StudyPrep AI / Legal

Cookie Policy

Every cookie and browser storage entry we write, what it is for, and how long it lasts.

Effective: August 11, 2026·Last updated: August 11, 2026

1. The Short Version

No third party sets a cookie on our website during ordinary use. Everything listed here is set by us, on our own domain.

We do not use advertising or tracking cookies at all. There is no advertising network, no retargeting pixel, no social media tracker and no data broker in this product. There is nothing to opt out of on that front because there is nothing there.

The cookies we do set fall into three groups:

  • Necessary. Your signed-in session, and the record of your cookie choices. These cannot be switched off, because switching off the session cookie signs you out and switching off the consent cookie means we have to ask you again on every page.
  • Preferences. Language, currency, theme and layout. These make the site look and read the way you set it. We read them on the server so the page arrives correct rather than flashing a default first.
  • Analytics. Product analytics through PostHog, and only after you accept. Before you accept, PostHog is not loaded at all: it is not merely muted, the code is never fetched.

You choose when the banner first appears, and you can change your mind at any time using the cookie settings link in the footer.

One thing worth knowing that most cookie policies get wrong about themselves: on the web, PostHog stores its state in local storage rather than in a cookie. So if you go looking for an analytics cookie you will not find one, even with analytics turned on. The data is still there, it is just not in a cookie, and a policy that called it a cookie would be misleading you about where to look.

2. Cookies, Local Storage, and Why Both Are Here

A cookie is a small file the site asks your browser to store and send back on the next request. Because it is sent back, the server can read it. That is why our language and theme preferences are cookies: the server needs them to render the first page correctly.

Local storage is a larger store that stays in your browser and is never automatically sent to us. The server cannot read it. We use it for things only the browser needs, such as your study widgets, your todo list and the state of a quiz in progress.

Legally these are usually treated the same way. The ePrivacy rules speak of storing or accessing information on a user's device, not of cookies specifically. So this document lists both, and marks which is which, rather than listing only the cookies and letting the larger store go unmentioned.

3. Necessary Cookies

These cannot be disabled without breaking sign-in or your consent choice.

  • sp_consent (cookie, 1 year). Records the choices you made in the consent banner: which of the three categories you accepted, the version of the consent schema, and the date you decided. Also mirrored into local storage under the same name so that a change in one browser tab takes effect in your other tabs immediately.
  • Supabase authentication session (cookie, lifetime set by Supabase Auth). Keeps you signed in. The name follows the pattern sb-[project]-auth-token, so it varies by environment rather than being a fixed string. Deleting it signs you out.
  • sp-install-id (local storage, until you clear it). A random identifier for this browser installation, used to keep locally stored study state associated with the right device. It is not linked to your identity and it is not sent to an advertising network.

Staff only. Two further cookies exist and you will never receive them unless you are an administrator of this Service: sp-admin-mfa, holding a short-lived second-factor grant, and sp-impersonation, holding a support impersonation grant. They are listed because a complete inventory means complete.

4. Preference Cookies

These remember how you like the site. All of them last one year and all are first-party. Turning them off does not break the Service, it just means it forgets your choices between visits.

  • sp-lang. Your interface language.
  • sp-currency. The currency prices are displayed in.
  • sp-theme and sp-dark. Your colour theme and whether you use dark mode.
  • sp-skin. Your visual Concept, meaning which of the overall design styles you chose.
  • sp-concept-prefs. Your per-Concept colour and font choices.
  • sp-landing-concept and sp-landing-dark. The same two settings for the public landing pages, kept separately so the marketing site and the app can differ.
  • sp-nav-mode, sp-sidebar-collapsed and sp-sidebar-autohide. How your navigation and sidebar are arranged.

We read these on the server. That is the entire reason they are cookies rather than local storage: without them the server would send you a page in the default appearance and your browser would repaint it a fraction of a second later, which is visible and unpleasant.

5. Analytics

Only set if you accept analytics in the consent banner.

  • ph_[key]_posthog (local storage, not a cookie). PostHog's own store, holding an anonymous distinct identifier and queued events. Written only after you consent. If you decline, the PostHog code is never loaded, so nothing is written and no event is sent.

