EduNode — Cookie Policy

1. What Cookies Are & Our Consent Model

1.1 Cookies are small text files stored on your device. We and our service providers also use similar technologies (e.g., local storage, pixels, SDKs). We refer to all of these as "cookies".

1.2 Consent model. For all cookies that are not strictly necessary, we ask for your prior opt-in consent through a cookie banner before they are set. Consent is:

  • Granular — you can accept or reject each non-essential category separately;
  • Freely given — no category is pre-ticked, and rejecting is as easy as accepting;
  • Withdrawable — you can change or withdraw consent at any time (see Section 4).

1.3 Strictly necessary cookies do not require consent because they are essential to provide the Service you requested.

1.4 Not everything we do is a cookie question. Some things we do involve no storage on, and no reading from, your device at all — the page-view counter in Section 3.1 is the example. Those are not governed by the cookie banner, and Section 3.1.6 explains why, so that you can check the reasoning rather than take our word for it.


2. Categories of Cookies We Use

  • Strictly necessary — required for core functionality: authentication/session, security, load balancing, consent state, and basic preferences needed to operate the Service. (No consent required.)
  • Functional — remember choices such as language, locale, and UI preferences to improve your experience. (Consent required.)
  • Analytics — help us understand how the Service is used so we can improve it (aggregate/statistical). (Consent required.)
  • Marketing — used to measure and (where applicable) personalise promotional content. (Consent required.)

These four categories describe cookies and other device storage. They are the categories the banner controls. Measurement that uses no device storage at all falls outside them — see Sections 3.1 and 3.2.


3. Cookies We Set (Per-Cookie Table)

Audited 3 August 2026; re-audited 6 September 2026. EduNode sets two cookies, both strictly necessary. We load no advertising and no third-party tracking scripts, and we use no third-party analytics provider, pixel, tag or SDK.

Cookie name Provider Category Purpose Expiry
edunode_session EduNode (first-party) Strictly necessary Maintains your logged-in session 120 minutes
XSRF-TOKEN EduNode (first-party) Strictly necessary Cross-site request forgery protection Session

From 6 September 2026 the Service also counts its own page views, using a first-party counter that sets no cookie and stores nothing on your device. That is why the table above is unchanged by it. Section 3.1 sets out exactly what that counter records and what it does not, and Section 3.2 explains what the Analytics control in the banner does and does not govern.

Your cookie preferences are not stored in a cookie at all — they are kept in your browser's localStorage under cookie_consent_v1, which is never transmitted to us. Clearing your browser storage clears that choice, and the consent banner will ask again.

Because we set no functional, analytics, or marketing cookies today, the consent controls currently govern categories that are declared but unused. If that changes — for example when payment checkout or video-meeting embeds are added — this table and the banner will be updated before those cookies are set.

3.1 Our first-party page-view counter (no cookies, no device storage)

3.1.1 What it is. We count page views ourselves, on our own servers, with software we run. No third party is involved: there is no external analytics provider, no pixel, no tag, no SDK, and nothing about your visit is sent anywhere outside the Service.

3.1.2 What each page view records.

  • the page path you viewed (the query string is not stored as such);
  • the utm_source, utm_medium and utm_campaign values, where the link you followed carried them;
  • the host name only of the site you arrived from — for example l.threads.com — and never the full referring address;
  • the display language of the page;
  • a UTC date and time;
  • a visitor hash — a SHA-256 value computed from a random daily salt, your IP address, and your browser's user-agent string.

3.1.3 What it does not do. Each of the following is enforced in the software, not merely promised here:

  • it sets no cookie, and writes nothing to localStorage, sessionStorage or IndexedDB;
  • it reads nothing from your device — no stored identifier, no device or browser fingerprint;
  • it never stores your IP address and never logs it. Your IP is used to compute the visitor hash and is then discarded;
  • the daily salt is random, is held only on our server, and is deleted after two days — a day's salt is kept for that day and the two days that follow, and is then deleted. Once it is gone, nobody holding our database — including us — can work out which IP address produced a past hash;
  • because that salt changes every day, there is no identifier that spans days. The same person visiting on two days produces two unrelated hashes. The counter can tell us how many distinct visitors a given day had; it cannot follow you from one day to the next, recognise you as a returning visitor, or build a profile of you;
  • traffic we identify as automated — bots and crawlers — is discarded rather than recorded.

