Cookies and browser storage
Storage used for sign-in, saved work and optional analytics.
Effective and updated: · Version: 2026-10-01.1
Human review required: operator details and binding legal translations are not yet confirmed.
Necessary storage
better-auth.session_token (with __Secure- on HTTPS) authenticates sessions for up to 7 days. NEXT_LOCALE remembers language. The theme preference uses localStorage. PrepKit stores anonymous search and practice drafts in prepkit.anon.v1.* for 7 days, guest favorites/progress in prepkit:guest-state, used-link fingerprints in prepkit.signIn.consumed, submission drafts in prepkit:submission-draft:v1 and private status links in prepkit:submissions:v1. Persistent entries without an expiry remain until cleared.
Tab storage and provider keys
sessionStorage holds sign-in email, submission email, correction drafts, staff editor drafts and key-free practice recovery data (prepkit.practice.*). Closing a tab normally ends this storage; browser session restoration can retain it. The provider key is held only in memory in this version, never in cookies, localStorage or sessionStorage. Clearing browser storage does not delete your server account.
Optional analytics
qs:consent:analytics in localStorage records your choice. Only after consent, prepkit:analytics:journey, prepkit:analytics:attribution and prepkit:analytics:landed use sessionStorage for a per-tab journey, channel, campaign and referrer host. Full referrer URLs and interview text are excluded. Global Privacy Control keeps analytics off. Use the preferences control here or in the footer to withdraw consent.
Usage statistics
Anonymous, first-party statistics about which pages and steps people use. No email, API key, interview text or search text is recorded.