Skip to main content

Cookie Notice

Last updated: 6 September 2026

This notice explains the cookies and similar technologies (such as browser local storage and session storage) that CtrlAltRevise uses, and your choices. It sits alongside our Privacy Policy, which explains how we handle the personal data those technologies may involve. This notice is provided under the Privacy and Electronic Communications Regulations (PECR) and UK GDPR.

What we use

The tables below describe the main cookies and browser storage used by the Platform.

Strictly necessary (no consent required)

These are required for the Platform to work — mainly to sign you in and keep your session secure, and to remember your cookie choice. Blocking authentication cookies prevents sign-in; rejecting optional analytics does not.

WhatTypePurposeRoughly how long
Authentication session cookieCookie (HTTP-only, set by our app via Auth.js)Keeps you signed in to your accountSession / until you sign out or it expires
CSRF / sign-in flow cookiesCookie (HTTP-only, set by Auth.js)Protects the sign-in process against cross-site request forgery and carries the callback URL during sign-inShort-lived, used during authentication
ctrlaltrevise_consent / ctrlaltrevise:analytics-consent:v1Cookie and local storageRemembers your analytics choice, including rejection.Cookie: one year. Local storage: until cleared or changed.

The authentication cookie names are set by the Auth.js library and depend on your connection: on secure (HTTPS) connections they carry a __Secure- or __Host- prefix. We do not rename or repurpose them.

Optional analytics — browser storage

PostHog loads only after you choose Accept allin the banner or Allow analytics below. It uses local storage to remember an analytics identifier and session state so we can understand feature usage and count normalized browser errors. Session replay is currently disabled. Analytics never includes input values, request bodies, console logs, canvas content, or code editors.

KeyPurpose
ctrlaltrevise:analytics-auth:v2Session storage: consented sign-in method and completion state for up to 30 minutes; contains no credentials.
ctrlaltrevise:analytics-identity-changedLocal storage: timestamp signaling sign-out to other tabs; contains no account identifier.
ph_<project-token>_posthogPostHog analytics identity, session, and attribution state; created only after consent.

Functional referral signup cookie

ctrlaltrevise_referral remembers the friend’s invite you chose when continuing signup with Google or Apple. It contains only the referral code, lasts up to 30 minutes, and is cleared after a new social-signup callback. It does not authenticate you or send data to PostHog. Signing up without an invite does not set it.

Functional — browser local storage

These values are written to your browser's localStorage to remember your preferences and workspace state across visits. They are not sent to any third party and do not track you across the web. Deleting them resets the relevant preference to its default.

KeyPurpose
car-themeRemembers your light or dark theme choice
car-accentRemembers your accent colour
car-pseudocode-editor-themeRemembers your code-editor colour theme (light, dark, Dracula, high-contrast)
car-pseudocode-layoutRemembers the panel size proportions in the pseudocode workspace
ctrlaltrevise:dashboard-layout:v1Remembers the order and visibility of widgets on your dashboard

Functional — browser session storage

These values are written to your browser's sessionStorage. They last only for the current browser tab and are deleted automatically when you close the tab; they are never sent to any third party.

KeyPurpose
quiz-state:<question-slugs>Preserves your answer selections during an active quiz session so that a page refresh does not lose your progress

Third-party providers

When you take a payment action we use Stripe, and when you choose social sign-in we use Google or Apple. Those providers may set their own cookies on their own pages as part of completing that action; their use is governed by their own cookie/privacy policies. If you allow analytics, PostHog processes the limited analytics data described below in its EU cloud region.

Analytics and advertising

We use PostHog for optional product analytics and normalized browser error counts. Session replay is currently disabled. It does not load until you actively allow analytics in our consent banner. Rejecting it does not affect the Platform. We do not use analytics for advertising or track you across unrelated websites.

We send page routes with dynamic identifiers removed, feature events without answers or code, browser/device details, acquisition labels, and normalized error categories. Signed-in analytics uses our internal account ID, never your name or email. When signed in, we also save your choice and campaign labels to measure verified signup, trial, first subscription payment, qualified referrals and earned rewards. These outcomes can arrive after you close the page. This analytics choice does not give permission for marketing email. You can change your choice at any time. Accept all enables optional analytics; Reject all keeps it off. Withdrawing consent stops browser collection immediately; while signed in, it also updates your account preference and cancels pending outcome reports. If offline, sign in again with analytics rejected to synchronize that choice:

Analytics is off.

Managing your stored data

You can delete or block cookies and clear local and session storage in your browser's settings, and use private/incognito browsing. Note:

  • Blocking the strictly-necessary cookies will stop you from signing in.
  • Clearing localStorage will reset your theme, accent colour, editor theme, workspace layout, and dashboard layout to their defaults.
  • Clearing sessionStorage (or closing the tab) will discard any unsaved quiz-answer progress for the current session.

Contact

Questions about this notice: ctrlaltrevise@gmail.com.