Cookie Policy
This page is the current inventory of cookies and browser storage used by grademy. It says what each item is for, which category it belongs to, and how long it lasts. We update the inventory when a storage key or third-party integration changes.
Last updated: August 23, 2026
Short version
Sign-in cookies keep the service working. Analytics and referral storage are your call.
There are no advertising trackers on grademy. Optional analytics and referral attribution stay switched off until you actively turn them on. Functional storage holds drafts and choices on your device when you use those features, and can be removed by clearing site data.
Strictly necessary (no consent required)
| Name or prefix | Type | Purpose | Category | Duration |
|---|---|---|---|---|
| Name or prefixsb-<project-ref>-auth-token (may be split into -token.0, -token.1) | TypeCookie | PurposeSupabase authentication session. Keeps you signed in across page loads and lets the server render your own data and nobody else's. | CategoryStrictly necessary | DurationRolling session, refreshed while you stay active. Cleared on sign out. |
| Name or prefixsb-<project-ref>-auth-token-code-verifier | TypeCookie | PurposeHolds the one-time PKCE verifier during an email link or Google sign-in handshake so the login cannot be intercepted. | CategoryStrictly necessary | DurationMinutes. Deleted as soon as the sign-in completes. |
| Name or prefixgrademy_teacher_view | TypeCookie | PurposeRemembers whether a teacher account last used the teacher dashboard or the learning dashboard, so the right one is server-rendered. | CategoryStrictly necessary | Duration365 days |
| Name or prefixgrademy:cookie-consent:v1 | TypeLocal storage | PurposeStores the cookie choice you made on this device, so we do not ask again and so optional categories stay off unless you enabled them. | CategoryStrictly necessary | DurationUntil you clear it with Cookie settings, or clear site data. |
| Name or prefixgrademy_cache_* | TypeLocal storage | PurposeShort-lived offline fallback copy of data you have already loaded, so the app still shows something useful on a flaky connection. | CategoryStrictly necessary | DurationShort-lived cache entries, replaced on next successful load. |
| Name or prefixgrademy:pending-chat-input:v1 | TypeLocal storage | PurposeHolds a tutor message you typed but that has not been delivered yet, so your words are not lost if the connection drops. | CategoryStrictly necessary | DurationUntil the message is delivered or discarded. |
| Name or prefixgrademy:family-invitation-token | TypeSession storage | PurposeCarries a family invitation link through the sign-in flow so the invitation can be accepted once you are authenticated. | CategoryStrictly necessary | DurationUntil the browser tab is closed. |
Functional storage that stays on your device
| Name or prefix | Type | Purpose | Category | Duration |
|---|---|---|---|---|
| Name or prefixgrademy:planner, grademy:planner-runway-sync-day | TypeLocal storage | PurposeKeeps your study planner layout and stops the same day being re-synced repeatedly. | CategoryFunctional | DurationUntil you clear site data. |
| Name or prefixgrademy:learner-memory, grademy:saved-notes, grademy:saved:notes | TypeLocal storage | PurposeCaches learner memory and notes you chose to save, so the tutor sidebar opens instantly with your own material. | CategoryFunctional | DurationUntil you clear site data or delete the notes. |
| Name or prefixmark-draft-content, mark-draft-timestamp | TypeLocal storage | PurposeAutosaves work-in-progress in the marking screen so a refresh does not lose your answer. | CategoryFunctional | DurationUntil the draft is submitted or cleared. |
| Name or prefixstory:settings:<subjectId>, story:speed:<subjectId> | TypeLocal storage | PurposeRemembers reading speed and lesson-story preferences per subject. | CategoryFunctional | DurationUntil you clear site data. |
| Name or prefixgrademy:voice:input-device | TypeLocal storage | PurposeRemembers which microphone you picked for the live tutor. It stores a device label only, never any audio. | CategoryFunctional | DurationUntil you clear site data. |
| Name or prefixgrademy:dock:pinned, command-palette-recent, ambient-audio-preferences, distraction-guard-count, distraction-guard-enabled | TypeLocal storage | PurposeInterface preferences: pinned study dock, recently used commands, focus-timer sound mix, and distraction-guard settings. | CategoryFunctional | DurationUntil you clear site data. |
| Name or prefixgrademy:onboarding:teacher, grademy:teacher-tutorial:autostart, grademy:tutorial:autostart, grademy-pwa-install-dismissed-v1 | TypeLocal storage | PurposeTracks which walkthroughs you have already seen and whether you dismissed the install prompt, so we stop showing them. | CategoryFunctional | DurationUntil you clear site data. |
| Name or prefixpendingPaper, generate-similar-history | TypeSession storage | PurposeCarries an in-progress past-paper upload and recent 'generate similar question' requests between steps of the same flow. | CategoryFunctional | DurationUntil the browser tab is closed. |
| Name or prefixWhiteboard, exam timer, and exam session keys | TypeLocal storage | PurposeSaves your whiteboard strokes, question highlights, timer state, and in-progress exam answers so a crash or refresh does not wipe your attempt. | CategoryFunctional | DurationUntil the attempt finishes or you clear site data. |
