Skip to content
Payment confirmation is delayed. If you already paid, do not pay again while we reconcile it.See live status at status.edustello.com

Edustello Β· Legal

Cookie policy

Last updated 17 August 2026

Four cookies keep Edustello working, one optional choice decides whether we may measure how the site is used, and your browser holds a short list of things locally. This page is the whole of it β€” if something is stored on your device by Edustello, it is named below.

How we ask

Under Dutch and EU law, consent is required for anything stored on or read from your device that is not necessary to deliver the service you asked for. Measurement is not necessary, so we ask before any of it loads.

Refusing takes exactly one click, in a button the same size as accepting, and nothing about Edustello behaves differently afterwards. If you refuse, or close the banner without choosing, no measurement script is fetched at all β€” not loaded and disabled, not fetched.

You can change your mind at any time from the Cookie preferences link in the footer, and withdrawing takes the same single click as giving.

edu_session β€” keeps you signed in

A signed cookie holding your session. Without it, every page load would forget who you are. For a visitor who has not signed up, it identifies the guest session instead, so a free exam you generated is still yours after a refresh.

It is HTTP-only, so page scripts cannot read it, and it is sent only over HTTPS. It lasts 30 days, and is deleted immediately when you sign out.

Strictly necessary. It cannot be switched off while you are signed in.

edu_device β€” recognises the browsers you use

A random value that lets us tell whether your account has been signed in from this browser before. Its only purpose is the security email that says your account was opened somewhere new.

It describes nothing about your device or software β€” it is a random number we generated, stored as a one-way digest. Deliberately weaker than a fingerprint: clearing it makes a familiar browser look new, which costs you one extra security email and costs us the ability to recognise you at all.

It is HTTP-only, lasts up to 400 days, and is strictly necessary for the security notices we are obliged to send.

edu_locale β€” remembers your language

Stores the interface language you chose from the language switcher, so the site does not revert to a guess about your browser on the next visit.

It holds a two-letter language code and nothing else. It lasts one year, and is only set once you actively pick a language.

A preference cookie, set by your own action. Clearing it simply returns the site to detecting a language from your browser.

edu_consent β€” remembers your answer to this page

Stores what you chose on the cookie banner, so you are not asked again on every page. It holds the categories you agreed to, when you decided, and the version of this policy you decided about.

It lasts six months, after which we ask again. If we add a purpose or a processor, we ask again immediately, because consent is specific to what was described when it was given.

Necessary: without it we could not honour the answer you gave, and would have to assume the safest one every time.

Measurement β€” only if you agree

If you accept, we load Google Analytics 4 and Microsoft Clarity. They tell us which pages get used, which ones people leave, and where an interface is confusing. We use it to fix things, and for nothing else.

Google Analytics is configured with IP anonymisation on, and Google's advertising signals are switched off and sent as explicitly refused β€” we run no advertising, we build no audiences, and we ask for no advertising consent. Microsoft Clarity records how a page is interacted with, and masks text content by default.

Both are operated by companies in the United States, so agreeing means a transfer outside the EU. Both are certified under the EU-US Data Privacy Framework, and both are covered by the standard contractual clauses in their processor terms.

Refusing loads neither. There is no cookieless fallback quietly reporting instead β€” the scripts are simply never requested.

Counting visits without cookies

Whether or not you agree to the above, we count page views on our own servers. That count stores no cookie, reads nothing from your device, and records only the page pattern, the referring site, whether the browser is a phone or a desktop, and a two-letter country code from our network provider.

Nothing in it can be traced to a person, including by us: two visitors from the same page on the same kind of device in the same country are the same row. There is no identifier to link them, and none is derived.

This is how we know how many people actually visit, which the figures above cannot tell us when many visitors refuse. It requires no consent because it stores nothing and identifies nobody, and we would have to ask if that ever changed.

Cookies set by others

Stripe may set cookies on its own checkout and billing pages, which are hosted by Stripe and used for fraud prevention on the payment itself. Those pages are covered by Stripe's own cookie notice.

Cloudflare Turnstile runs on the sign-up and generation screens to tell people from scripts. It is a privacy-preserving alternative to a CAPTCHA, does not track you across sites, and is strictly necessary to keep the free tier from being drained by automation.

There are no advertising pixels and no social media trackers on Edustello.

What your browser stores locally

Alongside cookies, a handful of small values sit in your browser's local storage. In full: whether the history sidebar is open, the exam settings you last used, a draft of an exam in progress so a refresh does not lose your answers, the id of a generation that is still running so you can close the tab and come back, the release note you have already seen, and β€” if you asked for a sign-in link by email β€” the address you asked for it with, so the link can complete on the same device.

None of it is sent to us, none of it is readable by another site, and none of it identifies you to anyone. It is strictly necessary in the sense the law means: every item exists to deliver something you asked the interface to do.

IndexedDB β€” only where sign-in is handled by Firebase

When a deployment uses Firebase Authentication, its code runs in your browser on the four sign-in screens and keeps your authentication state in IndexedDB, which is a database your browser provides to a site. That is how a signed-in tab still knows who you are after a reload without asking the server on every keystroke.

It holds a token and the identifiers that go with it, written by Firebase rather than by us. It is strictly necessary β€” it is the sign-in itself, not a measurement of it β€” so it is not something the banner asks about. Signing out clears it, and so does clearing your browser's site data.

We list it because a policy that claims to name everything has to name this too. It is easy to leave out precisely because we did not write the code that sets it.

Refusing or removing them

Every browser lets you block or delete cookies for a site. Blocking Edustello's session cookie means you cannot stay signed in, so most of the service will not work.

For measurement, the Cookie preferences link in the footer is the direct route, and it takes effect immediately.

We will update this page if we ever add another cookie or another processor, and where consent is required we will ask for it before anything is set.

Contact

Edustello is operated by Velyra Digital, the Netherlands. Questions about this document, or a request under it, reach a person at:

legal@edustello.com