We use PostHog to understand which features are used and where people get stuck. If you withdraw consent later, we instruct PostHog to stop capturing immediately and it stops within the same page view.

Error reporting through Sentry also runs, and this one is worth being precise about. Sentry receives crash reports containing stack traces, the URL and recent interactions. It is currently anonymous: we do not attach your account identity to error reports. Sentry does not set a cookie on our domain.

6. Everything We Keep in Local Storage

None of this is sent to our servers automatically. It stays in your browser until you clear it. It is listed in full because a partial list is worse than none.

Study and productivity tools:

  • sp-todo-items, sp-postit-text, sp-habits, sp-habit-done-[date], sp-daily-goal, sp-hydration-goal, sp-countdown-date, sp-login-streak, sp-study-rounds. Your widgets and study habits.
  • sp-quiz-sessions, sp-exam-in-progress, study_exams, sp-history. Quiz and exam state, so that closing a tab mid-session does not lose your place.
  • sp-pseudo. A display name you chose for yourself locally.

Interface state:

  • sp-widgets-no-autoopen-v1, settings_scroll_[tab], hero-demo-watched. Small reminders of what you have already seen or arranged.
  • sp-nt-glass, sp-nt-lg-active, sp-nt-rain-profiles, sp-landing-lab-overrides. Visual effect settings for particular design Concepts.
  • sp-pet-defaults-off-v1, sp-pet-last-check-in. Desk pet settings.
  • breakzone.version, breakzone.pp2.gallery. Break Zone state.
  • flashcards-qcm-lang, flashcards-qcm-dark, flashcards-qcm-skin. Legacy names for language, dark mode and Concept, kept for compatibility with older stored values. They hold the same information as the cookies above.
  • sp-lang, sp-landing-concept, sp-landing-dark, sp-concept-prefs. Local mirrors of the preference cookies.

Your own API key, if you supply one:

  • gemini_api_key and ai_provider. If you choose to use your own AI provider key, it is stored here, on your device, and sent from your browser to that provider directly. We never receive it and it is never stored on our servers. It is listed prominently because a stored credential you cannot find is worse than one you can. To remove it, clear it in the relevant settings screen, or clear this site's data in your browser.

7. The Mobile Apps

The iOS and Android apps do not use cookies, because they are not web browsers. They store the equivalent information in the operating system's own app storage, which is removed when you uninstall the app.

The categories are the same: your session, your preferences, and analytics if you have accepted it. The Privacy Policy describes what the mobile apps additionally collect, notably push notification tokens and purchase receipts.

Where the apps open a legal document or a support page, they open it in a browser view, and this policy applies to that view.

8. How to Change Your Mind

Use the cookie settings link in the footer of any page. It reopens the consent banner with your current choices shown, and you can change any of them. This is the easiest route and it is the one we would like you to use, because it lets us honour your choice properly rather than guessing from an absent cookie.

Your browser can also do it. Every major browser lets you view, block and delete cookies and site data, usually under Privacy or Site Settings. Be aware that:

  • Deleting the necessary cookies signs you out.
  • Deleting the sp_consent cookie makes the banner appear again, because we no longer know what you chose.
  • Deleting local storage clears your locally held study state, including a quiz in progress and any widget arrangement.
  • Blocking cookies entirely will prevent you from signing in.

Do Not Track and Global Privacy Control. We do not use advertising or cross-site tracking, so there is nothing for these signals to switch off here. We honour your consent banner choice, which is more specific than either signal.

Withdrawing consent does not delete what was already collected. To ask for that, write to support@studyprepai.app, which is a separate right described in the Privacy Policy.

9. Changes to This Policy

We will update this document whenever we add or remove a cookie or a storage key. Because the list is generated from a written inventory of the code rather than from a template, a change to the product is meant to force a change here in the same edit.

Material changes are announced the same way as changes to the Privacy Policy, and the effective date at the top of this page is revised when they take effect.

10. Contact

Questions about this policy, or about anything stored on your device by this Service: support@studyprepai.app.

Related documents: the Privacy Policy at /legal/privacy, the Terms of Service at /legal/terms, and the Refund Policy at /legal/refund.