Cookies
Last updated: September 28, 2026
Marsof Academy uses a single cookie, our own and technical, which is essential to sign in. We don't use analytics, advertising or third-party cookies. That's why you won't see a banner asking for permission.
The session cookie
- Name: academy_session.
- Who sets it: us (first-party cookie, from our domain).
- Purpose: keeping you signed in. Without it you couldn't access your account.
- Duration: 30 days, or until you sign out.
- Protections: HttpOnly (the page's code can't read it), Secure (it only travels over HTTPS) and SameSite=Lax.
There are no other cookies: protection against cross-site request forgery (CSRF) works with a header, not with cookies.
Browser local storage
To remember your preferences and not lose your work, the app stores the following on your own device (localStorage). It's all technical: it isn't used to track you or sent to third parties, and it stays in your browser:
- academy-locale: the language you chose.
- academy-theme: light or dark theme, if you change it.
- academy-listen-rate: the read-aloud speed.
- academy-lesson-view and academy-lesson-step:(lesson): whether you read lessons step by step or as one page, and the step you were on.
- academy-taller:(account):…: drafts of your Workshop files until they are saved to your account.
- academy.terms-prompt.(version): that you clicked «Not now» on the new-terms notice.
- academy-locale-beta-seen: that you already closed the notice about a language in beta.
- academy.bit.collapsed, academy.bit.silenced and academy.bit.greeted: whether you've minimized or muted Bit, the helper, and in which areas it has already greeted you today.
- academy.landingBit.minimized and academy.publicBit.hidden: whether you've minimized or hidden Bit on the home page and the public pages.
They last until you clear them in your browser settings (site data).
Also, only while the tab is open (sessionStorage, cleared when you close it): academy.bit.visited (the areas of the app you've already visited, so Bit doesn't repeat its introduction) and academy.sessionNotice (the notice that your session was closed because the account was opened on another device).
App files
So the academy loads quickly and works offline, a service worker keeps the app's own files in the browser cache: code, styles, icons and the Python interpreter (Pyodide). They contain no personal data: our server's responses with your data are never stored in this cache.
Why is there no consent banner?
The law only requires asking for your consent for cookies and storage that aren't strictly necessary to provide the service you ask for (art. 22.2 of the Spanish LSSI-CE, which implements Directive 2002/58/EC, known as «ePrivacy»). The session cookie is technical and the other data stores preferences you choose or the work you are doing, so they are exempt, as the AEPD's Guide on the use of cookies also states.
We don't use cookies or storage for analytics, advertising or tracking, nor third-party ones. If we ever did, we would ask for your permission first, with the option to reject them as easily as to accept them.
You can clear the cookie and local storage whenever you want in your browser; if you clear the cookie, you'll be signed out.
Payments with Stripe
When you pay or manage your subscription, you leave our site for Stripe's pages (checkout.stripe.com and billing.stripe.com). Those pages belong to Stripe and use their own cookies, needed for payment and fraud prevention, under its cookie policy. On our domain we don't load any Stripe script and we still use only the essential session cookie.