This page lists every cookie and similar storage that usanafoundation.org, or something embedded on it, can place in your browser. We keep it by hand, so it describes what the site actually does rather than what a scanner guessed. Cookies come in three groups. Necessary cookies make the site work, including the donation and contact forms. Statistics cookies help us understand how the site is used. Marketing cookies belong to the videos and social posts embedded on some blog stories and on the Who we are page. No optional cookies are set until you choose. Two things do happen when a page opens, before you choose: Google Analytics receives a cookieless count of the page view, which includes your IP address (see Statistics), and the home page shows a background video from Vimeo with Vimeo's do not track setting on (see Necessary).
Last updated September 23, 2026. Cookie list version 1.
Where your choice is stored
Your choice lives in your own browser, in one small first-party cookie called usf_consent. It records which groups you allowed, when you decided, and which version of this list you saw. Nothing about your choice is sent to or stored on our servers. If you want a copy for your own records, open Cookie settings and press Download a copy: your browser saves a short text file with your choices, the date and time, and the version of this list. To change your mind at any time, use the Cookie settings link at the bottom of every page, including the search and page not found pages.
Browser privacy signals
If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as an answer of only necessary cookies and do not show you the banner. You can still opt in later through Cookie settings, and that explicit choice is the one we follow.
Necessary
Needed for the site to work: our own cookie that remembers your choices, and the cookies set inside the Donorbox donation form and the Airtable contact form so you can give or write to us. Those two forms load only on the donate pages and the contact page. Always on.
| Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
usf_consent | USANA Foundation (first party) Provider details | Remembers which cookie groups you allowed, when you decided, and which version of this list you saw. It is also the record shown under Your current choices in Cookie settings.Used on: All pages, once you have made a choice | 12 months | HTTP cookie |
Donorbox session cookies | Donorbox (third party) Provider details | Keep the donation form working while you give. Set inside the Donorbox frame, not by our pages.Used on: Donate pages (5 pages)Checked 2026-09-22: Donorbox's privacy policy confirms it uses cookies and that Stripe and PayPal process payments, but does not name its cookies or their lifetimes. | Session | HTTP cookie |
__stripe_mid | Stripe (inside the Donorbox form) (third party) Provider details | Fraud prevention. Helps Stripe judge whether a card payment attempt is genuine. Needed to donate by card.Used on: Donate pages (5 pages)Checked 2026-09-22 against Stripe's cookie settings page: Essential, 1 year. | 1 year | HTTP cookie |
__stripe_sid | Stripe (inside the Donorbox form) (third party) Provider details | Fraud prevention for the current payment session.Used on: Donate pages (5 pages)Checked 2026-09-22 against Stripe's cookie settings page: Essential, 30 minutes. | 30 minutes | HTTP cookie |
m | Stripe (inside the Donorbox form) (third party) Provider details | Fraud detection. Helps Stripe assess the risk of a payment attempt. Set from m.stripe.com.Used on: Donate pages (5 pages)Checked 2026-09-22 against Stripe's cookie settings page: Essential, 2 years. | 2 years | HTTP cookie |
_GRECAPTCHA | Google reCAPTCHA (inside the Donorbox form) (third party) Provider details | Tells real donors from automated bots before a payment is accepted.Used on: Donate pages (5 pages)Checked 2026-09-22: Google's reCAPTCHA FAQ names _GRECAPTCHA as a necessary cookie for risk analysis but does not state a lifetime; 6 months is Google's commonly published value. | 6 months | HTTP cookie |
cf_clearance | Cloudflare (inside the Donorbox form; also set by the Vimeo player on the home page) (third party) Provider details | Proof that your browser passed Cloudflare's bot check, so you are not asked again.Used on: Donate pages (5 pages) and the home pageChecked 2026-09-22: Cloudflare describes cf_clearance as strictly necessary; the 1 year lifetime is from Vimeo's player cookie list. | 1 year | HTTP cookie |
__cf_bm | Cloudflare (inside the Donorbox form, the Airtable contact form and the Vimeo player on the home page) (third party) Provider details | Cloudflare's bot manager, which tells people from automated traffic.Used on: Donate pages, the contact page and the home pageChecked 2026-09-22: Cloudflare states it expires after 30 minutes of inactivity and is strictly necessary. | 30 minutes | HTTP cookie |
_cfuvid | Cloudflare (inside the Donorbox form; also set by the Vimeo player on the home page) (third party) Provider details | Lets Cloudflare tell apart visitors who share one internet address, for rate limiting.Used on: Donate pages (5 pages) and the home pageChecked 2026-09-22 against Cloudflare's cookie reference and Vimeo's player cookie list (session). | Session | HTTP cookie |
