Cookie Policy
Version 1.0 · Effective 1 October 2026
1. What this covers
This policy lists everything Prodemy stores in your browser — cookies, and the two similar technologies called local storage and session storage — what each one is for, how long it lasts, and who else can see it. Every item we set is named below. If something is not on this page, we do not set it.
It sits alongside our Privacy Policy, which covers the wider question of what we do with your information.
2. The four categories
Only the first is on by default. The other three stay off until you turn them on, wherever in the world you are.
Essential Always on
Keeps you signed in, remembers your place in a form, and protects your account from fraud. The Platform cannot work without these, so they are always on.
Preferences Off unless you turn it on
Remembers small choices so you do not have to make them again — the view you last used, a notice you dismissed, and the details that let the app still be useful when you have no connection.
Analytics Off unless you turn it on
Counts how many members use Prodemy as an installed app rather than in a browser tab. It uses a random identifier, is never shared with anyone else, and is never used for advertising.
Error diagnostics Off unless you turn it on
If something goes wrong, records a replay of what happened on screen so we can fix it. Text is hidden and images are blocked, and a recording is only sent when there is an actual error.
3. Cookies we set
__Secure-next-auth.session-token
- Set by
- Prodemy
- Category
- Essential
- Lasts
- 30 days, or until you sign out
Keeps you signed in as you move between pages. Without it you would have to sign in again on every page.
__Host-next-auth.csrf-token
- Set by
- Prodemy
- Category
- Essential
- Lasts
- The browser session
Protects your account by making sure a request that changes something really came from you and not from another site.
__Secure-next-auth.callback-url
- Set by
- Prodemy
- Category
- Essential
- Lasts
- The browser session
Returns you to the page you were trying to reach after you sign in.
prodemy_td
- Set by
- Prodemy
- Category
- Essential
- Lasts
- 14 days (7 days for club owners and admins)
Remembers that you already passed two-step sign-in on this device, so you are not asked for a code every time.
Only when you use two-step sign-in
prodemy_su
- Set by
- Prodemy
- Category
- Essential
- Lasts
- A few minutes
Records that you have just re-confirmed your identity, so a sensitive change can go ahead without asking twice.
Only around a sensitive action
coach_invite_token
- Set by
- Prodemy
- Category
- Essential
- Lasts
- Until you finish signing up
Carries a coach invitation through sign-up so you are joined to the club that invited you.
Only when you follow a coach invitation link
pdy_consent
- Set by
- Prodemy
- Category
- Essential
- Lasts
- 12 months (6 months in the UK and the EEA)
Stores the choices you made here, so we can honour them and stop asking.
pdy_cid
- Set by
- Prodemy
- Category
- Essential
- Lasts
- 12 months
A random identifier that lets us record which choices belong to this browser. It contains nothing about you, and without it we could not remember that you said no.
__stripe_mid
- Set by
- Stripe
- Category
- Essential
- Lasts
- 1 year
Used by our payment processor to detect fraudulent card use while you are paying.
Payment pages only
__stripe_sid
- Set by
- Stripe
- Category
- Essential
- Lasts
- 30 minutes
Used by our payment processor to detect fraudulent card use during a single payment.
Payment pages only
4. Things we store in your browser that are not cookies
Local storage and session storage hold small values on your device. Session storage is cleared when you close the tab; local storage stays until it is removed.
prodemy_chatbot_session
- Where
- Session storage
- Category
- Essential
Keeps one support-chat conversation together for the length of the visit. Cleared when the tab closes.
prodemy_support_nudge_seen
- Where
- Session storage
- Category
- Essential
Remembers that the support prompt was already offered in this visit, so it is not shown twice.
prodemy:pwa-recovered-at
- Where
- Session storage
- Category
- Essential
One-shot guard that stops the installed app reloading in a loop while recovering from a bad update.
mcc_onboarding_state
- Where
- Session storage
- Category
- Essential
Keeps your progress through sign-up if you refresh the page part-way, so you do not start again. Cleared when the tab closes.
prodemy_2fa_nudge_dismissed
- Where
- Session storage
- Category
- Essential
Remembers that you dismissed the two-step sign-in reminder, so it is not repeated during this visit.
prodemy-upcoming-view
- Where
- Local storage
- Category
- Preferences
Remembers whether you last viewed your schedule as a list or a calendar.
prodemy:slow-connection-dismissed-at
- Where
- Local storage
- Category
- Preferences
Remembers that you dismissed the slow-connection notice, so it stays dismissed.
prodemy:pwa-install-dismissed-at
- Where
- Local storage
- Category
- Preferences
Remembers that you dismissed the install prompt, so it is not offered again for a week.
promotion_banner_dismissed
- Where
- Local storage
- Category
- Preferences
Remembers that you dismissed the account-upgrade notice, so it stays dismissed.
prodemy.offlineHints.v1
- Where
- Local storage
- Category
- Preferences
Stores your name and a few links so the offline page can still be useful with no connection.
prodemy:pwa-device-id
- Where
- Local storage
- Category
- Analytics
A random identifier used only to count how many members use Prodemy as an installed app rather than a browser tab.
prodemy:pwa-usage-last-ping
- Where
- Local storage
- Category
- Analytics
Records when that count was last reported, so it is reported at most once every few hours.
5. Who else is involved
Stripe
- Category
- Essential
Takes payments and checks them for fraud. Only used on payment pages, and only because you asked to pay. Privacy policy
Cloudflare Turnstile
- Category
- Essential
Checks that the person using the public support chat is not an automated script. It sets no cookie of its own — it looks at browser signals. Privacy policy
Vercel
- Category
- Essential
Hosts the Platform. Sets infrastructure cookies needed to route your requests to a working server. Privacy policy
Sentry
- Category
- Error diagnostics
Receives error reports so we can fix faults. With Error diagnostics turned on it also receives a replay of the screen when an error happens, with text hidden and images blocked. Recordings are kept for 90 days. Privacy policy
We do not sell or share your personal information, and we do not use advertising or cross-site tracking technologies of any kind.
6. Changing your mind
Open Your Privacy Choices at any time. The same link is in the footer of every page and at the bottom of your dashboard.
Turning a category off also deletes what it had stored. We do not simply stop writing — the values already on your device are removed as soon as you save.
You can also clear or block this data through your browser settings. Blocking the strictly necessary items will stop the Platform working: you will not be able to stay signed in.
7. Global Privacy Control
If your browser sends a Global Privacy Control signal, we honour it automatically and leave everything non-essential off — everywhere, not only in the places that require it. You will see a confirmation in Your Privacy Choices when this has happened, and you can still turn something on yourself if you want to.
8. Children
A student account is never asked for these choices and never has anything beyond the essentials stored. A child cannot give consent, so we do not ask them for it and we do not act on an answer if one is somehow given. Where a parent manages a child's account, the parent's own choices apply to their own browsing.
9. Changes to this policy
If we add anything that stores data in your browser, it will appear in the tables above before it is used, and anything non-essential will ask you first. This page shows its version and effective date at the top.
Questions: hello@prodemy.app