Cookie Notice
Last updated: 6 September 2026
This notice explains the cookies and similar technologies (such as browser local storage and session storage) that CtrlAltRevise uses, and your choices. It sits alongside our Privacy Policy, which explains how we handle the personal data those technologies may involve. This notice is provided under the Privacy and Electronic Communications Regulations (PECR) and UK GDPR.
What we use
The tables below describe the main cookies and browser storage used by the Platform.
Strictly necessary (no consent required)
These are required for the Platform to work — mainly to sign you in and keep your session secure, and to remember your cookie choice. Blocking authentication cookies prevents sign-in; rejecting optional analytics does not.
| What | Type | Purpose | Roughly how long |
|---|---|---|---|
| Authentication session cookie | Cookie (HTTP-only, set by our app via Auth.js) | Keeps you signed in to your account | Session / until you sign out or it expires |
| CSRF / sign-in flow cookies | Cookie (HTTP-only, set by Auth.js) | Protects the sign-in process against cross-site request forgery and carries the callback URL during sign-in | Short-lived, used during authentication |
| ctrlaltrevise_consent / ctrlaltrevise:analytics-consent:v1 | Cookie and local storage | Remembers your analytics choice, including rejection. | Cookie: one year. Local storage: until cleared or changed. |
The authentication cookie names are set by the Auth.js library and depend on your connection: on secure (HTTPS) connections they carry a __Secure- or __Host- prefix. We do not rename or repurpose them.
Optional analytics — browser storage
PostHog loads only after you choose Accept allin the banner or Allow analytics below. It uses local storage to remember an analytics identifier and session state so we can understand feature usage and count normalized browser errors. Session replay is currently disabled. Analytics never includes input values, request bodies, console logs, canvas content, or code editors.
| Key | Purpose |
|---|---|
| ctrlaltrevise:analytics-auth:v2 | Session storage: consented sign-in method and completion state for up to 30 minutes; contains no credentials. |
| ctrlaltrevise:analytics-identity-changed | Local storage: timestamp signaling sign-out to other tabs; contains no account identifier. |
| ph_<project-token>_posthog | PostHog analytics identity, session, and attribution state; created only after consent. |
Functional referral signup cookie
ctrlaltrevise_referral remembers the friend’s invite you chose when continuing signup with Google or Apple. It contains only the referral code, lasts up to 30 minutes, and is cleared after a new social-signup callback. It does not authenticate you or send data to PostHog. Signing up without an invite does not set it.
Functional — browser local storage
These values are written to your browser's localStorage to remember your preferences and workspace state across visits. They are not sent to any third party and do not track you across the web. Deleting them resets the relevant preference to its default.
| Key | Purpose |
|---|---|
| car-theme | Remembers your light or dark theme choice |
| car-accent | Remembers your accent colour |
| car-pseudocode-editor-theme | Remembers your code-editor colour theme (light, dark, Dracula, high-contrast) |
| car-pseudocode-layout | Remembers the panel size proportions in the pseudocode workspace |
| ctrlaltrevise:dashboard-layout:v1 | Remembers the order and visibility of widgets on your dashboard |
Functional — browser session storage
These values are written to your browser's sessionStorage. They last only for the current browser tab and are deleted automatically when you close the tab; they are never sent to any third party.
| Key | Purpose |
|---|---|
| quiz-state:<question-slugs> | Preserves your answer selections during an active quiz session so that a page refresh does not lose your progress |
Third-party providers
When you take a payment action we use Stripe, and when you choose social sign-in we use Google or Apple. Those providers may set their own cookies on their own pages as part of completing that action; their use is governed by their own cookie/privacy policies. If you allow analytics, PostHog processes the limited analytics data described below in its EU cloud region.
Analytics and advertising
We use PostHog for optional product analytics and normalized browser error counts. Session replay is currently disabled. It does not load until you actively allow analytics in our consent banner. Rejecting it does not affect the Platform. We do not use analytics for advertising or track you across unrelated websites.
We send page routes with dynamic identifiers removed, feature events without answers or code, browser/device details, acquisition labels, and normalized error categories. Signed-in analytics uses our internal account ID, never your name or email. When signed in, we also save your choice and campaign labels to measure verified signup, trial, first subscription payment, qualified referrals and earned rewards. These outcomes can arrive after you close the page. This analytics choice does not give permission for marketing email. You can change your choice at any time. Accept all enables optional analytics; Reject all keeps it off. Withdrawing consent stops browser collection immediately; while signed in, it also updates your account preference and cancels pending outcome reports. If offline, sign in again with analytics rejected to synchronize that choice:
Managing your stored data
You can delete or block cookies and clear local and session storage in your browser's settings, and use private/incognito browsing. Note:
- Blocking the strictly-necessary cookies will stop you from signing in.
- Clearing
localStoragewill reset your theme, accent colour, editor theme, workspace layout, and dashboard layout to their defaults. - Clearing
sessionStorage(or closing the tab) will discard any unsaved quiz-answer progress for the current session.
Contact
Questions about this notice: ctrlaltrevise@gmail.com.