Cookies used
- scholiad_session_id — opaque session identifier issued by the session-authentication system.
- CSRF token cookie — anti-forgery token bound to session.
- Preference cookie — remembers your display preferences (theme,
language) so the service works the way you set it. It contains no
cross-site tracking data; cleared via Settings reset.
Analytics, Third-party, and Tracking cookies
Scholiad does not use analytics cookies, does not embed third-party cookies (the third-party payment processor's checkout sets cookies within its own domain), and does not deploy advertising/marketing trackers or browser fingerprinting beyond session authentication. If analytics are added in the future, we will require an opt-in consent banner and update this Policy with 30 days' notice.
Cookie Lifecycle
- scholiad_session_id: 30-day rolling-expiry (each authenticated request refreshes expiry).
- CSRF token cookie: bound to session lifetime; cleared at sign
out.
- Preference cookies: 1-year maximum; cleared via Settings reset.
User control and consent
Browser-level cookie controls allow you to block or clear Scholiad cookies (blocking essential cookies prevents sign-in). The "Sign out" action clears your session cookie server-side. Preference cookies can be reset via Settings.
Essential cookies (session, CSRF) are set with implicit consent on account creation, as they are required for authenticated service delivery. Should Scholiad add non-essential cookies in the future, we will require explicit opt-in consent via a consent banner.
## Cross-references
- Privacy Policy (/privacy)
- Terms of Service (/terms)
Version 1.0 · 2026