Cookies policy
Under the UK Privacy and Electronic Communications Regulations 2003 (PECR) we must tell you what cookies we set and why. Here is the full list.
Strictly necessary (no consent required)
| Name | Purpose | Lifetime |
|---|---|---|
aa_sid | First-party session cookie tied to your Ally cabinet sign-in. Without it we cannot keep you signed in. | 30 days (rolling) if "keep me signed in"; otherwise browser session. |
aa_c | First-party cookie recording your cookie choice from the banner so we do not ask again. | 12 months. |
Analytics (opt-in)
We use Plausible Analytics, hosted in the EU. Plausible does not set cookies and does not collect personal data — it counts unique daily visits using a hashed identifier that regenerates every 24 hours. No consent is legally required for Plausible under PECR because it is not a cookie, but we still respect your aa_c=n choice by disabling the beacon entirely.
Third parties
None. No Google Analytics, no Facebook Pixel, no LinkedIn tag, no chat widget. If we ever add a third-party cookie we will re-prompt via the banner.
Your controls
- Change your choice at any time by clearing
aa_cand reloading — the banner reappears. - Sign out from every device with sessions & devices → revoke all others.
- Delete your Ally cabinet from account deletion.
What each cookie does in detail
aa_sid — session cookie
Set by our web application when you complete magic-link sign-in. Contains a 256-bit random identifier tied server-side to a session record with your account ID, issued timestamp, browser fingerprint (rounded to family + major version + OS + locale) and last-active timestamp. Marked HttpOnly (JavaScript cannot read it), Secure (only sent over TLS), SameSite=Strict (never sent on cross-site requests). Without this cookie you cannot stay signed in — every page request would go to the sign-in flow. Lifetime: 30 days rolling if you ticked "keep me signed in", otherwise until browser close.
aa_c — cookie-choice cookie
Set when you click Accept or Decline in the cookie banner. Contains the string "y" or "n" and nothing else. Purpose: to stop showing you the banner on every page load. HttpOnly is false (JavaScript needs to read it), Secure yes, SameSite=Strict. Lifetime: 12 months.
How to inspect and clear
You can inspect Ally's cookies in your browser's developer tools (usually F12 → Application → Cookies or Storage → Cookies). Filter by domain allyhub.org. To clear, right-click the cookie and choose Delete, or use your browser's site-data controls (Settings → Privacy → Clear browsing data → "Cookies and other site data" scoped to allyhub.org).
Local storage and IndexedDB
The Ally cabinet uses local storage for a small number of UI preferences (last-selected mentor filter, notes editor pane widths, dark-mode preference where offered). None of this contains personal data; it is helper state to save you a click. IndexedDB is used only during an active video call to cache the E2EE key material; the store is cleared when the call ends.
Server-side session logging
For each active session we also log server-side: the IP address of the most recent request (rolling), the user agent, and the last-active timestamp. This is the data that appears on your sessions & devices page. It is retained for as long as the session is active, plus 90 days after logout for security-forensics purposes, then hard-deleted.
Do Not Track and Global Privacy Control
Ally honours the Global Privacy Control (GPC) header. When we detect it, we treat it as an implicit Decline choice: no non-essential cookies, no analytics beacon, cookie banner still shown once for transparency. We do not act on the older Do Not Track header, which the industry never converged on.
Third-party embedded content
Ally does not embed third-party widgets, ads, or trackers. Fonts are loaded from Google Fonts (fonts.googleapis.com and fonts.gstatic.com) which sets no cookies; the request is proxied through Cloudflare so your IP is not shared with Google. If we ever change this we will notify you and re-prompt via the banner.
Contact
Questions: DPO at dpo@allyhub.org.