Legal

Cookie policy

Exactly what Knowledge Forge stores in your browser, why, and how to change it.

Last updated 28 August 2026

What are cookies?

A cookie is a small file a website asks your browser to keep. Websites also use similar technologies — localStorage and sessionStorage — which store information in your browser in the same way. Throughout this page we use “cookies” to mean all of them, because the rules are the same.

Some of this storage is needed for the site to work at all: staying signed in, protecting a request, holding a part-finished booking. The rest is optional, and optional storage is only used if you switch it on.

How we use them

Strictly necessary — sign-in sessions, security, your cookie choice itself and checkout state. These operate without consent because the service cannot run without them.

Functional — remembers convenience settings such as the pupil Smart Working Board's tools and saved working. Off unless you allow it; the board still works, it just starts fresh.

Analytics — anonymous counts of journey steps so we can see where parents get stuck. No analytics provider is installed; nothing is recorded at all unless you allow this category.

Marketing and advertising — none in use. There is no Meta pixel, no Google Ads tag and no tag manager on this site. The category exists so that if one were ever added it would stay blocked until you allowed it.

Rejecting optional cookies does not make the site less secure. Security storage is strictly necessary and continues either way.

Children's information

Knowledge Forge holds children's educational information. No advertising or analytics technology receives it. The journey events we can record contain a step name and a timestamp only — never a child's name, a child identifier, an assessment result, questionnaire answers, a learning profile, school-match scores or report content.

Pages that show a child's work carry no analytics tag and no advertising pixel, and report identifiers are not placed in any measurement request.

Third-party services we checked

We audited every third-party service the site touches to see whether it actually stores or reads anything on your device. Being a processor is not the same as setting a cookie, so only the ones that genuinely use device storage appear in the table above.

Changing your mind

Use the “Cookie settings” link in the footer, or the button below, at any time. You can withdraw optional consent as easily as you gave it, and when you do we stop the optional activity and clear the first-party storage that belonged to it. You never need to email us or delete your account to change a cookie choice.

We keep a record of your decision — the categories you chose, when you chose them, the policy version and a random device identifier. Nothing about you or your children is attached to it. Questions can go to sakuralearning1@gmail.com.

Versions and updates

This policy is version 2026-08-28.1. If we materially change optional tracking, we update this page, update the inventory above and ask you to make a fresh choice. Routine wording changes do not re-show the banner.

Cookie and storage inventory

Taken from the running application. Where a duration is set by a third party on their own page, we say so rather than guess.

NameProviderPurposeCategoryDurationPartyConsent needed
sb-<project>-auth-tokenlocalStorageKnowledge Forge (Supabase auth)Keeps you signed in to your parent or tutor dashboard.Strictly necessaryUntil you sign out; access token refreshes hourlyFirst-partyNo
kf:cookie-consentlocalStorageKnowledge ForgeStores your cookie decision, its version and when you made it.Strictly necessaryUntil cleared or the cookie policy materially changesFirst-partyNo
kf:consent-devicelocalStorageKnowledge ForgeA random identifier with no personal data attached, used only to tie your cookie decision to this browser as evidence of the choice.Strictly necessaryUntil clearedFirst-partyNo
kf:privacy-notice-acklocalStorageKnowledge ForgeRecords that the privacy notice was shown and read before an account existed, so the evidence can be saved once you sign in.Strictly necessaryUntil cleared or the notice version changesFirst-partyNo
kf:pending-marketinglocalStorageKnowledge ForgeCarries your optional marketing choice from the sign-up form to your account. Removed once saved.Strictly necessaryUntil first sign-inFirst-partyNo
kf_checkout_draft_v1localStorageKnowledge ForgeHolds a part-finished booking so you do not lose it if you navigate away.Strictly necessaryUntil checkout completes or you clear your browserFirst-partyNo
jme:parent-emaillocalStorageKnowledge ForgePre-fills your email at checkout and on enquiry forms after you have used them once.Strictly necessaryUntil clearedFirst-partyNo
kf:forge-visitorlocalStorageKnowledge ForgeA random key so the Forge assistant can return your own conversation to you and nobody else's.Strictly necessaryUntil clearedFirst-partyNo
kf-board-prefs / kf-board-<question>localStorageKnowledge ForgeRemembers Smart Working Board tool settings and a pupil's own working on a question.FunctionalUntil clearedFirst-partyYes
kf_funnel_eventssessionStorageKnowledge ForgeCounts anonymous journey steps (page viewed, step reached) so we can see where parents drop out. No child data, no names.AnalyticsCleared when the browser tab closesFirst-partyYes
_fbpcookieMeta Platforms, Inc.A browser identifier set by the Meta Pixel so advertising visits and purchases on this site can be measured. Only created if you allow marketing cookies; no names, emails or child data are sent to Meta.MarketingUp to 3 months (confirm against Meta's current documentation)First-partyYes
kf:meta-sent:<event>sessionStorageKnowledge ForgeStops the same advertising event (for example a purchase) being reported to Meta twice.MarketingCleared when the browser tab closesFirst-partyYes
__stripe_mid / __stripe_sidCookieStripe Payments UK LtdFraud prevention and payment-session integrity on the Stripe-hosted checkout page. Set by Stripe on its own page, not by us.Strictly necessaryStripe states 1 year (mid) and 30 minutes (sid)Third-partyNo

Third parties audited

  • Google Analytics — not used. Not installed.
  • Google Tag Manager — not used. Not installed.
  • Meta / Facebook pixel — not used. Not installed.
  • Google Ads / advertising pixels — not used. Not installed.
  • Heatmap or session replay — not used. Not installed.
  • CAPTCHA (reCAPTCHA, Turnstile) — not used. Not installed.
  • Social embeds (YouTube, Vimeo, X) — not used. None. Videos are served from our own hosting, not an embedded player.
  • Stripe (payments) — in use. Yes, on Stripe's own checkout page — strictly necessary and fraud prevention.
  • Supabase (our database, auth and storage) — in use. Yes — the sign-in session in localStorage. Processor acting on our instructions.
  • Google Fonts — in use. No cookie or storage. The font files are fetched, which discloses your IP to Google as any request does.
  • AI providers (Lovable AI Gateway, ElevenLabs) — in use. No. Requests are made by our server, never from your browser to them.
  • Email delivery — in use. No device storage. No tracking pixel is placed in our emails.

Change your choices at any time. This opens the same preference centre as the footer link.