Legal
Cookie and browser-storage notice
The exact browser storage we use, what each item does, and how long it lasts.
Last updated: 3 September 2026. Version 2026-09-03.
Cookies are small browser files. Local storage and session storage are similar browser technologies. Under Irish rules, optional analytics, session replay and conversion measurement require your consent. They stay off until you accept, rejecting is just as easy as accepting, and changing your mind does not affect your access to the service.
Cookie-free aggregate traffic
Cloudflare Web Analytics counts page views and measures page performance without setting cookies or browser storage. It does not log URL query strings. This aggregate reporting is separate from the optional Google Analytics and PostHog choice below.
Strictly necessary and app-function storage
These items provide a feature you ask for or remember your in-app work. They are not used for advertising or cross-site tracking.
| Name | Technology | Purpose | Duration |
|---|---|---|---|
psp-privacy-preferences | Local storage | Remembers your separate optional analytics and Reddit conversion measurement choices. | Up to 6 months. |
sb-<project-reference>-auth-token | Local storage | Keeps a signed-in account authenticated and refreshes its session securely. | Until logout, account deletion, token expiry or browser data is cleared. |
psp-private-invite | Local storage | Preserves a private research invitation through signup and email confirmation. | Up to 7 days; cleared when redeemed or invalid. |
psp-grade, psp-eb-grade | Local storage | Remembers the grade selected for practice and interview tools. | Until changed or browser data is cleared. |
psp-guides-read | Local storage | Remembers which guides were opened on this device. | Until browser data is cleared. |
psp-heo-taster-visitor-v1 | Local storage | Gives the public HEO example taster a random browser identifier so refreshing cannot restart the single free check. It contains no example text or feedback. | Up to 30 days. |
| Cloudflare Turnstile challenge token | Security token | Checks that a person, rather than an automated script, requested the model-backed HEO feedback. PublicServicePathway validates the token once on the server. Cloudflare processes browser and network signals for this check. | The token expires after 5 minutes and can be used only once. |
psp-ws-*, psp-eb-seed | Local storage | Saves worksheet progress on the device and transfers notes into the experience coach when you ask it to. | Worksheet data remains until browser data is cleared; the transfer item is cleared after use. |
psp-onboarding-skipped | Session storage | Prevents an onboarding redirect loop if a profile save fails. | Until the browser tab/session closes. |
Optional first-party campaign attribution
This item is created only after you accept analytics or Reddit conversion measurement. It is not created when you reject both optional choices.
| Name | Technology | Purpose | Duration |
|---|---|---|---|
psp-acquisition-v1 | Local storage | Keeps a random journey ID plus campaign, source, content and landing-page labels so a consented visit can be connected to signup or purchase. It does not contain application text, coach answers, names or contact details. | Up to 90 days; cleared when both optional choices are rejected or withdrawn. |
Optional Reddit conversion measurement
These items can be created only after you accept the separate “Reddit conversion measurement” choice. The Pixel is limited to selected acquisition pages and the signup and purchase events. It is not loaded inside the application. We do not pass application text, coach answers, names, email addresses, phone numbers or internal account IDs. Reddit automatic email and phone matching is disabled.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
_rdt_uuid, _rdt_cid | Distinguish a browser and attribute a consented page visit, signup or purchase to a Reddit ad. | Reddit's provider-set browser duration. Collection stops and identifiers our site can access are cleared when you withdraw consent. |
Optional analytics and privacy-masked replay
These items are created only after you accept the single “Analytics and privacy-masked replay” choice.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics | Distinguishes one browser from another for visit statistics. | Up to 6 months. |
_ga_* | Google Analytics | Maintains the analytics session and measurement state. | Up to 6 months. |
ph_<project-token>_posthog and related ph_* keys | PostHog Cloud EU | Maintains the optional analytics session, consent state and privacy-masked replay identifiers. | Cleared when you reject or withdraw; consent is requested again after no more than 6 months. |
What session replay can and cannot show
If accepted, PostHog can reconstruct page layout, approved static navigation labels, clicks, pointer movement and scrolling. Every input is masked. Text inside the signed-in app is masked except approved static navigation, and captured page URLs have query strings and fragments removed. We do not enable console-log, network-header or network-body recording. Replay is for diagnosing usability problems, not assessing users.
Changing or withdrawing consent
Use “Privacy choices” in the site footer or app menu at any time. Rejecting stops new optional collection and removes the optional first-party campaign record, analytics and Reddit identifiers, and PostHog browser storage that our site can access. You can also clear site data in your browser. Blocking necessary storage may prevent login or device-saved app features.
More detail about personal-data handling is in our privacy policy.