Cookies
A short list, because there is a short list. Pallara sets no advertising cookies and carries no third-party trackers.
Last updated 18 August 2026
There is no consent banner because there is nothing to consent to. Every cookie Pallara sets is strictly necessary to sign you in and keep you signed in safely. We run no advertising, no analytics vendor and no cross-site tracking.
Cookies in the platform
| Cookie | Purpose | Life |
|---|---|---|
| Session | Keeps you signed in after you authenticate. Without it, every page would ask you to sign in again. | Session, or up to 30 days if you choose “remember me” |
| Multi-factor verification | Records that you have completed a second authentication factor, so you are not challenged on every page. | Up to 24 hours |
| CSRF token | Protects against cross-site request forgery — an attack where another site tries to act as you. | Session |
| Tenant view | Set only when a platform administrator is viewing an institution in read-only support mode. Signed, short-lived, and every use is written to the audit log. | 15 minutes |
All are set with the Secure and HttpOnly flags where applicable, and an
appropriate SameSite policy.
Storage on your device
The platform also stores small amounts of data in your browser's local storage — your interface preferences, pinned navigation items, and a cached copy of your place in a course so it survives a lost connection. This never leaves your device except where it syncs your lesson progress to your own account, so it follows you between the web and the mobile app.
This marketing site
Sets no cookies. Fonts are loaded from Google Fonts, which will see your IP address as part of serving them. There is no analytics, no pixel and no tag manager.
Controlling cookies
You can block or delete cookies in your browser settings. Blocking the cookies above will stop you signing in to Pallara, because they are how signing in works.