⚠️ DRAFT — not yet in force. This document is published in draft, for transparency, while our organisation's registration is being completed. It has not yet been reviewed by a solicitor or a Data Protection Officer, and any detail shown as 'to be confirmed' is not yet finalised. We will replace it with a reviewed, signed version.

Cookie & On-device Storage Policy — physmat.org

This policy explains what we store on your device when you and your child use physmat.org, why we store it, and what choices you have. It is written to be read alongside our Privacy Policy, which explains how we handle personal data more generally.

This service is offered in the United Kingdom. It is not offered in the United States at this time.

Who is responsible for your data. Where you sign up directly as a parent, we are the data controller for your and your child's personal data. Where your child's account is provided through a school, the school is the controller and we act as its processor. This does not change what is stored on your device (only the strictly-necessary sign-in tokens described below); the role split is explained in full in the Privacy Policy.


1. What "on-device storage" means

When you use a website, the site can keep small pieces of information on the device you are using (your phone, tablet or computer) through your web browser. "Cookies" are the best-known form of this, but a browser also offers other small storage areas — such as sessionStorage and localStorage — that a website can read and write.

We use this kind of storage only to keep you signed in. We explain exactly what we store, and why, below.


2. What we store on your device

The platform stores the following item(s) in your browser. We do not set any cookies of our own for tracking, and we do not run advertising or analytics trackers (see §3).

What is storedWherePurposeStrictly necessary or consented?Cleared when
Sign-in tokens (Amazon Cognito ID token + refresh token)browser sessionStoragekeep you signed in while you use the app, so you don't have to log in again on every pageStrictly necessarythe browser tab is closed

A few things worth knowing about these sign-in tokens:


3. What we do not use

We want to be clear about what is not present:

These statements describe the platform as built. If that ever changes, this policy will be updated before the change takes effect (see §6).


4. Server-side security logging (not stored on your device)

Separately from anything stored on your device, our content-delivery layer (Amazon CloudFront) records a viewer IP address as part of routine operation — for example to apply rate limiting and to protect the service against abuse. This is an operational and security measure, not a tracking or advertising one, and it is handled on our servers, not stored on your device. How we treat this kind of technical/security log is described in the Privacy Policy.


5. Consent — why we don't ask for it for sign-in storage

Under UK ePrivacy rules, storing information on, or reading information from, a user's device generally requires consent — except where the storage is strictly necessary to provide a service that the user has actively asked for. Keeping you signed in so you can use the platform falls within that "strictly necessary" exemption, so we do not ask for separate consent to store your sign-in tokens.

The sign-in tokens described in §2 are the only thing we store on your device, and they are strictly necessary. We therefore do not currently operate a cookie-consent banner, because there is no non-essential storage to consent to.


6. If we ever add non-essential storage

If in future we want to use any storage that is not strictly necessary — for example analytics, personalisation that isn't required for the core service, or any third-party tool that stores or reads data on your device — we will ask for consent first, present it as off by default, and let you withdraw it at any time. In the app context, where the user is a child, the relevant consent would be sought from the parent/guardian in line with our Privacy Policy and the ICO Children's Code.

We will not silently introduce trackers. Any such change is reflected in this policy before it goes live.


7. How to control storage in your browser

Because the only thing we store is strictly necessary for signing in, blocking it will stop you from being able to use the platform while logged in. You remain in full control of your browser, however, and can:

Signing out of the platform also ends your session.


8. More information

For how we handle personal data overall — including security logs, the optional AI tutor, sub-processors and your rights — please see our Privacy Policy. For questions about this policy, contact mail@physmat.org.


9. Changes to this policy

We may update this policy. If we make a material change — in particular, if we ever introduce any non-essential storage (§6) — we will tell affected users in an age-appropriate way before it takes effect. The "last updated" date at the top shows the current version.