player_clearance | Vimeo (home page background video) (third party) Provider details | Bot prevention for the Vimeo video player that shows the home page background video.Used on: Home page (background video), set on page openChecked 2026-09-22: Vimeo lists it as an essential security cookie that is set even when the player's dnt (do not track) option is on. The home page video is loaded with dnt on (Elementor passes it because the section's settings carry background_privacy_mode, which the site adds at serve time), so Vimeo's analytics cookie vuid and its player cookie are not set. This cookie exists because the home page loads the video on page open; the banner does not control it. | 7 days | HTTP cookie |
NRBA_SESSION | New Relic (inside the Donorbox form) (third party) Provider details | Performance monitoring for the Donorbox form, so Donorbox can see when their form is slow or failing.Used on: Donate pages (5 pages)Reported by the previous scanner inside the Donorbox frame; not re-verified against New Relic's documentation on 2026-09-22. Spot-check in a browser before cutover. | Session | HTTP cookie |
Airtable session cookies (including AWSALB and AWSALBCORS) | Airtable (third party) Provider details | Keep the contact form working and route your form session to the right Airtable server.Used on: Contact page (1 page)Checked 2026-09-22: Airtable's cookie policy describes a strictly necessary category but does not name cookies; its linked cookie list is a JavaScript page that could not be read. AWSALB and AWSALBCORS are Amazon load balancer cookies with a default life of 7 days. | Up to 7 days | HTTP cookie |
hmt_id | hCaptcha (inside the Airtable contact form) (third party) Provider details | Tells real people from bots on the contact form.Used on: Contact page (1 page)Checked 2026-09-22 against hCaptcha's privacy policy cookie table: strictly necessary, 30 days. | 30 days | HTTP cookie |
__cflb | Cloudflare (inside the Airtable contact form, via hCaptcha) (third party) Provider details | Keeps your form session on the same server while you fill it in.Used on: Contact page (1 page)Checked 2026-09-22: Cloudflare states from several seconds up to 24 hours; hCaptcha lists it as strictly necessary. | Up to 24 hours | HTTP cookie |
The donation form and the contact form are frames from Donorbox and Airtable. The cookies inside them are set by Donorbox, Stripe, Google reCAPTCHA, Cloudflare, New Relic, Airtable and hCaptcha, not by our pages, and they are needed to donate or to send us a message. We list them so you know they exist, but we cannot switch them off without breaking the forms. The background video at the top of the home page comes from Vimeo and loads when the page opens, with Vimeo's do not track setting on: Vimeo sees your IP address and sets only the security cookies listed here, not its analytics cookie. Those load on page open and the cookie banner does not control them. Fonts are loaded from Google Fonts on every page; Google Fonts sets no cookies, but Google does see your IP address when your browser fetches the font files.
Statistics
Help us see how the site is used: which pages are read, from which countries, on what kind of device. Google Analytics sets these cookies only after you say yes. Before that, Google still receives a cookieless count of each page view; that request carries your IP address and browser details, which Google says it does not use to identify you.
| Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
_ga | Google Analytics (first party) Provider details | Tells one visitor from another so we can count visits and returning visitors. Set only after you accept statistics cookies.Used on: All pages (live site only; analytics is off on the staging address)Checked 2026-09-22: Google states 2 years, used to distinguish users. | 2 years | HTTP cookie |
_ga_XS1J1JCEZ2 | Google Analytics (first party) Provider details | Keeps the pages you view in one visit together as a session. Set only after you accept statistics cookies.Used on: All pages (live site only)Checked 2026-09-22: Google states 2 years for _ga_<container-id>, used to persist session state. | 2 years | HTTP cookie |
Turning Statistics off tells Google Analytics to stop and deletes its cookies at once. Vimeo, which hosts the home page background video, is not in this group: that video loads with Vimeo's do not track setting on, so Vimeo sets no analytics cookie for it. Its security cookies are listed under Necessary.
Marketing
Videos and posts embedded from YouTube, Facebook, Instagram and Issuu on some of our blog stories and on the Who we are page. Those companies set cookies to recognise you across websites and, for their own purposes, to personalise what you see, including advertising on their platforms. We do not run ads. On this site each embed stays covered by a Load button until you accept marketing cookies or press the button; pressing Load on one item loads only that item unless you also tick the remember box under it.
| Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
VISITOR_INFO1_LIVE | YouTube (Google) (third party) Provider details | Estimates your connection speed and can enable personalised recommendations on YouTube based on past views.Used on: The 12 pages that embed a YouTube video (11 blog stories and Who we are)Checked 2026-09-22 against Google's cookie list: expires 6 months after last use. Independent tests report YouTube can set this cookie on youtube-nocookie.com as well, which is why the video stays covered until you choose. | 6 months | HTTP cookie |
YSC | YouTube (Google) (third party) Provider details | Makes sure requests within one browsing session come from you and not from another site.Used on: The 12 pages that embed a YouTube video (11 blog stories and Who we are)Checked 2026-09-22 against Google's cookie list: lasts for the browsing session. | Session | HTTP cookie |
PREF | YouTube (Google) (third party) Provider details | Stores player preferences such as autoplay choices and player size.Used on: The 12 pages that embed a YouTube video (11 blog stories and Who we are)Checked 2026-09-22 against Google's cookie list: expires 8 months from last use. | 8 months | HTTP cookie |
__Secure-ROLLOUT_TOKEN | YouTube (Google) (third party) Provider details | Lets YouTube launch new features and measure them when other identifiers cannot be used.Used on: The 12 pages that embed a YouTube video (11 blog stories and Who we are)Checked 2026-09-22 against Google's cookie list: 6 months. | 6 months | HTTP cookie |
__Secure-YENID | YouTube (Google) (third party) Provider details | Helps YouTube detect spam, fraud and abuse, and supports Google's advertising purposes on YouTube.Used on: The 12 pages that embed a YouTube video (11 blog stories and Who we are)Checked 2026-09-22 against Google's cookie list: 13 months, to detect spam, fraud and abuse and for advertising purposes. Google lists the older __Secure-YEC with the same lifetime and purpose alongside it. | 13 months | HTTP cookie |
yt-remote-device-id and related yt-remote entries | YouTube (Google) (third party) Provider details | Browser storage the YouTube player uses to remember the device and any connected screens.Used on: The 12 pages that embed a YouTube video (11 blog stories and Who we are)Local storage written by the embedded player, widely reported by cookie scanners; Google's cookie list does not describe it. Spot-check in a browser before cutover. | Persistent (until cleared) | Browser storage |
fr | Facebook (Meta) (third party) Provider details | Meta's main advertising cookie. Recognises your browser to deliver, measure and improve ads on Meta's platforms.Used on: The 12 blog stories that embed a Facebook video or postMeta's cookie policy confirms it sets cookies on other companies' websites that embed Meta content. Its per-cookie table is a JavaScript page that could not be read by an automated check on 2026-09-22; 90 days is the lifetime Meta publishes for fr. Spot-check in a browser before cutover. | 3 months | HTTP cookie |
datr | Facebook (Meta) (third party) Provider details | Identifies the browser for security, for example to detect suspicious logins and bots.Used on: The 12 blog stories that embed a Facebook video or postLifetime per Meta's published list (400 days); table not machine-readable on 2026-09-22. Spot-check in a browser before cutover. | 400 days | HTTP cookie |
sb | Facebook (Meta) (third party) Provider details | Identifies the browser for security and to remember account chooser settings.Used on: The 12 blog stories that embed a Facebook video or postLifetime per Meta's published list (400 days); table not machine-readable on 2026-09-22. Spot-check in a browser before cutover. | 400 days | HTTP cookie |
csrftoken | Instagram (Meta) (third party) Provider details | Security token that protects Instagram's embed against forged requests.Used on: The 45 blog stories that embed Instagram postsInstagram is covered by Meta's cookie policy, whose per-cookie table could not be read by an automated check on 2026-09-22; 1 year is the lifetime Meta publishes. Spot-check in a browser before cutover. | 1 year | HTTP cookie |
mid | Instagram (Meta) (third party) Provider details | Machine identifier that ties the embed to your browser.Used on: The 45 blog stories that embed Instagram postsInstagram has requested lifetimes as long as 10 years for this cookie; modern browsers cap any cookie at 400 days. Spot-check in a browser before cutover. | Up to 400 days | HTTP cookie |
ig_did | Instagram (Meta) (third party) Provider details | Device identifier used when showing embedded Instagram posts.Used on: The 45 blog stories that embed Instagram postsInstagram has requested lifetimes as long as 10 years for this cookie; modern browsers cap any cookie at 400 days. Spot-check in a browser before cutover. | Up to 400 days | HTTP cookie |
datr | Instagram (Meta) (third party) Provider details | Identifies the browser for security on Instagram's embed.Used on: The 45 blog stories that embed Instagram postsSame cookie name as Facebook's, set on the instagram.com domain. Lifetime per Meta's published list. | 400 days | HTTP cookie |
iutk | Issuu (third party) Provider details | Recognises your device and remembers which Issuu documents you have read.Used on: The 2 annual report stories that embed the Issuu readerIssuu's cookie list page rendered only navigation on 2026-09-22 and its privacy policy names no cookies; description per third-party cookie databases. Spot-check in a browser before cutover. | Not published by Issuu (long-lived) | HTTP cookie |
mc | Issuu (third party) Provider details | Short-lived identifier used by Issuu's reader analytics.Used on: The 2 annual report stories that embed the Issuu readerLifetime per third-party cookie databases; not readable from Issuu's own page on 2026-09-22. | 1 day | HTTP cookie |
__qca | Quantcast (via the Issuu reader) (third party) Provider details | Audience measurement and advertising analytics for Issuu.Used on: The 2 annual report stories that embed the Issuu readerLifetime per third-party cookie databases; not readable from Issuu's own page on 2026-09-22. | 13 months | HTTP cookie |
YouTube videos use youtube-nocookie.com, YouTube's privacy-enhanced player, which stops your viewing here from shaping your YouTube recommendations, but YouTube can still set cookies once the video runs. The covered box for a video is drawn by our own page, not a preview picture from the provider, so nothing is fetched from these companies until you choose. Lifetimes are the values each company publishes and can change without notice; where a company does not publish one, we say so.