Legal documents
Cookies and analytics
This document describes only the cookies, localStorage, sessionStorage, and connected external technologies actually used by LARNES. Third-party web analytics, advertising pixels, and cross-site tracking are not used in the current configuration.
- Status
- Effective
- Data controller
- Индивидуальный предприниматель Бояркин Алексей Станиславович
- Who it applies to
- Public visitors, adult account holders, workspace users, and legal representatives of children using classroom.
Current status
LARNES uses first-party technical cookies and local browser storage for sign-in, security, OTP flows, classroom, workspace and language selection, and interface preferences.
Yandex Metrica, Google Analytics, advertising pixels, tag managers, heatmaps, attribution, and cross-site tracking are not used in the current configuration.
No consent banner exists because optional analytics and advertising categories do not run. A preference centre and consent ledger are mandatory before any such technology is introduced.
Storage technologies
A cookie is a small browser record returned with later requests. An HttpOnly cookie is unavailable to ordinary page JavaScript.
localStorage persists on the device until removal; sessionStorage usually remains through the tab session. They are not automatically sent like cookies, but page code can read them for the requested feature.
Similar technologies include local identifiers, security tokens, external widget load events, and embedded-player technical events.
The native mobile app uses no browser cookies: adult, classroom-device, and child-session tokens are kept in operating-system secure storage.
Data involved
A technical record may contain a signed token, user, child, device, lesson or workspace ID, selected language, interface preference, and expiry.
A network request also exposes IP address, date and time, URL, HTTP headers, browser and device data, and security-check result.
LARNES cookies are not intended to store passwords, CVC, or full card numbers. A signed JWT resists undetected modification but is not described as encrypted storage.
Where identifiers relate to a directly or indirectly identifiable person, LARNES treats them as personal data under the Privacy Policy.
Grounds for use
Essential cookies support a requested feature, user relationship, account protection, and legitimate security interests without overriding user rights.
Separate optional consent is not requested for a record required to perform selected sign-in, OTP, classroom, OAuth, or workspace-selection functionality.
Analytics, advertising, profiling, or other optional identifiers require prior separate, specific, informed, and unambiguous consent.
Current storage register
First-party cookies and browser records:
- session · cookie · first-party LARNES · HttpOnly · authenticated account session and active workspace · duration: 24 hours; renewed on activity when less than 12 hours remain
- register_contact_verified · cookie · first-party LARNES · HttpOnly · carry verified phone or email between registration steps · duration: 30 minutes
- password_reset_verified · cookie · first-party LARNES · HttpOnly · carry successful OTP verification into password reset · duration: 30 minutes
- contact_change_pending · cookie · first-party LARNES · HttpOnly · secure a pending account contact change · duration: 15 minutes
- larnes_sms_device · cookie · first-party LARNES · HttpOnly · first-party device identifier for SMS abuse rate limits · duration: 1 year
- classroom_device · cookie · first-party LARNES · HttpOnly · bind an enrolled classroom or kiosk device · duration: 1 year
- classroom_child · cookie · first-party LARNES · HttpOnly · temporary child lesson session on a classroom device · duration: 12 hours
- LARNES_TEACHER_WORKSPACE · cookie · first-party LARNES · HttpOnly · remember the teacher's selected work mode · duration: 1 year
- LARNES_NETWORK_SCOPE · cookie · first-party LARNES · HttpOnly · remember the selected network or centre data scope · duration: 1 year
- yandex_oauth_connect · cookie · first-party LARNES · HttpOnly · protect an organisation-initiated Yandex CRM OAuth connection · duration: 10 minutes
- NEXT_LOCALE · cookie · first-party LARNES · browser-interface readable · remember the selected interface language · duration: managed by current next-intl browser settings
- interface preferences · localStorage · first-party LARNES · local browser record · remember sidebar and schedule-range UI · duration: until browser storage is cleared
- temporary interface state · sessionStorage · first-party LARNES · local browser record · hold form drafts, trainer launch state, table view, and flash messages · duration: until the tab session ends or the feature clears it
Duration is the current maximum technical life. A record may end earlier on sign-out, process completion, device unbinding, browser clearing, or applicable consent withdrawal.
Sign-in and contact verification
The “session” cookie maintains authenticated access for up to 24 hours and renews on activity when less than 12 hours remain. Sign-out removes it, and server session versioning can revoke an issued token.
The “register_contact_verified” and “password_reset_verified” cookies last up to 30 minutes and carry OTP verification through registration or recovery.
The “contact_change_pending” cookie lasts up to 15 minutes and secures a phone or email change after password verification.
These cookies use HttpOnly and SameSite=Lax; production sign-in and verification tokens use Secure.
SMS protection
The “larnes_sms_device” cookie is a random first-party device ID lasting up to one year for device-level rate limiting and bulk-code abuse prevention.
It contains no phone number, name, or SMS text by itself but may link server-side security events.
It is not used for advertising, interest scoring, or cross-site tracking.
Classroom and child session
The “classroom_device” cookie binds an enrolled classroom device for up to one year; unbinding must invalidate it.
The “classroom_child” cookie creates a temporary lesson session for up to 12 hours and carries child, device, and lesson-session IDs.
