This page is a first-draft cookie policy. It is published so the footer doesn’t link to a 404. The wording below has notbeen reviewed by counsel and the cookie table will be re-verified against the live codebase before publishing.
Last updated · 2026-05-21 · v0.1 (draft)
Cookie Policy
A “cookie” is a small piece of data a website asks your browser to remember between visits. Pardis uses only the cookies needed to make the service work. We set no third-party tracking, advertising, or analytics cookies today. The full list is below.
For the broader picture of what we collect and why, see our Privacy Policy.
01
First-party cookies
These are the cookies Pardis sets directly on the pardis.app domain. They are essential— the product cannot work without them. No consent banner is shown for essential cookies because removing them would break sign-in, profile switching, or the parent PIN.
Auth session
Essential
Keeps the parent signed in across page loads. Without it you would have to re-enter your email and password on every page.
- Lifetime
- Session (typical) or up to 30 days when "remember me" is selected.
- Set by
- Set by the auth provider (Clerk or Supabase, depending on AUTH_PROVIDER).
Active-child preference
Essential
Remembers which child profile is currently active inside the family. Lets the dashboard and the reader pick up where they left off.
- Lifetime
- Persistent until the parent switches the active child or signs out.
- Set by
- Set by Pardis on the dashboard.
Parent-PIN grace cookie
Essential
After a successful PIN entry, a short grace window during which the dashboard does not re-prompt for the PIN. Stops the PIN screen from interrupting a parent who steps away briefly.
- Lifetime
- 30 minutes.
- Set by
- Set by Pardis on successful PIN unlock.
Admin locale
Essential (admin only)
Remembers a Pardis-staff preference for the admin console’s language. Only set on admin-staff sessions — never set on parent or child sessions.
- Lifetime
- Persistent until the admin changes their locale.
- Set by
- Set by Pardis on the admin console.
Pending legal review: exact cookie names, max-age values, and theSameSite / Secure / HttpOnly flags should be enumerated from the live codebase before publishing.
02
Third-party cookies
None today. Pardis does not set, and does not allow any vendor to set, third-party tracking, advertising, or analytics cookies. Sub-processors listed in our Privacy Policyreceive data over server-to-server APIs (not through a browser-side script), so they don’t place cookies on your device.
03
Future: cookie consent banner
Today we don’t need a consent banner because every cookie we set is essential. If we ever introduce non-essential cookies (for example, opt-in analytics to understand which stories children finish), we will ship a consent banner first, default it to “off,” and document the new cookie in the table above before turning it on for anyone.
The banner work is tracked under COPPA-04 (not yet a numbered issue in GitHub; will be filed when the audit’s recommendations are prioritised for launch).
04
Managing cookies in your browser
Every modern browser lets you clear or block cookies on a per-site basis. Blocking essential cookies on pardis.app will sign you out and make the product unusable. To clear Pardis cookies specifically, open your browser’s site-data settings and remove pardis.app.
05
Contact
Questions about cookies? Email privacy@pardis.app. (This address may change while our mail setup is finalized.)