Skip to main content

Cookie Policy

Last updated: 12 September 2026

What Are Cookies?

Cookies are small text files that are placed on your device when you visit our website. They help us provide you with a better experience by remembering your preferences and understanding how you use our site. This page also covers browser local storage, which works the same way but is only readable by the page itself.

Cookies We Set

We set only cookies that are needed for the site to work. None of them is used for advertising, and no third party reads them. They cannot be disabled without breaking sign-in.

  • Authentication cookies - set by Supabase, our authentication provider, to keep you signed in. Refreshed while you keep using the site; up to 400 days.
  • Device token - one random token per device, used to enforce the 2-device limit on every account. Lasts 1 year.
  • Country - the two-letter country code our hosting provider derives from your IP address, so that prices can be shown in a matching currency. Refreshed on every visit; lasts 30 days. This cookie contains no identifier.
  • Landing intent - if you arrive on a page for a particular assessment provider or the assessment centre and then sign up, this remembers which one so your dashboard can open on it. It holds a page name only and lasts 30 minutes or until you sign in, whichever comes first.

Legal basis: strictly necessary for the service you have asked for.

Browser Local Storage

  • Theme - your light or dark mode choice.
  • Entry intent - the provider or product page you first arrived on, so the dashboard can put it first. A page name only.
  • PostHog identifiers - the analytics identifiers described below. PostHog is configured to use local storage rather than cookies.

Analytics and Error Monitoring

PostHog

We use PostHog to understand which games and features are used and where people get stuck. It sets no cookies. What it does do:

  • Records page views, named product events and page performance measurements
  • Links those events to your account ID and plan tier once you are signed in, so we can see how different plans use the product. Your name and email address are never sent.
  • For roughly one in ten visits, records a session replay of how the page changed as you used it. Everything you type is masked in your browser before it is sent.
  • Sends its data through our own domain rather than directly to PostHog

Sentry

Sentry sets no cookies. When an error happens in your browser it receives a report containing the error, the page, your browser details, and your account ID and email address if you were signed in, together with a replay of the seconds leading up to the error with all text masked and all images and video blocked. A small sample of requests also sends a performance trace.

Interview Practice: No Additional Cookies

The Interview Practice feature does not set any additional cookies. Video uploads go directly from your browser to Cloudflare R2 using short-lived signed URLs; no new cookie is created during this process. Your existing authentication cookie is used only to authorise the session creation and completion API calls.

How We Use Game & Interview Statistics

When you complete a game, we store the following in our database:

  • The full game state, including every trial, your responses, and timing data
  • Raw score, normalised score, and percentile ranking
  • Session start/end times and duration
  • Game-specific metrics (e.g., reaction time, accuracy)
  • A generated feedback report with strengths, weaknesses, and recommendations (generated on-demand, not stored)

When you complete an Interview Practice session, we store:

  • AI-generated transcript of your spoken answers
  • Content scores (relevance, clarity, structure) and non-verbal scores (eye contact, posture, confidence)
  • Detected filler words, improvement suggestions, and an overall score
  • Interview credit transaction records

This data is stored in our secure database and is only accessible to you. We use it to:

  • Show you your scores, progress charts, and improvement trends
  • Generate personalised feedback and recommendations
  • Calculate your percentile ranking against anonymised population benchmarks
  • Track your daily practice streak and personal best
  • Display interview feedback and history in your dashboard

Game session data is automatically deleted after 2 years. Interview feedback and transcripts are kept until you delete the session or your account. Raw interview video files are deleted from cloud storage as soon as AI processing completes successfully. Full retention periods are in our Privacy Policy.

Third-Party Services

We use the following third-party services:

  • Stripe- Payment processing. Checkout happens on Stripe's own pages, which set Stripe's cookies under Stripe's policy.
  • Supabase - Authentication and database services (sets the authentication cookies above)
  • Google and GitHub- Optional sign-in. If you use one, that provider's own pages and cookies are involved during sign-in.
  • Vercel - Hosting. Derives the country used for the country cookie from your IP address.
  • PostHog - Product analytics (no cookies; local storage)
  • Sentry - Error monitoring (no cookies)
  • Cloudflare R2 - Cloud storage for interview video uploads (no cookies set; uploads use signed URLs, not session cookies)
  • OpenAI - AI processing for interview feedback, assessment centre written-answer reviews and the help assistant (server-side only; no cookies set in your browser)
  • Trigger.dev, Resend and Upstash - Background jobs, email delivery and rate limiting, all server-side; none sets cookies in your browser.

Why There Is No Cookie Banner

We set no advertising cookies and no third-party tracking cookies, and our analytics uses browser local storage rather than cookies. The cookies we do set are strictly necessary for signing in, enforcing the device limit and showing prices, so we do not show a consent banner. If you would rather not be included in analytics, most browsers let you block local storage for a site, or you can use an ad blocker; the site works without analytics.

Cookie Retention

  • Authentication cookies - up to 400 days, refreshed while you use the site
  • Device token - 1 year
  • Country - 30 days, refreshed on every visit
  • Landing intent - 30 minutes, or until you sign in

You can clear cookies and local storage at any time using your browser settings, but this will sign you out and reset your theme.

Your Rights

Under GDPR and other privacy laws, you have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to data processing
  • Export your data (data portability)
  • Withdraw consent at any time

Contact Us

If you have questions about our cookie policy, please contact us at:

  • Email: support@cogniprep.app

Changes to This Policy

We may update this cookie policy from time to time. When we do, we update the “Last updated” date on this page and show a notice in your dashboard the next time you sign in. We do not send emails about policy changes.