Skip to main content

Legal

Cookie Policy

How Trace Learn uses cookies and similar browser storage.

  • Effective date: August 3, 2026
  • 19 storage entries

This policy explains the cookies, localStorage, sessionStorage, and short-lived provider tokens used by Trace Learn. Strictly necessary storage supports login, learning-session continuity, anti-abuse checks, and checkout. With an adult visitor’s permission, Google Analytics measures public marketing pages and attribution can connect a campaign visit to coarse funnel milestones such as adult activation, diagnostic completion, trial start, or first payment. Providers do not receive a child identifier, answer, score, skill result, or profile. We do not use personalized-advertising cookies or sell browsing data.

1. Scope

A cookie is a small value stored by a browser and sent with matching web requests. localStorage and sessionStorage stay in the browser and are not sent automatically. This inventory covers storage we create directly and the principal security and payment storage used during the Cloudflare Turnstile and Stripe-hosted parts of a journey.

2. Current storage inventory

Current Trace Learn cookies and browser storage, including provider, purpose, party, and duration
tx-agent-kit.auth-tokenTechnologysessionStorageProviderTrace LearnPurposeKeeps the current adult or learner signed in within one browser tab.First or third partyFirst partyDurationBrowser tab session. Removed on sign-out.
trace-learn.learner-session-modeTechnologysessionStorageProviderTrace LearnPurposeMarks a learner tab so it cannot silently restore an adult session.First or third partyFirst partyDurationBrowser tab session. Removed on sign-out.
tx-agent-kit.refresh-tokenTechnologyHttpOnly, Secure, SameSite=Lax cookieProviderTrace Learn APIPurposeRenews an adult session without exposing the refresh credential to browser scripts.First or third partyFirst party, same-site APIDurationPersistent for up to 30 days. Rotated during refresh and cleared on sign-out or learner login.
tx-agent-kit.auth-refresh-lockTechnologylocalStorageProviderTrace LearnPurposePrevents several open tabs from refreshing the same adult session at once.First or third partyFirst partyDurationNormally removed immediately. Its record expires after 10 seconds; a stale record is discarded on the next refresh attempt.
tx-agent-kit.google-auth.next-pathTechnologylocalStorageProviderTrace LearnPurposeKeeps a safe internal return path while an adult signs in through Google.First or third partyFirst partyDurationRemoved when the Google callback consumes it. An abandoned flow can leave it until the next callback or browser-data clear.
trace-learn:last-runtime-resultTechnologysessionStorageProviderTrace LearnPurposeCarries the latest assessment result summary to the results screen in the current tab.First or third partyFirst partyDurationBrowser tab session, or until overwritten.
trace_learn_events_<session-id>TechnologylocalStorageProviderTrace LearnPurposeTemporarily preserves pseudonymous learning telemetry when a delivery attempt fails, so events are not silently lost.First or third partyFirst partyDurationUp to 3 days and at most 12 sessions. Expired entries are pruned on a later telemetry write.
sidebar:openTechnologylocalStorageProviderTrace LearnPurposeRemembers whether an adult application sidebar is expanded or collapsed.First or third partyFirst partyDurationPersistent until changed or browser data is cleared.
_gaTechnologyCookieProviderGoogle AnalyticsPurposeDistinguishes browsers for aggregate usage measurement on public marketing pages.First or third partyFirst-party cookie set by Google on tracelearn.appDurationPersistent, up to 2 years by default, subject to browser limits.
_ga_J4BCXH23KDTechnologyCookieProviderGoogle AnalyticsPurposeMaintains session state for the Trace Learn GA4 stream on public marketing pages.First or third partyFirst-party cookie set by Google on tracelearn.appDurationPersistent, up to 2 years by default, subject to browser limits.
_gcl_*TechnologyCookieProviderGoogle tagPurposePreserves a consented advertising click so an adult acquisition outcome can be attributed. It is not used for personalized advertising.First or third partyFirst-party cookie set by Google on tracelearn.appDurationPersistent, normally up to 90 days, subject to browser limits.
tracelearn_marketing_consent_v1TechnologylocalStorageProviderTrace LearnPurposeRemembers the adult visitor’s analytics and advertising measurement choices and the policy version used for that choice.First or third partyFirst partyDurationPersistent until changed through Cookie settings, the policy version changes, or browser data is cleared.
tracelearn_marketing_consent_sync_pending_v1TechnologylocalStorageProviderTrace LearnPurposeMarks a consent choice whose server receipt still needs to be synchronized after a temporary connection failure.First or third partyFirst partyDurationRemoved after the server confirms the choice, or when browser data is cleared.
tracelearn_marketing_consent_idTechnologyHttpOnly, Secure, SameSite=Lax cookieProviderTrace Learn APIPurposeLinks the browser to the server-side receipt that records the adult visitor’s current optional-storage choices.First or third partyFirst party, same-site APIDurationPersistent for up to 365 days. Replaced when Cookie settings are changed.
tracelearn_attribution_idTechnologyHttpOnly, Secure, SameSite=Lax cookieProviderTrace Learn APIPurposeStores an opaque key that can link an allowlisted campaign touch to coarse diagnostic, report, trial, checkout, activation, or first-payment milestones. The cookie itself contains no click ID or learner data.First or third partyFirst party, same-site APIDurationPersistent for up to 90 days.
Turnstile response tokenTechnologyEphemeral widget tokenProviderCloudflare TurnstilePurposeLets the API verify that a sign-up attempt passed the anti-bot check.First or third partyThird-party security serviceDurationUp to 5 minutes and single use. The application does not persist it in browser storage.
__stripe_midTechnologyCookie on Stripe-hosted CheckoutProviderStripePurposeAssesses fraud risk for an attempted payment.First or third partyProvider-hosted first-party cookie on checkout.stripe.com; Stripe is our third-party payment serviceDurationPersistent for up to 1 year.
__stripe_sidTechnologyCookie on Stripe-hosted CheckoutProviderStripePurposeAssesses fraud risk during a payment session.First or third partyProvider-hosted first-party cookie on checkout.stripe.com; Stripe is our third-party payment serviceDurationPersistent for up to 30 minutes.
mTechnologyCookie on m.stripe.comProviderStripePurposeHelps Stripe assess fraud risk for an attempted payment.First or third partyProvider-hosted first-party cookie; Stripe is our third-party payment serviceDurationPersistent for up to 2 years.

