Skip to main content

Cookie Policy

Effective date: August 3, 2026

This policy explains the cookies, localStorage, sessionStorage, and short-lived provider tokens used by Trace Learn. Strictly necessary storage supports login, learning-session continuity, anti-abuse checks, and checkout. With an adult visitor’s permission, Google Analytics measures public marketing pages and attribution can connect a campaign visit to coarse funnel milestones such as adult activation, diagnostic completion, trial start, or first payment. Providers do not receive a child identifier, answer, score, skill result, or profile. We do not use personalized-advertising cookies or sell browsing data.

1. Scope

A cookie is a small value stored by a browser and sent with matching web requests. localStorage and sessionStorage stay in the browser and are not sent automatically. This inventory covers storage we create directly and the principal security and payment storage used during the Cloudflare Turnstile and Stripe-hosted parts of a journey.

2. Current storage inventory

Current Trace Learn cookies and browser storage, including provider, purpose, party, and duration
IdentifierTechnologyProviderPurposeFirst or third partyDuration
tx-agent-kit.auth-tokensessionStorageTrace LearnKeeps the current adult or learner signed in within one browser tab.First partyBrowser tab session. Removed on sign-out.
trace-learn.learner-session-modesessionStorageTrace LearnMarks a learner tab so it cannot silently restore an adult session.First partyBrowser tab session. Removed on sign-out.
tx-agent-kit.refresh-tokenHttpOnly, Secure, SameSite=Lax cookieTrace Learn APIRenews an adult session without exposing the refresh credential to browser scripts.First party, same-site APIPersistent for up to 30 days. Rotated during refresh and cleared on sign-out or learner login.
tx-agent-kit.auth-refresh-locklocalStorageTrace LearnPrevents several open tabs from refreshing the same adult session at once.First partyNormally removed immediately. Its record expires after 10 seconds; a stale record is discarded on the next refresh attempt.
tx-agent-kit.google-auth.next-pathlocalStorageTrace LearnKeeps a safe internal return path while an adult signs in through Google.First partyRemoved when the Google callback consumes it. An abandoned flow can leave it until the next callback or browser-data clear.
trace-learn:last-runtime-resultsessionStorageTrace LearnCarries the latest assessment result summary to the results screen in the current tab.First partyBrowser tab session, or until overwritten.
trace_learn_events_<session-id>localStorageTrace LearnTemporarily preserves pseudonymous learning telemetry when a delivery attempt fails, so events are not silently lost.First partyUp to 3 days and at most 12 sessions. Expired entries are pruned on a later telemetry write.
sidebar:openlocalStorageTrace LearnRemembers whether an adult application sidebar is expanded or collapsed.First partyPersistent until changed or browser data is cleared.
_gaCookieGoogle AnalyticsDistinguishes browsers for aggregate usage measurement on public marketing pages.First-party cookie set by Google on tracelearn.appPersistent, up to 2 years by default, subject to browser limits.
_ga_J4BCXH23KDCookieGoogle AnalyticsMaintains session state for the Trace Learn GA4 stream on public marketing pages.First-party cookie set by Google on tracelearn.appPersistent, up to 2 years by default, subject to browser limits.
_gcl_*CookieGoogle tagPreserves a consented advertising click so an adult acquisition outcome can be attributed. It is not used for personalized advertising.First-party cookie set by Google on tracelearn.appPersistent, normally up to 90 days, subject to browser limits.
tracelearn_marketing_consent_v1localStorageTrace LearnRemembers the adult visitor’s analytics and advertising measurement choices and the policy version used for that choice.First partyPersistent until changed through Cookie settings, the policy version changes, or browser data is cleared.
tracelearn_marketing_consent_sync_pending_v1localStorageTrace LearnMarks a consent choice whose server receipt still needs to be synchronized after a temporary connection failure.First partyRemoved after the server confirms the choice, or when browser data is cleared.
tracelearn_marketing_consent_idHttpOnly, Secure, SameSite=Lax cookieTrace Learn APILinks the browser to the server-side receipt that records the adult visitor’s current optional-storage choices.First party, same-site APIPersistent for up to 365 days. Replaced when Cookie settings are changed.
tracelearn_attribution_idHttpOnly, Secure, SameSite=Lax cookieTrace Learn APIStores an opaque key that can link an allowlisted campaign touch to coarse diagnostic, report, trial, checkout, activation, or first-payment milestones. The cookie itself contains no click ID or learner data.First party, same-site APIPersistent for up to 90 days.
Turnstile response tokenEphemeral widget tokenCloudflare TurnstileLets the API verify that a sign-up attempt passed the anti-bot check.Third-party security serviceUp to 5 minutes and single use. The application does not persist it in browser storage.
__stripe_midCookie on Stripe-hosted CheckoutStripeAssesses fraud risk for an attempted payment.Provider-hosted first-party cookie on checkout.stripe.com; Stripe is our third-party payment servicePersistent for up to 1 year.
__stripe_sidCookie on Stripe-hosted CheckoutStripeAssesses fraud risk during a payment session.Provider-hosted first-party cookie on checkout.stripe.com; Stripe is our third-party payment servicePersistent for up to 30 minutes.
mCookie on m.stripe.comStripeHelps Stripe assess fraud risk for an attempted payment.Provider-hosted first-party cookie; Stripe is our third-party payment servicePersistent for up to 2 years.

