VidyaSchool Docs
Legal Policies

Cookie Policy & Tracking Technologies

Effective Date: August 18, 2026  |  Last Updated: August 18, 2026

NO THIRD-PARTY ADVERTISING TRACKERS: VidyaSchool does not deploy third-party advertising cookies, cross-site trackers, or behavioral profiling pixels. We utilize strictly necessary session tokens, cryptographic security cookies, and local client preferences essential for educational portal functionality.

1. What Are Cookies & Local Storage Tokens

Cookies, session storage, and local storage tokens are small cryptographic text files placed on your browser or device when accessing the VidyaSchool portal. These technologies allow our servers to identify authenticated sessions, enforce Role-Based Access Control (RBAC), preserve user theme settings, and protect against Cross-Site Request Forgery (CSRF).

2. Categories of Cookies We Use

A. Strictly Necessary & Authentication Cookies:

Essential for logging into the portal, preserving cryptographic sessions, verifying multi-device logins, and preventing unauthorized elevation of student/teacher privileges.

B. Security & Firewall Cookies:

Used to enforce edge rate limiting, thwart brute-force password guessing, and block malicious automated bots.

C. Functional & User Preference Storage:

Stores theme preference (Light, Dark, Sepia Mode), sidebar collapse state, and note reader text size.

Cookie / Key NameTypeDurationPurpose
better-auth.session_tokenFirst-Party HTTPOnly7 DaysPrimary cryptographic user authentication token.
__Secure-better-auth.session_tokenSecure HTTPOnly7 DaysEnforces SSL/TLS transport security in production.
themeClient Cookie1 YearStores user UI theme selection (Dark, Light, System).
sidebar:stateLocal StoragePersistentMaintains navigation sidebar expanded/collapsed state.

4. Multi-Device Session Tracking & QR Tokens

When you sign into VidyaSchool across multiple devices (mobile phones, tablets, classroom PCs), our system assigns an encrypted session identifier paired with your client IP and browser user-agent. You can inspect all active sessions and remotely disconnect unrecognized devices anytime via the Active Sessions Portal.

5. Third-Party Subprocessor Storage

During checkout or error telemetry, third-party subprocessors may store necessary cryptographic tokens:

  • Razorpay: Utilizes temporary local tokens strictly to execute two-factor authentication and tokenized card verification for fee payments.
  • Sentry: Utilizes anonymous session identifiers strictly for crash diagnostics and performance debugging.

Most web browsers permit you to block or delete cookies through browser security settings. However, because our cookies are strictly necessary for authenticated identity verification:

Disabling or clearing essential session cookies will immediately terminate your active portal login and require re-authentication.

7. Contact Privacy & Security Cell

For questions regarding our cookie implementation or session encryption standards:

VidyaSchool Privacy Architecture Team
Security Center: Manage Active Sessions

On this page