Cookie Policy
Last updated: 9 September 2026
This Cookie Policy explains how SkyStudy uses cookies, local storage, service workers, and similar browser technologies. It should be read together with our Privacy Policy and Terms of Service.
1. Technologies We Use
- Essential cookies keep you signed in and protect authenticated sessions.
- Local storage stores preferences such as theme, reduced-motion choices, and practice resume state.
- IndexedDB stores encrypted offline question packs and pending offline answers on your device.
- Service workers and browser cache help the app shell load and support offline study.
- Analytics technologies are optional and are loaded only after you make the relevant choice in the cookie controls.
2. Storage Inventory
SkyStudy does not use advertising or cross-site tracking cookies. The table below lists the cookie families we set, and the browser-storage items that are used across the whole app, grouped by category and, where one feature keeps several related entries, by family with the key prefix those entries share. Families rather than names, because the sign-in library chooses the exact cookie name at the moment it writes it: a session too long for one cookie is split across numbered ones, and a sign-in still in progress adds a short-lived extra. The first row names that whole group. It is not the complete list of every key: each tool also keeps its own settings and your own unfinished work on your device, and those are described in the paragraph under the table rather than named one by one, because the list changes whenever a tool is added. Strictly necessary items are always on (the Service cannot function without them). Preferences are written only in response to something you do: changing a setting, typing into one of the document tools, finishing an exercise or a scenario, dismissing a prompt, opening a feature that needs its own local cache, or reading far enough down a guide for a one-off prompt to have been offered. Analytics is never active by default: nothing in that category is written to your device, no analytics script loads, and our browser error-monitoring service is not loaded (Section 4), unless you accept analytics in the banner. Declining, or changing your mind later, prevents new optional analytics processing and removes the listed browser storage where the browser permits it.
One thing is not in the table, and its absence is deliberate rather than an omission. The largest measurement we make of the public site is a set of 55 anonymous counters kept in our own database. They are not listed below because this table lists cookies and browser storage, and the counters are neither: they write nothing to your device, and nothing they read is anything we put there. One of them, the counter that records what kind of place linked you here, does read two values your own browser hands to the page as it loads, the referring address and the campaign tags on the address you arrived at, and sends us only a single word derived from them, never either original value. A counter row holds a counter name from a closed list, a key such as a page path, the calendar day, and a number. It holds no account identifier, no IP address, no user-agent string, no session identifier and no cookie value. Section 2.17 of our Privacy Policy sets out what a row contains, what it cannot contain, and why that means there is no export or erasure path for it.
| Name / key | Type | Category | Purpose |
|---|---|---|---|
sb-<project>-auth-token, and, when the session is too long for one cookie, sb-<project>-auth-token.0, .1 and so on. While a sign-in is in progress, sb-<project>-auth-token-code-verifier as well. | Cookie | Strictly necessary | Keeps you signed in and protects your authenticated session (set by Supabase Auth). The verifier is the one-time value that proves the sign-in you finish is the sign-in you started, and it is cleared as soon as that is done. Signing out clears all of them. |
skystudy-cookie-consent | Local storage | Strictly necessary | Records your analytics choice, with advertising fixed to off, the policy version and the time of the choice. The record expires after 180 days, and an older or incompatible record is not reused. |
| Tab-scoped refusal marker, only if saving a refusal fails | Window name | Strictly necessary | Preserves a refusal through a reload in the same tab when browser local storage cannot save it. It never records acceptance, is not used across tabs, and ends when that tab is closed. |
| Offline question packs & pending answers | IndexedDB | Strictly necessary | Stores downloaded questions and answers submitted offline, synced when you reconnect. |
| App shell & asset cache | Service worker / Cache | Strictly necessary | Lets the app load quickly and work offline. |
skystudy-theme, skystudy-accent, skystudy-brightness | Local storage | Preferences | Remember your theme, accent colour, and brightness on this device. |
skystudy-question-reading-settings-v1 | Local storage | Preferences | Remember reading settings (font size, spacing) for questions. |
skystudy-practice-resume-v1, skystudy-practice-preferences-v1 | Local storage | Preferences | Resume an in-progress practice session and remember your practice filters. |
autoNextOnCorrect, autoNextOnWrong, autoAdvanceDelayMs | Local storage | Preferences | Remember your auto-advance behaviour between questions. |
skystudy-path-explainer-seen-v1 | Local storage | Preferences | Remember that you dismissed the “how your Path works” explainer, so it does not reappear. |
skystudy-offline-subjects | Local storage | Preferences | Caches the subject list (id, code, name) so the offline practice runner can label subjects by name. |
skystudy:mind-sanctuary:v1 | Local storage | Preferences | Remembers your ambient-sound mixer: which sounds are on, their volumes, and any mixes you saved. Written only once you change something in the mixer. |
examAutoAdvance, examAutoAdvanceDelayMs | Local storage | Preferences | Remember your auto-advance behaviour inside a mock exam. |
skystudy-aptitude-* (the family: -best:, -history:, -difficulty:, -pacing:, -mode:, -adaptive:, -practice-done:, -battery-progress:, -profile:, -coach-draft:, -coach-feedback:, -achievements-seen, -cloud-imported:, each followed by the exercise or question it belongs to) | Local storage | Preferences | Run the pilot aptitude exercises without an account: your scores and attempt history, your difficulty, pacing and Learn or Exam choice per exercise, an unfinished battery, your answers to a self-report questionnaire, a draft answer and its coaching feedback, and which achievement cards you have already seen. If you sign in, one further entry records that this browser’s existing runs have been copied to your account, so they are not copied twice. Everything here stays on this device unless you are signed in. The Clear my progress control on the aptitude progress page removes your scores, your attempt history, which practice sets you have completed, your coaching drafts and their feedback, which achievement cards you have seen, and the copied-to-account marker. It deliberately keeps the settings you chose: difficulty, pacing, adaptive mode, the Learn or Exam choice, an unfinished battery, and your self-report answers. Clearing site data in your browser removes all of it. |
skystudy:atc-sim:* (progress, resume, intro, map-orientation, readback-mode, ground-input, rate, readability, save-note) | Local storage | Preferences | Run the ATC comms simulator without an account: which scenarios you have completed, an unfinished one so you can resume it, your map, readback and ground-input choices, the voice speed and readability settings, and which one-off notices you have dismissed. |
skystudy:icao-english:progress:v1, skystudy:icao-english:intro:v1 | Local storage | Preferences | Your progress through the free ICAO English drills, and that you dismissed the intro card. |
skystudy-cv:v1, skystudy-cv:versions:v1, skystudy-cover-letter:v1, skystudy-exam-planner:v1 | Local storage | Preferences | The documents you are writing in the CV maker, the cover letter builder and the exam planner, kept in your own browser so you can close the tab and come back. These are the only entries that can hold substantial personal details, because they hold whatever you typed into them. The cover letter and the exam planner never leave your device at all: there is no route that uploads either. The CV reaches SkyStudy only if you are signed in and use cloud save, in which case a copy also sits on your account and is covered by Section 2.13 of the Privacy Policy. Clearing site data removes the browser copy for good; it does not touch a copy you saved to your account. |
skystudy-forum-new-thread-draft | Local storage | Preferences | An unsent forum post, so a mistyped navigation does not lose what you wrote. |
skystudy-tools-theme, skystudy-currency, skystudy-ownership-region, skystudy:display-mode | Local storage | Preferences | Settings you chose on a tool page: the theme for the public tools, your currency, the region for the ownership cost calculator, and how the installed app opens. |
skystudy:career-step, skystudy:exam-date-prompt-dismissed, skystudy-metar-study-ribbon-dismissed, skystudy-magnet-unlocked-<guide> | Local storage | Preferences | Small markers so the site does not repeat itself: where you were in the become-a-pilot guide, and which one-off prompts, ribbons and download gates you have already seen or unlocked. They hold a step number or the single character 1, and nothing that identifies you. |
skystudy-scroll-capture-seen | Local storage | Analytics | Set once the free study-plan card has slid in for you on a guide page, so it is not offered twice. It holds the single character 1. It is written only if you accepted analytics in the banner; if you declined, or have not answered, the card is never shown and nothing is written. |
skystudy:stale-chunk-reload, skystudy-forum-viewed:<thread> | Session storage | Strictly necessary | Two per-tab guards: one stops a reload loop after a stale script is detected, the other stops one forum thread being counted as viewed twice in the same visit. Both are cleared when you close the tab. |
skystudy-globe-cap | Session storage | Strictly necessary | Result of a one-off check of what this device can render, so heavy visuals are skipped on hardware that cannot handle them. Holds no information about you and is cleared when you close the tab. |
skystudy-attribution | Local storage | Analytics (consent required) | Records which campaign or link brought you to the site, so we can tell which of our own efforts work. Three things go in it: the utm_ tags on the address you arrived at, the page on this site you landed on, and the origin of the site that linked you, meaning https://www.google.com and never the full address of the page you came from. A link from one of our own pages is dropped rather than recorded. It holds no identifier that could follow you to another website, it is written only if you accept analytics, and declining removes it. |
| Cookieless analytics (when enabled) | Script (no cookies) | Analytics (consent required) | Privacy-friendly, aggregate usage measurement. Sets no cookies and does not track you across sites. No analytics is active unless explicitly enabled in the deployment. |
Two groups of keys sit outside the table, and neither of them measures you. The first is the tools: each one keeps its own settings, and the work you have not finished, in your own browser under a name beginning skystudy-. Examples are skystudy-currency for the flight currency tracker, skystudy-tools-theme for the light or dark setting on the public weather tools, skystudy-ownership-region for the aircraft ownership calculator, skystudy-forum-new-thread-draft for a forum post you started and did not send, the skystudy-aptitude- keys that hold your aptitude scores, difficulty and pacing settings, the CV, cover letter and exam planner drafts, and the keys that remember you closed a prompt so it does not come back, such as skystudy-metar-study-ribbon-dismissed. Each is written by the tool you were using, it holds your own settings or your own work, none of them is a cookie, none is in the Analytics category, and clearing site data in your browser removes all of them. The second group is the admin and staff tools, which store a small number of operational keys (for example a last-export timestamp); those are strictly necessary and only present for staff accounts.
3. Strictly Necessary Storage
Authentication, security, payment access checks, rate limiting, fraud prevention, and offline study storage are necessary for the Service to work. These technologies cannot be disabled from the app without breaking core functionality, but you can remove them from your browser settings.
4. Analytics
The browser measurements below require analytics consent. Server-side service records are described separately in the Privacy Policy.
First, our own anonymous counters. They are the largest of the three and the emptiest: 55 named counters in our own database, four values to a row, no identifier of any kind, and nothing written to your device. That is why they are not in the inventory above. One of them reads two values your own browser hands to the page it is loading, which is the exception set out in Section 2 above; whether that read is covered by the same rule as cookies is an open question we state rather than settle, and Section 2.17 of the Privacy Policy describes all of it in full. Browser-initiated counters run only after you accept analytics. The server separately counts completed account creation while processing that request.
Second, Vercel Web Analytics and Speed Insights, served from our own domain. Neither sets a cookie and neither stores anything on your device, and both load only after you accept analytics. They are not identical to each other. Vercel's own privacy documentation says that for Web Analytics end users are identified by a hash created from the incoming request, and that the lifespan of a visitor session is not stored permanently and is discarded automatically after 24 hours; for Speed Insights it lists what is stored and there is no visitor identifier among it. That hash is made by Vercel from the request, it stays with this site, and it is not an advertising or cross-site identifier, but it is an identifier and this page names it rather than claiming there is none.
Third, Plausible Analytics: optional cookieless analytics. Our own browser adapter sends pageviews and custom events to Plausible's Events API only after you accept analytics. It loads no remote Plausible script and omits page query strings, fragments and referrer addresses. Rejection or no answer keeps those requests off. This choice also controls the other browser measurements above; the separate server-side account-creation totals do not depend on it.
Accepting analytics also lets us keep skystudy-attribution on your device: a short note of the campaign tags on the link you arrived through, the page you landed on, and the origin of the site that linked you, so that if you sign up days later we can still tell which of our own pages or campaigns brought you. This paragraph said "campaign labels only" until 2 September 2026, and the row in the table above is the full list. There is no identifier in it that could follow you to another website.
It does leave your device, and this policy used to say it did not. It leaves in four situations, each one something you started, and we would rather list them than summarise them:
- When you create an account with an email address, the whole note is sent with the form, so that the record of where you came from is attached to your account instead of to you as a visitor.
- When you sign in or sign up with Google, the campaign tags, the page you landed on and the origin of the referring site are added to the address of the sign-in redirect. A redirect away from our site would otherwise lose them. This one happens on signing in as well as on signing up.
- When you ask us to email you one of our free resources, it is sent with that request, for the same reason as the first.
- While you have accepted analytics, the campaign tags, and only those, are attached as labels to the events our analytics provider records. The page you landed on and the referring origin are not sent there.
If you decline analytics, or change your mind after accepting, it is not written and any existing copy is removed.
Accepting analytics also switches on error monitoring in your browser. Sentry, our error-monitoring service, hosted in its EU region in Germany, is loaded only after you accept. It then reports crashes, a sample of slow page loads and a short health signal for the visit. Your IP address, email address, cookies and request contents are removed from each report before it leaves your browser; like any server, Sentry still sees the address the report was sent from. If you decline, or have not answered the banner, the Sentry script is never loaded and nothing is sent to it from your browser. Errors on our own servers are still recorded, because that happens on our servers and touches nothing on your device. We have not verified whether Sentry creates other browser storage when it is enabled, so do not rely on this policy as a statement that it creates none.
5. Offline Study Storage
If you download offline question packs, the questions and pending answer queue are stored locally in your browser using IndexedDB. Clearing browser data, using private browsing, or switching devices may remove this offline data. Pending answers sync to your account when you return online.
6. Third-Party Processors
Some cookies or local storage entries may be set by processors that provide authentication, hosting, payments, analytics, or security services, including Supabase, Vercel, Upstash, Cloudflare Turnstile, and, when enabled, Stripe and a cookieless analytics provider. If you use optional features, Google sign-in or community explanation-video embeds (YouTube/Vimeo) may also set storage. We do not permit these processors to use SkyStudy data for advertising. See our Privacy Policy for the full processor list and regions.
7. Managing Cookies and Storage
You can manage or remove cookies and local storage from your browser settings. Common controls include:
- Deleting site data for skystudy-related domains
- Blocking non-essential cookies in your browser
- Clearing IndexedDB and cache storage for this site
- Using the in-app offline settings page to remove downloaded question packs and pending answers
Removing essential storage may sign you out, remove offline packs, delete unsynced local answers, or reset preferences on that device.
8. Changes
We may update this policy when we add or remove browser storage technologies. Material changes will be reflected on this page and, where required, communicated through the app.
9. Contact
Questions about cookies or local storage: to2000bv@gmail.com