Cookie Policy

Last Updated: August 24, 2026

Overview

LynxFlow Health uses only essential cookies that are strictly necessary for the operation, security, and HIPAA compliance of our healthcare platform. We do not use analytics, tracking, advertising, or marketing cookies of any kind.

What Are Essential Cookies?

Essential cookies are cookies that are strictly necessary for the website to function and provide the services you have requested. These cookies are exempt from consent requirements under GDPR Article 6(1)(f) and similar regulations because they serve a legitimate interest in maintaining security and functionality.

Essential Cookies We Use

1. Authentication Cookies

Purpose: Maintain secure user sessions and verify user identity

Provider: Supabase (our authentication service)

Data Stored: Encrypted session tokens, access tokens, refresh tokens

Duration: Session-based (cleared when you log out)

Why Essential: Required to keep you securely logged in and protect your protected health information (PHI) in compliance with HIPAA regulations

2. Security Activity Cookie

Cookie Name: last_activity

Purpose: Track user activity to enforce automatic logout after inactivity

Data Stored: Unix timestamp of your last activity (e.g., 1733154000000)

Duration: 1 hour (3600 seconds)

Inactivity Timeout: 10 minutes of inactivity triggers automatic logout

Why Essential: Required for HIPAA compliance to prevent unauthorized access if you step away from your workstation. This protects patient data from unauthorized viewing.

Why Can't I Disable These Cookies?

These cookies cannot be disabled because they are strictly necessary for:

  • Security: Protecting your account and preventing unauthorized access
  • Authentication: Verifying your identity and maintaining your secure session
  • HIPAA Compliance: Meeting federal healthcare privacy and security requirements
  • Platform Functionality: Enabling core features like automatic logout for security

Without these cookies, you would not be able to securely access the platform or protect sensitive health information as required by law.

What We Don't Use

LynxFlow Health is committed to privacy and does NOT use:

  • ❌ Analytics or tracking cookies (e.g., Google Analytics)
  • ❌ Advertising or marketing cookies
  • ❌ Third-party tracking technologies
  • ❌ Social media cookies or plugins
  • ❌ Performance or preference cookies

HIPAA & Privacy Compliance

As a healthcare technology platform handling Protected Health Information (PHI), LynxFlow Health maintains strict HIPAA compliance requirements:

  • All authentication cookies are encrypted and transmitted over secure HTTPS connections
  • Session timeouts enforce the HIPAA Security Rule's automatic logoff requirements (§164.312(a)(2)(iii))
  • No PHI is ever stored in cookies
  • Cookies are used solely for technical security and session management purposes

Legal Basis

Under GDPR Article 6(1)(f), we have a legitimate interest in using essential cookies to ensure the security and proper functioning of our platform. Under HIPAA, these security measures are required to protect electronic Protected Health Information (ePHI).

Managing Browser Cookies

While you can configure your browser to block or delete cookies, doing so will prevent you from accessing LynxFlow Health, as these cookies are essential for the platform to function securely.

If you log out or clear your browser cookies, you will need to log in again with your credentials.

This Cookie Policy is part of our comprehensive Privacy Policy and Terms of Service. By using LynxFlow Health, you acknowledge and accept our use of essential cookies as described above.