. Blocking strictly necessary cookies may prevent the Platform from working properly. Blocking other cookies is supported and will not affect Your ability to use the Platform’s core features.
8.5. We log Your consent decisions (timestamp, version of this Cookie Policy in force, and Your choice per category) in order to demonstrate compliance with GDPR Article 7.
- “Do Not Track” and Global Privacy Control
9.1. Some browsers offer a “Do Not Track” (DNT) signal or a “Global Privacy Control” (GPC) signal. Where required by applicable law, Tonic will treat such signals as an objection to non-essential cookies and as a request to refuse consent.
- Changes to this Cookie Policy
10.1. Tonic may update this Cookie Policy from time to time, in particular when we add, remove, or replace cookies or providers. Where changes are material – for example, where we introduce a new category of marketing technology – we will request Your fresh consent through the cookie banner.
10.2. Non-material changes will be notified by publishing the updated Cookie Policy on tonicapp.io with the revised version date.
- Contact
For questions about this Cookie Policy or to exercise Your rights, please contact:
Tonic Easy Medical S.A. – Data Protection Officer
Rua do Heroรญsmo 281 Arm. 1, 4300-259 Porto, Portugal
Telephone: +351 223 162 973
Email: dpo@tonicapp.com