3. Analytics, Turnstile, and Stripe caveats

Google Tag Manager container GTM-53V6J33S loads on public marketing pages and provides the Trace Learn GA4 stream. Advertising storage is enabled only after the adult visitor permits campaign attribution, while personalized advertising remains disabled. GTM and GA4 do not load on learner, parent, tutor, sign-in, sign-up, or token routes. Google documents _ga and _ga_<container-id> as GA4's first-party cookies, each with a default two-year expiry. Browser privacy controls can shorten that period. We do not send child names, email addresses, raw learner identifiers, answers, or diagnostic details to Google Analytics. See Google's GA4 cookie documentation.

When a public acquisition URL contains an allowlisted campaign value such as a Google or Microsoft click ID or a UTM parameter, the browser sends that value once to the Trace Learn API. The API stores first-touch and last-touch records for up to 90 days and returns only an opaque HttpOnly cookie. Raw click IDs are not placed in localStorage, the analytics data layer, Stripe metadata, or learner records. If the visitor later creates a parent or tutor account, we can link coarse funnel milestones to that adult acquisition record. Provider events can say that a diagnostic was started or completed, a skill report was viewed, a trial started, checkout began, or a first payment succeeded. They do not contain the learner's identity, answers, score, skills, progress, or diagnostic result.

Our current managed Turnstile widget uses Cloudflare's default one-time token and has pre-clearance turned off, so it does not issue a cf_clearance cookie. Cloudflare can use necessary challenge state inside its hosted frame, but it does not expose a stable application-controlled storage key for us to name. Cloudflare documents the token as single-use with a five-minute lifetime. See the Turnstile integration documentation.

Trace Learn redirects an adult to Stripe-hosted Checkout rather than embedding payment fields on our public pages. Stripe can set additional necessary storage depending on the payment method, Link use, fraud checks, location, and any required bank authentication. Stripe's live list is authoritative for its hosted pages. See Stripe Cookie settings.

4. What we do not use

  • No ad-targeting, remarketing, or cross-site profiling cookies.
  • No social-media tracking pixels.
  • No Google Analytics on learner, parent, tutor, sign-in, sign-up, or token routes.
  • No learner names, identifiers, answers, scores, skills, progress, or diagnostic results in advertising attribution.
  • No sale or sharing of browsing data.

5. Your choices

Use the persistent Cookie settings button on an adult public route to review or withdraw optional analytics and attribution consent at any time. A withdrawal is sent to the API immediately so linked measurement and click identifiers are cleared. You can also clear cookies and site data in your browser settings. This signs you out, removes local preferences, and can remove a locally buffered learning session. Blocking essential storage may stop login, sign-up protection, or checkout from working. Browser settings and content-blocking controls can also restrict analytics and attribution storage. To object to public-site measurement or ask us to remove linked attribution data, contact the privacy address below.

6. Controller and contact

Just Understanding Data Ltd is a private limited company registered in England and Wales under company number 12472031. Registered office: 68, Kings Ride, Penn, High Wycombe, Buckinghamshire, HP10 8BP.

Questions about this policy? Email privacy@tracelearn.app. See also our Privacy Policy and GDPR page.