Cookie Policy & Tracking Technologies
Effective Date: August 18, 2026 | Last Updated: August 18, 2026
1. What Are Cookies & Local Storage Tokens
Cookies, session storage, and local storage tokens are small cryptographic text files placed on your browser or device when accessing the VidyaSchool portal. These technologies allow our servers to identify authenticated sessions, enforce Role-Based Access Control (RBAC), preserve user theme settings, and protect against Cross-Site Request Forgery (CSRF).
2. Categories of Cookies We Use
Essential for logging into the portal, preserving cryptographic sessions, verifying multi-device logins, and preventing unauthorized elevation of student/teacher privileges.
Used to enforce edge rate limiting, thwart brute-force password guessing, and block malicious automated bots.
Stores theme preference (Light, Dark, Sepia Mode), sidebar collapse state, and note reader text size.
3. Detailed Cookie Ledger
| Cookie / Key Name | Type | Duration | Purpose |
|---|---|---|---|
| better-auth.session_token | First-Party HTTPOnly | 7 Days | Primary cryptographic user authentication token. |
| __Secure-better-auth.session_token | Secure HTTPOnly | 7 Days | Enforces SSL/TLS transport security in production. |
| theme | Client Cookie | 1 Year | Stores user UI theme selection (Dark, Light, System). |
| sidebar:state | Local Storage | Persistent | Maintains navigation sidebar expanded/collapsed state. |
4. Multi-Device Session Tracking & QR Tokens
When you sign into VidyaSchool across multiple devices (mobile phones, tablets, classroom PCs), our system assigns an encrypted session identifier paired with your client IP and browser user-agent. You can inspect all active sessions and remotely disconnect unrecognized devices anytime via the Active Sessions Portal.
5. Third-Party Subprocessor Storage
During checkout or error telemetry, third-party subprocessors may store necessary cryptographic tokens:
- Razorpay: Utilizes temporary local tokens strictly to execute two-factor authentication and tokenized card verification for fee payments.
- Sentry: Utilizes anonymous session identifiers strictly for crash diagnostics and performance debugging.
6. Managing, Disabling & Revoking Cookies
Most web browsers permit you to block or delete cookies through browser security settings. However, because our cookies are strictly necessary for authenticated identity verification:
Disabling or clearing essential session cookies will immediately terminate your active portal login and require re-authentication.
7. Contact Privacy & Security Cell
For questions regarding our cookie implementation or session encryption standards: