Cookies and browser storage
Draft for review — not effective terms or a completed privacy notice.
Version 2026-10-10-draft-3 · Updated 10 October 2026
Storage used for sign-in, preferences, navigation and registration sources.
Sign-in and access
The browser and identity provider store information needed to recognise sign-in and protect sessions. Private testing can use a classcanvas_testing HttpOnly access cookie for up to seven days when password access is enabled; Sites owner sign-in uses its own controls. Google Firebase stores sign-in state on the live platform. Provider storage must be inventoried in the deployed environment.
Preferences and work
Local storage holds device/session identifiers and preferences such as appearance, toolbar order, pen width and pane layout. Session storage holds navigation positions, device views and registration choices. Some local preferences remain until cleared or overwritten. They are not all deleted by signing out.
Any browser-resident assignment draft or recovery information must be included in a shared-device review. Signing out and clearing this site’s browser storage can remove local state; clearing storage does not delete work already saved on the server.
Optional source tracking
The current acquisition script captures campaign labels and a referring hostname into session storage, potentially for up to 24 hours within a tab, then sends them with registration. It does not use an external analytics script. Its purpose and PECR consent or exception must be assessed before use; first-party storage is not automatically exempt.
No cookie banner is being presented as proof of compliance. A deployed browser inventory, purpose classification and any necessary consent or opt-out controls remain release requirements. Essential security storage is assessed separately from optional tracking.