Cookies

Cookie and Local Storage Policy

Effective date: 25 July 2026

The website currently uses only strictly necessary authentication and security cookies and functional first-party storage. These are needed for sign-in, session security, saving permitted browser state and providing the functions you request. They are not used for advertising or cross-site behavioural tracking. Consent is not requested for strictly necessary technology. Blocking these essential cookies may prevent sign-in and saved progress from working.

What we use

Name or patternProviderPurposeSession / persistentApproximate durationStrictly necessary
sb-<project-ref>-auth-token (and its chunked parts)SupabaseKeeps you signed in and secures your sessionPersistentGoverned by the Supabase session and refresh-token configuration; refreshed while you stay signed in and cleared on sign-outYes
PKCE code-verifier cookie (set briefly during sign-in and email links)SupabaseCompletes secure sign-in, email confirmation and password recoverySessionShort-lived; used only to complete the sign-in exchangeYes
assessments-aced:<module>:attempts (browser local storage)First-party (this website)Saves your recent practice attempts in your browser, including for guest usePersistentRemains until you clear it or clear your browser storageFunctional

We do not publish fixed expiry numbers for the Supabase cookies because their lifetime is controlled by the Supabase session configuration rather than hard-coded in the site.

What we do not use

Future changes

If we ever introduce non-essential analytics or advertising technology, we will add a consent mechanism and request your permission before it is enabled.

For more about how we handle personal information, see the Privacy notice.