Cookie Policy
Last updated: August 11, 2026 · Version 2026-08-11.2
The short version
We set cookies for authentication, consent and region handling, a short-lived dashboard transition flag, and (where enabled) analytics. Equivalent browser storage is listed below as well. You can switch off optional measurement at any time via Legal & Privacy in the footer.
We use no advertising cookies today. If we ever add them, they will be off by default and will stay off unless you turn them on.
1. What cookies are
A cookie is a small file a site stores in your browser so it can recognise your browser on a later request. This policy also covers equivalent technologies such as local storage, which we use for your theme preference and for keeping an in-progress drill from being lost if you reload the page.
2. The three categories
| Category | Can you refuse? | What it covers |
|---|---|---|
| Strictly necessary | No — limited to a feature you request, security, or remembering your choices | Login session, security, daily-attempt controls, and remembering your cookie choices |
| Analytics | Yes | Understanding which pages and features get used, and how the product performs |
| Marketing | Yes — and off by default for everyone | Advertising and remarketing. None currently in use |
3. Every cookie we set
3.1 Strictly necessary
| Name | Provider | Duration | Purpose |
|---|---|---|---|
sb-*-auth-token | Supabase (first party) | Session / refresh cycle | Keeps you logged in. Sent to Supabase with authenticated requests; not used for advertising |
wsm_consent | Wall St Math | 6 months | Stores the cookie choices you made here, so we do not ask again on every visit; sent only as a request cookie to Wall St Math |
wsm_region | Wall St Math / edge | 6 months, refreshed on visits | Stores coarse region classification for consent defaults; sent to Wall St Math, not a precise location |
dashboardSkipInitialLoadingOnce | Wall St Math | Up to 30 seconds / one dashboard transition | Avoids a duplicate loading state after auth navigation; sent to Wall St Math and then cleared |
wsm_daily_id | Wall St Math | 31 days | Pseudonymous identifier for best-effort daily-attempt limiting and abuse prevention; sent to Wall St Math daily endpoints |
wsm_recent_auth | Wall St Math | 10 minutes | Signed, HttpOnly proof that you recently re-entered your password before exporting or deleting account data; sent only to Wall St Math |
These are used only where necessary to provide a feature you request, protect the service, or remember your privacy choice. The consent cookie is itself necessary — we cannot remember that you refused analytics without storing the fact that you refused.
3.2 Analytics
| Name | Provider | Duration | Purpose |
|---|---|---|---|
wsm_anon_id | Wall St Math (first party) | 12 months | A random identifier for first-party analytics measurement; sent to Wall St Math analytics endpoints when analytics is enabled and cleared when analytics is withdrawn. It is not required for account functionality |
_ga | Google Analytics | 2 years | Distinguishes users for Google Analytics where analytics is enabled; sent to Google |
_ga_* | Google Analytics | 2 years | Maintains Google Analytics session state where analytics is enabled; sent to Google |
_gid | Google Analytics | 24 hours | Distinguishes users for Google Analytics where analytics is enabled; sent to Google |
3.3 Marketing
None. We currently run no advertising, remarketing, or conversion-tracking pixels. The category exists in our consent tool so that if we introduce them, they arrive switched off and can only be enabled by you. We will update this page before any such cookie is set for the first time.
3.4 Browser storage (local and session)
| Key | Purpose | Transmission | Duration |
|---|---|---|---|
wall-st-math-theme | Light/dark theme preference | Stays in this browser | Until cleared |
currentSession | In-progress drill state (sessionStorage) | Stays in this browser; submitted drill data is sent to Wall St Math | Up to 15 minutes inactivity / completion |
guestSession | Guest drill state (sessionStorage) | Stays in this browser; result sent when submitted | Until completion, sign-in, or clear |
submittedSessionIds | Prevents duplicate submissions (sessionStorage) | Stays in this browser | Session lifetime |
hasBooted | Skips terminal intro after first view (sessionStorage) | Stays in this browser | Session lifetime |
__wsm_prefetch_auth | Prefetched auth seed (sessionStorage) | Stays in this browser and is consumed by the auth hook | Up to 60 seconds |
__wsm_prefetch_progress | Prefetched dashboard data (sessionStorage) | Stays in this browser and is consumed by the dashboard | Up to 60 seconds |
basicsSession:<userId> | In-progress Basics run (sessionStorage) | Stays in this browser; explicit save may sync results | Until completion or clear |
wsm:sprint:history:v2 / v1 | Local sprint history and legacy migration | Stays in browser; selected runs sync only when saved | Up to 25 runs / until cleared |
wsm:sprint:conversion-intent:v1 | Short-lived sign-in intent | Stays in browser; ID may appear in Wall St Math auth redirect | 24 hours |
wsm-daily-attempt:<date> | Daily result display cache | Stays in browser; attempt sent on submission | Until replaced or cleared |
feature-requests | Feature request drafts | Stays in browser until explicitly submitted | Until cleared |
wallstmath-sound-enabled | Sound preference | Stays in browser | Until cleared |
basicsHistory:<userId> | Basics practice history | Stays in browser; may sync when explicitly saved | Up to 30 entries / until cleared |
sessionHistory | Legacy local session-history cleanup key | Stays in this browser; not used by current sync | Until cleared |
wsm:drill:completions:v1 | Pending authenticated drill completions and recent receipts | Unsynced attempt payloads are sent to Wall St Math until confirmed | Unsynced until confirmed; newest 25 synced receipts for up to 30 days; until cleared |
Browser storage is origin-scoped. We do not sell it or use it for cross-context advertising; transmission occurs only where the purpose above calls for a request or explicit sync.
4. How your choices work
What you are asked depends on where you are, because the law genuinely differs rather than because we treat you differently:
| If you are in | What happens |
|---|---|
| Strict-consent regions (EU/EEA, UK, Brazil, Canada, China, Switzerland, Türkiye, and unknown locations) | Nothing beyond strictly necessary cookies is set until you opt in. Rejecting is exactly as easy and as prominent as accepting |
| Standard regions | Analytics may run under the applicable permitted basis; marketing is off. You can switch analytics off immediately and persistently |
Either way, Your Privacy Choices in the footer leads to privacy settings on any page, and changing your mind takes effect immediately. We ask again after 6 months, or sooner if we materially change what we collect.
Consent and analytics behavior follows the region resolver and current consent implementation. In strict-consent regions, analytics is blocked until opt-in; in standard regions it may run under the applicable permitted basis, with an immediate persistent opt-out in Privacy Choices.
5. Controlling cookies in your browser
You can block or delete cookies through your browser settings — every major browser documents this under Privacy or Settings. Blocking strictly necessary cookies will stop you being able to log in.
Browser-level clearing removes our record of your consent choices too, so you will be asked again on your next visit. Where the consent implementation detects a Global Privacy Control signal, it applies the corresponding non-necessary opt-out; see the in-product Privacy Choices control for current behavior.
6. Related policies
What we do with the data these cookies generate is described in our Privacy Policy. The third parties that receive any of it are listed at /subprocessors.
Questions: hello@wallstmath.com