Cookie Policy
Last updated: 22 August 2026
Important: Reasora is independent exam preparation software. We are not affiliated with, endorsed by, sponsored by, or connected to Università Bocconi or any other university. “Bocconi” and “Online Bocconi Test” are used only to describe which admissions exam our practice is designed for.
Draft for legal review: This page describes our technical cookie and storage setup. It is not legal advice and does not by itself establish GDPR or ePrivacy compliance. Final wording, retention periods, and lawful bases must be reviewed and approved by qualified privacy counsel.
This Cookie Policy explains how Reasora uses cookies and similar technologies on https://reasora.org. You can change your preferences at any time using Cookie settings in the site footer.
1. What are cookies and similar technologies?
Cookies are small text files stored in your browser. We also use localStorage and sessionStorage for essential study features (for example, resuming a mock exam in the same tab). These storage mechanisms are listed below with their purpose and consent category.
2. Consent categories
- Strictly necessary — required for authentication, security, study session continuity, and storing your consent choice. These run without optional consent because the site cannot function without them. [Confirm lawful basis with counsel.]
- Analytics — optional usage measurement. Scripts in this category load only after you grant analytics consent. No analytics provider is currently configured.
- Marketing / advertising — reserved for future use. No marketing trackers are active today.
3. How to manage consent
On your first visit, a banner at the bottom of the page lets you choose Accept All, Only Necessary, or Manage Preferences. Optional categories are never pre-selected. You can reopen preferences via Cookie Settings in the footer at any time.
No analytics provider is configured in this deployment. Your analytics preference is stored for when a provider is added; no optional analytics scripts run today.
4. Strictly necessary cookies and storage
| Name | Type | Provider | Party | Purpose | Duration |
|---|---|---|---|---|---|
| reasora_consent | cookie | Reasora (first-party) | first-party | Stores your cookie and tracking consent choices so we do not ask again on every visit. | Up to 12 months (configurable — legal review required) |
| reasora_session | cookie | Reasora (first-party) | first-party | Signed session cookie for authentication when running in local demo mode (without Supabase).Applies when: demo | 30 days |
| reasora_progress | cookie | Reasora (first-party) | first-party | Signed cookie storing study progress when running in local demo mode (without Supabase).Applies when: demo | 30 days |
| reasora_ref | cookie | Reasora (first-party) | first-party | Stores a referral code when you arrive via a referral link so a discount may apply to your first qualifying purchase after sign-up. | 30 days |
| sb-*-auth-token (and related Supabase auth cookies) | cookie | Supabase | third-party | Authentication session and refresh tokens when Supabase auth is enabled.Applies when: supabase | Session to ~7 days (Supabase defaults — verify in your project) |
| reasora_mock_{mockId} | localStorage | Reasora (first-party) | first-party | Local backup of completed mock exam results for recovery if server sync fails. | Until cleared by the user or browser |
| reasora_mock_progress_{mockId} | sessionStorage | Reasora (first-party) | first-party | In-progress mock exam answers, timer start, and navigation state within the browser tab. | Until the browser tab is closed |
| reasora_practice_draft_{topic}_{questionId} | sessionStorage | Reasora (first-party) | first-party | Temporary storage of selected (unsubmitted) practice answers within the browser tab. | Until the browser tab is closed |
5. Referral attribution
When you visit the site through a referral link, we store a first-party referral cookie so a qualifying first-purchase discount may apply after you create an account. This cookie is listed in the strictly necessary table above because it is part of how the referral programme operates.
6. Analytics (consent required)
No entries in this category.
When analytics is enabled by the site operator, events may include page views, sessions, approximate location, device/browser type, referral source, and anonymous product events such as mock started or completed. Passwords, payment card data, and authentication tokens are not sent to analytics.
7. Marketing / advertising (not active)
| Name | Type | Provider | Party | Purpose | Duration |
|---|---|---|---|---|---|
| No marketing trackers currently deployed | cookie | N/A | first-party | This category is reserved for future advertising or remarketing technologies. Nothing in this category is active today.Applies when: marketing | N/A |
8. Third-party services
- Supabase (when configured) — authentication cookies; strictly necessary.
- Stripe — loaded when you start checkout; payment processing, not used for optional analytics in this application.
- Plausible (when configured and consented) — analytics script from plausible.io.
- Vercel — hosting; standard server logs may include IP addresses for security and operations. [Describe retention with counsel.]
9. Changes
We may update this Cookie Policy when we add or remove technologies. Material changes should be reflected in the “Last updated” date and, where required, by requesting fresh consent.
10. Contact
Questions: support@reasora.com. See also our Privacy Policy.