| Name or prefixgrademy:tutorial-library, grademy:onboarding-tour | TypeLocal storage | PurposeRemembers tutorial progress and which onboarding tour steps this browser has already completed. | CategoryFunctional | DurationUntil you clear site data. |
| Name or prefixgrademy-saved-content, grademy:gamification | TypeLocal storage | PurposeKeeps content you chose to save and a local cache of progress acknowledgements used by the study interface. | CategoryFunctional | DurationUntil you remove the saved content or clear site data. |
| Name or prefixgrademy:interactive-diagram:v1:*, grademy:conversation-whiteboard:* | TypeLocal storage | PurposeRestores controls you moved in an interactive diagram and whiteboard work attached to a conversation activity. | CategoryFunctional | DurationUntil the activity is cleared or you clear site data. |
Optional: analytics and marketing
| Name or prefix | Type | Purpose | Category | Duration |
|---|---|---|---|---|
| Name or prefixgrademy_public_signup_attribution | TypeCookie | PurposeA 15-minute, HttpOnly, SameSite nonce used only after consent to connect an anonymous signup-intent session to a completed first account. The signed analytics token never appears in an OAuth or fallback URL. | CategoryAnalytics | Duration15 minutes at most. Consumed and cleared after the OAuth admission callback, or cleared on callback failure. |
| Name or prefixgrademy_referral_code | TypeCookie | PurposeRecords that you arrived from a referral link so the person who referred you gets credited when you sign up. | CategoryMarketing | Duration90 days, or until the referral is claimed. |
| Name or prefixgrademy:referral_code, grademy:referral_claimed:<userId>:<code> | TypeLocal storage | PurposeMirrors the referral code on your device and records that it has already been claimed, so it is not claimed twice. | CategoryMarketing | DurationUntil the referral is claimed, then removed. |
| Name or prefixgrademy:analytics-session:v1 | TypeSession storage and server event | PurposeCreates an opaque per-tab ID and obtains a short-lived, server-signed consent token so content-free events can distinguish demo use, login or waitlist intent, and signup completion. It never includes answers, email, names, URLs, referrers, IP addresses, or transcripts. | CategoryAnalytics | DurationNot set unless you consent. The signed token expires after 2 hours; the tab ID is removed when the tab closes or you withdraw consent. Accepted server events are deleted after 13 months. |
How we ask for consent
- Strictly necessary cookies are set as soon as you load the site, because Grademy cannot sign you in or keep your account secure without them. UK law does not require consent for these.
- Analytics and referral-attribution storage are off by default. Nothing is pre-ticked, and closing or ignoring the banner is never treated as consent.
- Functional local storage is created only when you use a feature that needs to remember a draft, saved item, display choice, or in-progress activity. It stays on your device and is not an analytics or advertising opt-in category.
- Accept all and Reject all sit side by side, in the same size and weight, on the first layer of the banner. Refusing is exactly as easy as agreeing.
- Your choice is stored on your device under grademy:cookie-consent:v1 with the version, the timestamp, and the categories you allowed. It is not sent to an ad network.
Changing or withdrawing your choice
- Use the Cookie settings link in the footer at any time. It clears the stored decision and brings the banner straight back so you can choose again.
- You can also clear cookies and site data in your browser settings. Doing so will sign you out and reset your in-progress drafts held on the device.
- Withdrawing consent stops future optional processing. It does not undo processing that already happened lawfully before you withdrew.
Cookies and people under 18
- Grademy is used by school-age learners, so we apply the ICO Age Appropriate Design Code default of high privacy.
- We do not run behavioural advertising, we do not sell or share data with ad networks, and we do not build commercial profiles of learners.
- Marketing storage is limited to referral attribution, so we can tell that a link brought someone to the site. It does not follow anyone across other websites.
Third parties that can set storage
- Supabase (authentication and database) sets the sb-* session cookies described above. These are first-party cookies on grademy.work.
- Vercel (hosting and edge network) may set short-lived operational cookies for routing, load balancing, and abuse protection.
- Stripe sets cookies on its own hosted checkout and billing portal pages for fraud prevention when you go through payment. Those pages are governed by Stripe's own notice.
- Google handles account sign-in when you choose Google. YouTube can receive a user-requested search and can set its own storage when a video player is loaded; its own privacy notice then applies.
- We do not embed advertising pixels, social media trackers, or cross-site retargeting tags on grademy.work.
Questions, or want your data removed?
The privacy policy explains what we hold, how long we keep it, who processes it, and how to exercise your UK GDPR rights, including erasure. Email privacy@grademy.work and we will respond within one month.