Child classroom cookies are essential to the requested lesson and are not used for child analytics or advertising profiles.
Workspace and language
The “LARNES_TEACHER_WORKSPACE” and “LARNES_NETWORK_SCOPE” cookies last up to one year and remember teacher mode and network or centre scope.
The “NEXT_LOCALE” cookie remembers interface language. Its actual lifetime follows current next-intl and browser configuration; this policy does not invent a fixed period.
These values are not used to infer interests, advertise, or assess a person.
Yandex CRM OAuth connection
The “yandex_oauth_connect” cookie is a signed first-party cookie lasting up to 10 minutes. It carries state, PKCE verifier, owner, and return route for an organisation-initiated CRM connection.
Its name does not mean Yandex Metrica or ad tracking is connected. It is created only when that integration starts.
It is deleted or expires after connection completion or error.
localStorage and sessionStorage
localStorage holds only active interface preferences: sidebar state and selected schedule range. They are not used for visitor behavioural tracking.
sessionStorage may temporarily hold a homework-send draft, trainer launch parameters, group column view, CRM error flash, and development-tool state.
A temporary draft can contain user-entered text. On shared devices, finish the session and close the tab; the feature or browser clears it after use or tab-session end.
Cloudflare Turnstile
When enabled, Turnstile loads on OTP-send steps to protect registration and recovery from automated attacks.
Cloudflare receives a verification token, IP address, and browser or device signals required for the check. This is a security function, not LARNES advertising analytics.
Cloudflare's production status, legal entity, address, country, and cross-border-transfer status appear in its service card in the Privacy Policy.
Mux Player
Mux Player is created only after the user opens an internal help video. No playback flow starts before the modal player opens.
To deliver an opened video, Mux receives playback ID, IP, and ordinary network-request data. LARNES explicitly disables Mux Data tracking and Mux cookies in the player, so it does not create a viewer ID or send playback analytics.
Administrative help-video uploads and thumbnails also contact Mux. LARNES does not use it for lesson recording, child uploads, or advertising profiles.
Mux's production status, legal entity, address, country, and cross-border-transfer status appear in its service card in the Privacy Policy.
Analytics and advertising
Public LARNES pages currently load no Yandex Metrica, Google Analytics, social ad pixels, heatmaps, or third-party tag managers.
Security server logs and product technical events are not relabelled as marketing analytics; they are limited to operations, error investigation, and protection.
The internal Analytics workspace calculates organisation operational metrics from PostgreSQL and is not third-party visitor behavioural analytics.
LARNES does not sell cookie identifiers or disclose browsing history to advertising networks.
If optional categories are introduced
Before an optional script loads, the interface must offer equally accessible “Accept selected” and “Reject optional” actions plus purpose-level settings.
Boxes start unchecked; closing, scrolling, silence, or continued use is not consent. Refusal does not block public pages, registration, the free workspace, or payment.
The ledger records user or pseudonymous browser ID, list version, purposes, providers, category choices, time, interface, and withdrawal. The preference cookie itself is essential.
Before consent, no analytics or advertising-provider request, cookie/localStorage write, or IP, URL, referrer, or identifier transfer is allowed.
Changing and withdrawing a choice
Once optional categories exist, a persistent Cookie settings link must make withdrawal as easy as consent.
Withdrawal immediately stops future loading, removes available first-party identifiers, and invokes the provider's opt-out mechanism.
Data previously collected on consent is deleted or anonymised within 30 days of withdrawal unless another legal ground requires limited retention. Withdrawal does not invalidate earlier lawful processing.
Browser controls
The user can inspect, remove, or block cookies and local storage in browser settings. Instructions vary by browser and device.
Blocking essential cookies may sign the user out, reset language or scope, or stop OTP, classroom, or OAuth. Refusing future analytics and advertising must not break those features.
Deleting a record on one device does not delete the server account or other-device data; use sign-out, device unbinding, and Privacy Policy rights for those actions.
Children and shared devices
Child classroom uses only essential lesson and device identifiers by default. Optional child analytics and advertising are disabled.
Any future need requires a separate legal assessment, notice, and consent from the proper subject or representative based on the child's age and capacity. An adult's choice for their own cookies does not cover the child.
On shared devices, adults should end adult sessions and organisations should unbind lost classroom devices. A child must not receive an adult session cookie.
Security and retention
Tokens are purpose- and time-limited, server-signed, and use HttpOnly, SameSite, and Secure where applicable. In production, all authentication, classroom, security, and workspace cookies must travel over HTTPS only.
At purpose end, a record is removed, expires, or is revoked server-side. A long technical lifetime does not permit a new incompatible purpose.
A cookie or local-ID incident follows the Privacy Policy security and notification procedure.
Changes and contacts
Before adding technology, LARNES updates the register with name/type, provider, purpose, data, lifetime, first/third party, ground, countries, and opt-out.
A document change does not enable optional cookies automatically. A new purpose or provider requires a new choice where prior consent does not cover it.
Questions, withdrawal, or identifier requests use the operator contacts on Company details; Roskomnadzor complaint and court protection remain available.