Cookie & On-device Storage Policy — physmat.org
This policy explains what we store on your device when you and your child use physmat.org, why we store it, and what choices you have. It is written to be read alongside our Privacy Policy, which explains how we handle personal data more generally.
This service is offered in the United Kingdom. It is not offered in the United States at this time.
Who is responsible for your data. Where you sign up directly as a parent, we are the data controller for your and your child's personal data. Where your child's account is provided through a school, the school is the controller and we act as its processor. This does not change what is stored on your device (only the strictly-necessary sign-in tokens described below); the role split is explained in full in the Privacy Policy.
1. What "on-device storage" means
When you use a website, the site can keep small pieces of information on the device you are using (your phone, tablet or computer) through your web browser. "Cookies" are the best-known form of this, but a browser also offers other small storage areas — such as sessionStorage and localStorage — that a website can read and write.
We use this kind of storage only to keep you signed in. We explain exactly what we store, and why, below.
2. What we store on your device
The platform stores the following item(s) in your browser. We do not set any cookies of our own for tracking, and we do not run advertising or analytics trackers (see §3).
| What is stored | Where | Purpose | Strictly necessary or consented? | Cleared when |
|---|---|---|---|---|
| Sign-in tokens (Amazon Cognito ID token + refresh token) | browser sessionStorage | keep you signed in while you use the app, so you don't have to log in again on every page | Strictly necessary | the browser tab is closed |
A few things worth knowing about these sign-in tokens:
- They are kept in sessionStorage, not localStorage. The practical effect is that they are cleared automatically when you close the browser tab — they do not persist indefinitely on the device.
- They exist so the platform knows you are the logged-in user; without them you could not stay signed in to use the service at all. That is why they are strictly necessary.
- The sign-in token itself carries the account's identity fields used for login (such as the account identifier, group membership, email and an expiry time). How we handle that identity information is described in the Privacy Policy.
3. What we do not use
We want to be clear about what is not present:
- No third-party analytics. We do not use Google Analytics, Sentry, Mixpanel or any similar analytics service in the student or admin app.
- No advertising or tracking. We do not set tracking cookies, advertising cookies, or tracking pixels, and we do not build advertising profiles of you or your child.
- No persistent local storage of your data. The app does not use the browser's localStorage to store your personal data.
These statements describe the platform as built. If that ever changes, this policy will be updated before the change takes effect (see §6).
4. Server-side security logging (not stored on your device)
Separately from anything stored on your device, our content-delivery layer (Amazon CloudFront) records a viewer IP address as part of routine operation — for example to apply rate limiting and to protect the service against abuse. This is an operational and security measure, not a tracking or advertising one, and it is handled on our servers, not stored on your device. How we treat this kind of technical/security log is described in the Privacy Policy.
5. Consent — why we don't ask for it for sign-in storage
Under UK ePrivacy rules, storing information on, or reading information from, a user's device generally requires consent — except where the storage is strictly necessary to provide a service that the user has actively asked for. Keeping you signed in so you can use the platform falls within that "strictly necessary" exemption, so we do not ask for separate consent to store your sign-in tokens.
The sign-in tokens described in §2 are the only thing we store on your device, and they are strictly necessary. We therefore do not currently operate a cookie-consent banner, because there is no non-essential storage to consent to.
6. If we ever add non-essential storage
If in future we want to use any storage that is not strictly necessary — for example analytics, personalisation that isn't required for the core service, or any third-party tool that stores or reads data on your device — we will ask for consent first, present it as off by default, and let you withdraw it at any time. In the app context, where the user is a child, the relevant consent would be sought from the parent/guardian in line with our Privacy Policy and the ICO Children's Code.
We will not silently introduce trackers. Any such change is reflected in this policy before it goes live.
7. How to control storage in your browser
Because the only thing we store is strictly necessary for signing in, blocking it will stop you from being able to use the platform while logged in. You remain in full control of your browser, however, and can:
- Close the tab — this clears the sign-in tokens automatically (they live in sessionStorage).
- Clear site data for physmat.org from your browser's settings or history menu, which removes stored items for the site.
- Adjust your browser's cookie and site-data settings to block or limit storage. Each browser does this differently; your browser's own help pages explain how. Note that blocking storage for this site will prevent you from staying signed in.
Signing out of the platform also ends your session.
8. More information
For how we handle personal data overall — including security logs, the optional AI tutor, sub-processors and your rights — please see our Privacy Policy. For questions about this policy, contact mail@physmat.org.
9. Changes to this policy
We may update this policy. If we make a material change — in particular, if we ever introduce any non-essential storage (§6) — we will tell affected users in an age-appropriate way before it takes effect. The "last updated" date at the top shows the current version.