Cookie and Local Storage Policy
Effective date: 25 July 2026
The website currently uses only strictly necessary authentication and security cookies and functional first-party storage. These are needed for sign-in, session security, saving permitted browser state and providing the functions you request. They are not used for advertising or cross-site behavioural tracking. Consent is not requested for strictly necessary technology. Blocking these essential cookies may prevent sign-in and saved progress from working.
What we use
| Name or pattern | Provider | Purpose | Session / persistent | Approximate duration | Strictly necessary |
|---|---|---|---|---|---|
sb-<project-ref>-auth-token (and its chunked parts) | Supabase | Keeps you signed in and secures your session | Persistent | Governed by the Supabase session and refresh-token configuration; refreshed while you stay signed in and cleared on sign-out | Yes |
| PKCE code-verifier cookie (set briefly during sign-in and email links) | Supabase | Completes secure sign-in, email confirmation and password recovery | Session | Short-lived; used only to complete the sign-in exchange | Yes |
assessments-aced:<module>:attempts (browser local storage) | First-party (this website) | Saves your recent practice attempts in your browser, including for guest use | Persistent | Remains until you clear it or clear your browser storage | Functional |
We do not publish fixed expiry numbers for the Supabase cookies because their lifetime is controlled by the Supabase session configuration rather than hard-coded in the site.
What we do not use
- No Google Analytics.
- No Google Tag Manager.
- No Meta Pixel.
- No TikTok Pixel.
- No Microsoft Clarity.
- No advertising cookies or cross-site trackers.
Future changes
If we ever introduce non-essential analytics or advertising technology, we will add a consent mechanism and request your permission before it is enabled.
For more about how we handle personal information, see the Privacy notice.