1. Cookies
Legal Document / Cookies

Cookie Policy

Last Updated: July 17, 2026

Effective Date: April 20, 2026

Cookie and local-storage usage policy with strict privacy safeguards.

Introduction

01

WHAT ARE COOKIES?

Cookies are small text files stored by a website in Your browser. Classgrid also uses Local Storage and Session Storage for application state and preferences.

Authentication may use an HttpOnly cookie named token set by the server. In some browser flows, the client may store a signed token under the token key in Local Storage as a bearer-token fallback for API requests. A signed token is an authentication credential, not a link or URL, and it must not be placed in a URL.

Storage technologies used

  • Cookies: Small text files stored in Your browser.
  • Local Storage: Browser storage that persists until it is cleared.
  • Session Storage: Browser storage that is cleared when the browser tab is closed.

02

HOW WE USE COOKIES AND SIMILAR TECHNOLOGIES

We use cookies and similar technologies only to provide authentication, security, tenant experience, and user-interface functionality.

2.1 Strictly Necessary

  • token: The server sets the authentication cookie named token. It is HttpOnly, Secure in production, and protected by SameSite. Its default lifetime is 24 hours on desktop, 7 days when Remember Me is selected, and up to 365 days for mobile-app requests. The browser sends the HttpOnly cookie automatically with requests. In some browser flows, the client may store a signed token under the token key in Local Storage as a fallback for API requests.
  • parent_token: A Local Storage token used by the parent portal workflow.
  • admission_token: A Local Storage token used by the admission candidate portal workflow.
  • rescue_token: A temporary Local Storage token used for a restricted security workflow.
  • client_device_fp: An HttpOnly security cookie used for trusted-device verification after device verification. The implementation sets a one-year lifetime.
  • sidebar_state: A first-party cookie that remembers whether the dashboard sidebar is open or collapsed. The implementation sets a seven-day lifetime.

2.2 Functional

  • org_title and org_favicon: Organization branding preferences that may be stored in Local Storage.
  • The selected theme and last selected authentication role may be stored in browser storage.
  • push_banner_dismissed: Remembers whether a notification prompt was dismissed.
  • draft-[id]: Stores an unsent chat draft until the message is sent, removed, or cleared.
  • reset_success_[token]: A short-lived Local Storage entry used by the relevant password-reset workflow.
  • Other temporary authenticated workflows may use short-lived browser-storage entries.

2.3 Performance and Analytics

The reviewed platform runtime does not set third-party analytics or advertising cookies. Server-side operational logs and analytics are not browser cookies.

2.4 What We Do Not Use

  • Advertising cookies or behavioral retargeting cookies.
  • Social-media tracking pixels in the reviewed platform runtime.
  • Cross-site advertising or browsing-history tracking.
  • A limited trusted-device security cookie may be used for authentication protection. This Policy does not claim that no device-security metadata is ever processed.

03

COOKIES ON TENANT WEBSITES

Tenant websites may use first-party cookies or browser storage required by the deployed website template, such as session handling, branding, accessibility, or basic preferences. The exact storage keys can vary by tenant configuration and deployment.

The reviewed platform repository does not implement universal fixed keys named tenant_theme or visitor_session. They are not described as universal Classgrid cookies in this Policy.

A Tenant Organization may independently add an external service or embed. Those third-party services may set their own cookies, and their privacy and cookie policies apply to that activity.

04

COOKIES ON THE MOBILE APP

A native mobile application does not use browser cookies in the same way as a web browser. Where a native client is used, authentication and preferences are managed by that application's storage implementation. This browser Cookie Policy does not replace the mobile application's own privacy disclosures.

05

MANAGING YOUR COOKIE PREFERENCES

5.1 Browser Settings

You can view, delete, or block first-party cookies through Your browser settings. Blocking the authentication cookie may prevent You from signing in or using protected features.

5.2 Impact of Disabling Storage

  • You may be unable to log in or remain authenticated.
  • The dashboard may not remember the selected theme, branding, sidebar state, or dismissed prompts.
  • Unsaved chat drafts may be lost when browser storage is cleared.

5.3 Local Storage and Session Storage

To clear Local Storage or Session Storage, open browser Developer Tools, select Application or Storage, choose the relevant origin, and delete the stored entries. Clearing Local Storage may sign You out and remove saved preferences or drafts.

06

DATA COLLECTED THROUGH COOKIES

6.1 What We Collect

Depending on the feature and authentication flow, browser storage may process:

  • Authentication status and signed authentication-token data.
  • User, role, or organization identifiers needed to authorize a request.
  • Trusted-device verification metadata.
  • Theme, sidebar, branding, notification, and draft preferences.

6.2 How We Use It

The reviewed platform runtime does not use this browser storage for advertising, sale of personal information, or cross-site behavioral profiling.

07

CHILDREN AND COOKIES

Essential authentication and security storage may be used by Users, including minor students, when an institution provides access to the Platform.

Classgrid does not use browser storage for behavioral advertising or profiling of minor students. Tenant Organizations remain responsible for obtaining required consent and providing appropriate notices for their Users.

08

THIRD-PARTY COOKIES

8.1 Current Third-Party Cookies

The core platform runtime reviewed for this Policy does not actively set third-party advertising or analytics cookies.

8.2 Embedded Content

Third-party cookies may be set by content embedded or independently configured on a tenant website, such as a video player, map, analytics tool, or other external service. Classgrid does not control those third-party cookies. Please refer to the applicable third party's policy for details.

09

CHANGES TO THIS COOKIE POLICY

We may update this Cookie Policy when storage behavior, security controls, or applicable legal requirements change. When material changes are made, We will update the Last Updated date and provide notice through the Platform or email where appropriate.

Need legal help?

Contact our team for policy, security, or compliance clarifications.

Contact Support

Ask AI

Ask about Classgrid, Classgrid features, pricing, demos, or support.