Cookie Policy
Last Updated: August 8, 2026 · Effective: August 8, 2026
2. What We Use
2.1 Essential — required, cannot be disabled
Disabling these prevents login.
| Cookie | Purpose | Retention | Provider |
|---|---|---|---|
| sb-access-token | Authentication token | Session | Supabase |
| sb-refresh-token | Token refresh | 1 year | Supabase |
| session_id | Session identifier | Session | Pathion |
| user_preferences | Your settings (theme, language) | 1 year | Pathion |
| csrf_token | Cross-site request forgery protection | Session | Pathion |
2.2 Analytics — opt-out available
| Cookie | Purpose | Retention | Provider |
|---|---|---|---|
| mp_<id>_mixpanel | User identification | 1 year | Mixpanel |
| mixpanel_distinct_id | Unique analytics ID | 1 year | Mixpanel |
| mp_session_id | Session tracking | Session | Mixpanel |
| mp_referrer | Referral source | Session | Mixpanel |
2.3 Session recording — opt-out available
We record 100% of browsing sessions. Password fields are masked and never captured.
We record sessions so we can see where the interface confuses people, reproduce bugs you report without making you describe them, and understand how students actually work through problems. You can turn this off — see Section 4.
| Cookie | Purpose | Retention | Provider |
|---|---|---|---|
| __mps | Session recording flag | Session | Mixpanel |
| __mpso | Session recording options | Session | Mixpanel |
Recordings are retained up to 24 months. See our Data Retention Policy.
2.4 Marketing
None. We do not use advertising or marketing cookies and do not participate in ad networks.
3. Third-Party Cookies
| Service | Cookies | Purpose |
|---|---|---|
| Supabase | sb-*-auth-token, sb-*-session | Authentication, JWT management |
| Mixpanel | mp_*, __mps, __mpso | Analytics, session recording |
| _gid, _ga | OAuth authentication |
4. Your Choices
4.1 Turn off session recording — recommended, and it works
Account settings → Privacy Settings → "Disable Session Recording."
Takes effect immediately. Other analytics continue. This is the most effective control we offer.
4.2 Turn off analytics
Block Mixpanel cookies in your browser settings, or use a content blocker. Core functionality is unaffected.
4.3 Clear cookies
Any time, from your browser settings. Clearing cookies logs you out and resets saved preferences.
5. Do Not Track
We do not currently respond to DNT browser signals.
Our previous Cookie Policy stated that Mixpanel respects DNT and disables session recording. That was inaccurate and we have corrected it. There is no uniform standard for honoring DNT, and enabling it in your browser does not stop session recording on our platform.
Use the session-recording toggle in Section 4.1 instead. That one actually works.
If a DNT standard is adopted that we are required to follow, we will implement it and update this policy.
6. Clearing Cookies by Browser
Chrome
Settings → Privacy and security → Delete browsing data → "Cookies and other site data" → Delete
Safari
Safari → Settings → Privacy → Manage Website Data → Remove All
Firefox
Settings → Privacy & Security → Cookies and Site Data → Clear Data
Edge
Settings → Privacy, search, and services → Choose what to clear → "Cookies and other site data" → Clear now
7. Summary
| Type | Opt-out |
|---|---|
| Essential | No, required for login |
| Analytics | Yes, via browser settings |
| Session recording | Yes, in account settings |
| Marketing | Not used |
| Do Not Track | Not honored — use the toggle instead |