Cookies

Cookie notice

TimesOwl sets a few first-party cookies so practice can continue on this device and so we can count usage ourselves. There are no ad pixels.

Last updated September 18, 2026

What this notice covers

Cookies are small text files a site stores in your browser. TimesOwl uses a few first-party cookies so practice can continue on this device, so we can count visits ourselves, and so the homepage can remember which headline this browser was shown.

This page lists the cookies the app sets. It is part of the privacy policy. It is not a third-party advertising disclosure, because we do not run third-party ads.

How we group them

Larger education sites often split cookies into strictly necessary, analytics, and marketing. TimesOwl is smaller. In that vocabulary:

  • Strictly necessary: `timesowl_session` — without it, the household and active learner do not stick in this browser.
  • Analytics (first-party): `tw_analytics_visit` — a visitor key we store in our own database, not in Google Analytics or an ad network.
  • Product experiment: `tw_hero_exp` — which homepage headline package was assigned. It is not used to advertise on other sites.

We do not currently show a cookie-consent popup. There is nothing in the marketing or advertising bucket to opt into. Browser controls still work; see Your controls.

Cookies TimesOwl sets

These are first-party cookies on timesowl.com (and www.timesowl.com). We set them. They are not set by an ad exchange.

First-party cookies set by TimesOwl
NameWhy it existsAbout how longWho can read it
`timesowl_session`Keeps this browser attached to the household and the active learner. The server stores only a hash of the token.30 daysThe TimesOwl server only (HttpOnly). JavaScript on the page cannot read it.
`tw_analytics_visit`A random visitor key for first-party page views, practice funnel events, and time-on-page. Lets us tell a returning browser from a new one without an email.30 daysTimesOwl’s own JavaScript on this site, and the server. Not HttpOnly, because the tracker in the page has to send the key.
`tw_hero_exp`Remembers which homepage headline this browser was assigned, so a reload does not enroll a second experiment. Crawlers do not get this cookie.30 daysThe TimesOwl server only (HttpOnly). Set when a person loads the homepage.

The session cookie is SameSite=Lax. In production it is also marked Secure. The analytics cookie is set with `SameSite=Lax` from the page; it is not Secure in every environment. The hero cookie is SameSite=Lax and Secure in production.

Cookies and data Cloudflare may set

TimesOwl is hosted on Cloudflare (Workers for the app, D1 for the database, R2 for error screenshots). Cloudflare’s network may set cookies of its own for security or bot management, using names they control (often starting with `__cf` or similar). We do not use those cookies to advertise. Their lifetime and purpose are described in Cloudflare’s own documentation and privacy policy, which we do not copy here so we do not go stale.

Application data itself is not stored in those network cookies. Households, learners, and practice rows live in D1. Error screenshot files live in R2. First-party analytics events live in D1, keyed by `tw_analytics_visit`.

Similar technologies we do not use

We do not embed marketing pixels, social widgets, or other companies’ analytics scripts. We do not drop flash objects or use a tag manager.

Local storage is not how we keep you signed in; the session cookie is. If a browser feature stores UI state, it is not a cross-site identifier we sell.

Fonts ship with the app. We do not call Google Fonts or other font CDNs from the visitor’s browser at runtime.

What the analytics cookie actually records

The visit key is a random id, not your email. Events include page path, event name (for example a practice start), first-touch referrer and UTM fields when a link had them, user-agent, and approximate foreground time. Admin pages are not tracked.

We join that visitor to a caregiver when we can, so we can see which links lead to families who practice — not so we can advertise at a child later. More detail is in the privacy policy analytics section.

Your controls

Every widely used browser lets you delete cookies, block them, or use a private window. If you block all cookies on timesowl.com:

  • Practice will not stay attached to this household. Each visit looks like a new anonymous family, until those records expire.
  • We will not be able to tell that you already started a sitting, and the homepage experiment may assign a headline again.
  • Signing in will not “stick” after you close the tab.

Clearing only `tw_analytics_visit` leaves practice intact and starts a new analytics visitor. Clearing only `tw_hero_exp` may assign a new homepage headline the next time you load `/`. We do not honor a separate “Do Not Track” header with extra behavior, because we already do not run third-party ad tracking. If you want the household deleted, use Settings or email us as described in the privacy policy.

Cookies and children

The same cookies run for a child practicing and for a parent reading the marketing pages. We do not switch to a more invasive set of cookies on the practice screens. We do not use cookies to advertise to children on other sites.

A parent who does not want analytics on a shared device can delete `tw_analytics_visit` or block it. The session cookie is still needed if the child should keep a review schedule on that device.

Changes

If we add a cookie, a consent banner, or a third-party script, this page will list it before that ships to real households. The date at the top of the page is the latest revision.