3. Analytics, Turnstile, and Stripe caveats

Google Tag Manager container GTM-53V6J33S loads on public marketing pages and provides the Trace Learn GA4 stream. Advertising storage is enabled only after the adult visitor permits campaign attribution, while personalized advertising remains disabled. GTM and GA4 do not load on learner, parent, tutor, sign-in, sign-up, or token routes. Google documents _ga and _ga_<container-id> as GA4's first-party cookies, each with a default two-year expiry. Browser privacy controls can shorten that period. We do not send child names, email addresses, raw learner identifiers, answers, or diagnostic details to Google Analytics. See Google's GA4 cookie documentation.

When a public acquisition URL contains an allowlisted campaign value such as a Google or Microsoft click ID or a UTM parameter, the browser sends that value once to the Trace Learn API. The API stores first-touch and last-touch records for up to 90 days and returns only an opaque HttpOnly cookie. Raw click IDs are not placed in localStorage, the analytics data layer, Stripe metadata, or learner records. If the visitor later creates a parent or tutor account, we can link coarse funnel milestones to that adult acquisition record. Provider events can say that a diagnostic was started or completed, a skill report was viewed, a trial started, checkout began, or a first payment succeeded. They do not contain the learner's identity, answers, score, skills, progress, or diagnostic result.

Our current managed Turnstile widget uses Cloudflare's default one-time token and has pre-clearance turned off, so it does not issue a cf_clearance cookie. Cloudflare can use necessary challenge state inside its hosted frame, but it does not expose a stable application-controlled storage key for us to name. Cloudflare documents the token as single-use with a five-minute lifetime. See the Turnstile integration documentation.

Trace Learn redirects an adult to Stripe-hosted Checkout rather than embedding payment fields on our public pages. Stripe can set additional necessary storage depending on the payment method, Link use, fraud checks, location, and any required bank authentication. Stripe's live list is authoritative for its hosted pages. See Stripe Cookie settings.

4. What we do not use

  • No ad-targeting, remarketing, or cross-site profiling cookies.
  • No social-media tracking pixels.
  • No Google Analytics on learner, parent, tutor, sign-in, sign-up, or token routes.
  • No learner names, identifiers, answers, scores, skills, progress, or diagnostic results in advertising attribution.
  • No sale or sharing of browsing data.

5. Your choices

Use the persistent Cookie settings button on an adult public route to review or withdraw optional analytics and attribution consent at any time. A withdrawal is sent to the API immediately so linked measurement and click identifiers are cleared. You can also clear cookies and site data in your browser settings. This signs you out, removes local preferences, and can remove a locally buffered learning session. Blocking essential storage may stop login, sign-up protection, or checkout from working. Browser settings and content-blocking controls can also restrict analytics and attribution storage. To object to public-site measurement or ask us to remove linked attribution data, contact the privacy address below.

6. Controller and contact

Just Understanding Data Ltd is a private limited company registered in England and Wales under company number 12472031. Registered office: 68, Kings Ride, Penn, High Wycombe, Buckinghamshire, HP10 8BP.

Questions about this policy? Email [email protected]. See also our Privacy Policy and GDPR page.