Draft · pending legal review · 2026-05-21

This page is a first-draft cookie policy. It is published so the footer doesn’t link to a 404. The wording below has notbeen reviewed by counsel and the cookie table will be re-verified against the live codebase before publishing.

Last updated · 2026-05-21 · v0.1 (draft)

Cookie Policy

A “cookie” is a small piece of data a website asks your browser to remember between visits. Pardis uses only the cookies needed to make the service work. We set no third-party tracking, advertising, or analytics cookies today. The full list is below.

For the broader picture of what we collect and why, see our Privacy Policy.

01

First-party cookies

These are the cookies Pardis sets directly on the pardis.app domain. They are essential— the product cannot work without them. No consent banner is shown for essential cookies because removing them would break sign-in, profile switching, or the parent PIN.

Auth session

Essential

Keeps the parent signed in across page loads. Without it you would have to re-enter your email and password on every page.

Lifetime
Session (typical) or up to 30 days when "remember me" is selected.
Set by
Set by the auth provider (Clerk or Supabase, depending on AUTH_PROVIDER).

Active-child preference

Essential

Remembers which child profile is currently active inside the family. Lets the dashboard and the reader pick up where they left off.

Lifetime
Persistent until the parent switches the active child or signs out.
Set by
Set by Pardis on the dashboard.

Parent-PIN grace cookie

Essential

After a successful PIN entry, a short grace window during which the dashboard does not re-prompt for the PIN. Stops the PIN screen from interrupting a parent who steps away briefly.

Lifetime
30 minutes.
Set by
Set by Pardis on successful PIN unlock.

Admin locale

Essential (admin only)

Remembers a Pardis-staff preference for the admin console’s language. Only set on admin-staff sessions — never set on parent or child sessions.

Lifetime
Persistent until the admin changes their locale.
Set by
Set by Pardis on the admin console.

Pending legal review: exact cookie names, max-age values, and theSameSite / Secure / HttpOnly flags should be enumerated from the live codebase before publishing.

02

Third-party cookies

None today. Pardis does not set, and does not allow any vendor to set, third-party tracking, advertising, or analytics cookies. Sub-processors listed in our Privacy Policyreceive data over server-to-server APIs (not through a browser-side script), so they don’t place cookies on your device.

03

Future: cookie consent banner

Today we don’t need a consent banner because every cookie we set is essential. If we ever introduce non-essential cookies (for example, opt-in analytics to understand which stories children finish), we will ship a consent banner first, default it to “off,” and document the new cookie in the table above before turning it on for anyone.

The banner work is tracked under COPPA-04 (not yet a numbered issue in GitHub; will be filed when the audit’s recommendations are prioritised for launch).

04

Managing cookies in your browser

Every modern browser lets you clear or block cookies on a per-site basis. Blocking essential cookies on pardis.app will sign you out and make the product unusable. To clear Pardis cookies specifically, open your browser’s site-data settings and remove pardis.app.

05

Contact

Questions about cookies? Email privacy@pardis.app. (This address may change while our mail setup is finalized.)