Policy

Cookies

Last updated: October 6, 2026
Draft for beta. This document is under legal review and will be finalized before paid access opens. It reflects how the service actually works today.

Why there is no cookie banner

Consent banners exist because most sites load trackers that need permission. We do not load any. RichiePrep sets three cookies, all strictly necessary to run a signed-in test or finish a sign-up, and strictly necessary cookies do not require consent under the ePrivacy Directive or the equivalent rules elsewhere.

Putting a banner up anyway would ask you to agree to something that is not happening. We would rather list the three cookies and the four items of local storage, and let you check.

Every cookie we set

Every cookie RichiePrep sets: name, purpose, lifetime, type
NamePurposeLifetimeType
rp_sessionKeeps you signed in. Holds a random token — never your email, name or password. The server stores only its hash.30 days, or until you sign outStrictly necessary
rp_profileRemembers which student profile you are viewing, so a guardian with several students does not reselect on every page.Until the browser session endsStrictly necessary
rp_pending_signupSet only while you finish a Google sign-up, so the half-finished registration survives the redirect. Deleted the moment the account is created.30 minutesStrictly necessary

All three are HttpOnly and SameSite=Lax, and are marked Secure in production — so they are not readable by scripts and do not travel unencrypted. Lax keeps them off cross-site requests made in the background, such as a form post or an image request from another site, while still sending them when someone follows a link to us from elsewhere and stays signed in.

What we store outside a cookie

Your browser’s own local storage holds four items, and no cookie is involved. The timestamp and the reading text size never leave your device. The Final Check games’ progress stays on it too, for a visitor; for a signed-in student whose progress is being saved, the same record is also kept with their student profile, so the morning list is there on any device they sign in on. The unsent answers exist so that they can leave: if a timed section cannot reach us, they wait here and are sent the next time you open that test.

Every item RichiePrep keeps in local storage: name, purpose, lifetime
NamePurposeLifetime
rp_offer_dismissed_atA single timestamp recorded when you close the welcome message, so it stays quiet for a month. It is never sent to us.One month; clearing site data removes it and the message asks once more
rp.reader.sizeThe text size you chose for reading passages with A− and A+, as a single step number, so the next passage opens at the size you read at. It is never sent to us.Until you change it again, or clear site data
rp_final_checkYour progress in the Final Check word games on this device: which words you have locked, which wait on your morning list, how quickly and when you last answered each, and when you last finished a Night Run or a Morning Run or started a list over. No name, no email. A visitor’s stays on this device. For a signed-in student whose progress is being saved, the same record is also kept with their student profile — so the morning list is there on any device they sign in on — and this item notes which profile it belongs to.Until you press Start over on a list, or clear site data; the copy kept with a student profile goes when the profile is deleted
rp_unsent_answersAnswers a timed section could not send because the connection dropped — the question, the choice or essay draft, the flags you set, and any lines you marked on a reading passage. No name, no email. It is written only when a save fails, and it is sent and erased the next time you open that test.Until the answers reach us, or 12 hours, whichever is sooner

Neither identifies or tracks you, and clearing your browser’s site data removes both. Clearing it in the middle of a test would discard answers that had not yet been sent.

What we do not set

  • No advertising or retargeting cookies.
  • No third-party analytics cookies — usage counts are first-party, aggregate, and carry no advertising identifier.
  • No social-network pixels or share-button trackers.
  • No cross-site identifiers, fingerprinting, or device graphs.

The help assistant sets no cookie and writes nothing to your browser’s storage. A conversation is held in the open page’s memory only, so your browser keeps nothing of it once the page is closed. What our servers keep, and for how long, is in the Privacy Policy.

Turning them off

Your browser can block or clear these cookies at any time. Blocking rp_session means you cannot stay signed in, so timed tests and saved progress will not work — the public pages, the sample questions and the Word Game still will.

Third-party cookies during Google sign-in

If you choose Sign in with Google, Google sets its own cookies on its own domain while you are on its sign-in page. Those are Google’s, governed by Google’s privacy policy, and we can neither read nor control them. Using the email-and-password route avoids them entirely.

More detail on what we hold and why: Privacy Policy.