Skip to main content
LMS
Learning Management System
FeaturesSolutionsPricingResourcesAbout
Legal & trust
FeaturesSolutionsPricingResourcesAboutLegal & trust
Home/Cookie and Browser Storage Policy
Legal · Storage inventory

Cookie and Browser Storage Policy — Draft

A plain inventory of storage the repository uses today, with unknown production details left visibly unconfirmed.

1Confirmed from code3Inferred — requires confirmation
Last updated: 19 July 2026Runtime capture still required3Inferred — requires confirmation
On this page6 entries
  • Operator details required
  • 1. Current cookies and browser storage
  • 2. Contact-form behavior
  • 3. Browser controls
  • 4. Consent and preferences
  • 5. Production verification required
On this page
  • Operator details required
  • 1. Current cookies and browser storage
  • 2. Contact-form behavior
  • 3. Browser controls
  • 4. Consent and preferences
  • 5. Production verification required
Plain-language overview

Read this first

The development build needs authentication cookies and remembers one sidebar preference. It contains no third-party analytics or advertising SDK.

1Confirmed from code
01

Sign-in needs cookies

Auth.js session storage is required to keep users signed in and protect private routes.

1Confirmed from code
02

One local preference

The portal remembers only whether its navigation rail is open or collapsed.

1Confirmed from code
03

Production details unknown

Names, attributes, rotation, and expiry need a real deployed-browser capture.

3Inferred — requires confirmation
Repository evidence

How to read these drafts

Each factual or decision-bearing statement shows whether it is proven today, inferred and awaiting confirmation, missing from the product, or reserved for a human decision.

  • 1Confirmed from code
  • 2Confirmed from configuration
  • 3Inferred — requires confirmation
  • 4Missing implementation
  • 5Business/legal decision required
3Inferred — requires confirmation5Business/legal decision requiredThis draft is not legal advice and is not ready for publication. No duration, consent rule, or production cookie property is promised until runtime and jurisdiction review are complete.

Operator details required

5Business/legal decision required

This draft requires [COMPANY LEGAL NAME], [PRODUCT NAME], [COOKIE CONTACT], and [POLICY EFFECTIVE DATE] before approval.

1Current cookies and browser storage

1Confirmed from code

Auth.js JWT session cookie(s) maintain sign-in and carry session identity and claims used by protected routes. Disabling them prevents authenticated LMS access.

3Inferred — requires confirmation

Auth.js may also emit short-lived authentication-flow cookies for state or framework protections. The exact set and duration require deployed runtime capture.

3Inferred — requires confirmation

Exact cookie names, attributes, and lifetime need a deployed runtime capture. Secure, HttpOnly, SameSite, path, domain, rotation, and expiry behavior are not explicitly fixed in repository configuration.

1Confirmed from code

The eduflow-rail local-storage item remembers whether the signed-in portal rail is open or collapsed. It remains until overwritten or browser storage is cleared.

1Confirmed from code

No external analytics, advertising, pixel, or cross-site tracking SDK was found.

2Contact-form behavior

1Confirmed from code

The demo contact form validates typed name, institution, work email, and role in the browser, then prevents submission and resets. Application code does not transmit or store those values; browser autofill remains controlled by the user and browser.

3Browser controls

1Confirmed from code

Clearing the sidebar preference changes only the remembered interface state; it does not delete an account or academic record.

3Inferred — requires confirmation

Browsers can block or clear cookies and local storage, but exact controls differ by browser and device.

4Consent and preferences

4Missing implementation

No cookie banner, consent record, preference center, analytics opt-out, or consent-withdrawal mechanism is implemented.

5Business/legal decision required

[LEGAL REVIEW REQUIRED] Decide whether the functional local-storage preference needs consent and whether a banner is required after jurisdictions and production behavior are confirmed.

5Business/legal decision required

Do not add non-essential analytics, advertising, replay, personalization, or third-party embeds until purpose, provider, data, duration, legal basis or consent, and withdrawal behavior are approved and documented.

5Production verification required

4Missing implementation

Capture all cookies and storage before sign-in, during sign-in, while authenticated, after sign-out, and after password change on the deployed domain.

4Missing implementation

Record each name, owner, purpose, content category, path/domain, security attributes, creation, rotation, and expiry behavior; then test sign-out and password-change session invalidation.

LMS
Learning Management System

A repository-backed learning management project for courses, assignments, submissions, grading, files, discussions, and quizzes.

Platform

  • Course management
  • Assignments
  • Communication
  • Quizzes

Solutions

  • For teachers
  • For students
  • For institutions
  • Student lifecycle

Resources

  • Help centre
  • FAQ
  • Getting started
  • About us

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie & Storage
  • Acceptable Use
  • Refunds
  • Data Protection Readiness
  • Legal & trust center
© 2026 LMS project. Operator: [COMPANY LEGAL NAME].
Legal & trustPrivacyTermsCookies