3.1.4 What we use it for. To see how many people visit, which pages they read, which languages they read them in, and which campaigns or referring sites brought them — so that we can decide what to improve and where to spend effort. It is not used to target you, to personalise what you see, or to make any decision about you.

3.1.5 How long it is kept. Page-view rows are deleted automatically after a configurable retention period, 365 days by default. The daily salt is deleted after two days, as described above, which is a shorter and separate clock: after two days the rows survive but the link back to an IP address does not.

3.1.6 Why this sits outside the cookie banner. The consent requirement for cookies does not come from the GDPR. It comes from Article 5(3) of the ePrivacy Directive (2002/58/EC) and the national laws implementing it — in the United Kingdom, PECR. That rule attaches to one specific event: storing information in, or gaining access to information already stored in, a user's terminal equipment. It is a rule about your device, not a rule about data in general.

The counter does neither of those things. It writes nothing to your device and reads nothing from it. What it works from is the page you are already on and the request your browser has to send in order to be shown that page at all. There is therefore no storage-or-access event for the banner to collect consent for, which is why asking you to consent to it would misdescribe what is happening.

That does not put the counter outside data-protection law. Forming the visitor hash uses your IP address and user-agent, and that processing is governed by the GDPR. We rely on our legitimate interest in measuring the audience of our own website — Article 6(1)(f) — and we describe it, with its retention period, in Section 3 (row 18) and Section 4 of the Privacy Policy.

3.1.7 If you would rather not be counted. The count is sent by a small script on the page. If your browser does not run it — because you have disabled JavaScript, or because a content blocker filters the request — then no page view is recorded and nothing about your visit is stored. You may also object to this processing under GDPR Article 21, on grounds relating to your particular situation, by writing to privacy@edunode.co; Section 7 of the Privacy Policy explains what we can and cannot do in response, given that we hold no identifier that would let us find your past page views.

3.2 What the "Analytics" control does and does not govern

3.2.1 The Analytics category in Section 2 governs analytics that use cookies or other storage on your device. We run none of those, which is why Section 3 says the category is declared but unused. That statement is still true.

3.2.2 The page-view counter in Section 3.1 is analytics in the ordinary sense of the word, but it is not in that category, because it uses no device storage — and device storage is what the banner exists to control. So, stated plainly:

Turning "Analytics" off does not switch off the page-view counter, because that counter is not a cookie and the banner does not govern it. Turning it off is still meaningful: it withholds consent for any cookie-based analytics, which we would otherwise have to ask you for before setting one.

3.2.3 We would rather say this in as many words than let two accurate statements sit next to each other and mislead you by their arrangement. If you object to the counting itself, Section 3.1.7 is the route, and it is a different right from the one the banner exercises.


4. Managing or Withdrawing Consent

4.1 You can change or withdraw your consent at any time via the "Cookie settings" link in the site footer (or the cookie banner), which reopens the preference controls.

4.2 You can also manage cookies through your browser settings (blocking or deleting cookies). Note that blocking strictly necessary cookies may break parts of the Service.

4.3 Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

4.4 Consent is not the mechanism for the page-view counter, because none is required for it — see Sections 3.1.6 and 3.1.7 for what applies instead.


5. Relationship to Our Privacy Policy

This Cookie Policy supplements our Privacy Policy, which explains the broader processing of personal data, sub-processors, international transfers, and your data-subject rights. The page-view counter described in Section 3.1 appears there as row 18 of the legal-basis table in Section 3, with its retention period in Section 4.