Cookie Policy
Effective date:
1. What this policy covers
This policy explains the cookies and similar browser-storage technologies Jalees uses on the
marketing site (jalees.io) and in the application (app.jalees.io).
It supplements our Privacy Policy.
2. Categories of cookies
We group cookies into three categories:
- Essential
- Required to deliver the Service. They keep you signed in, protect signup and login forms from automated abuse, and remember your cookie choices. These cannot be turned off through the cookie banner without breaking the Service.
- Analytics
- Help us understand which features are used and where the Service is slow or broken. Off by default; loaded only after you opt in.
- Marketing
- Reserved for any future personalised outreach. Currently unused; would be off by default and require opt-in if ever introduced.
3. Cookies we set
The table below lists the cookies that Jalees and its processors may set in your browser. Provider-set cookies are listed with their typical name; exact names can vary slightly between versions of the underlying SDK.
| Name | Purpose | Category | Duration | Party |
|---|---|---|---|---|
jalees_refresh | HttpOnly, SameSite=Lax session refresh token. Required to keep you signed in. | Essential | Up to 30 days | First-party |
jalees_oauth_state | HttpOnly anti-CSRF state for "Sign in with Google". Set when you start the OAuth flow and cleared when you return. | Essential | 5 minutes | First-party |
PARAGLIDE_LOCALE | Remembers which UI language (English or Arabic) you last selected, so the app renders in that language on your next visit. Set by the Paraglide i18n runtime when you change the language. | Essential (preference) | Up to 400 days | First-party |
cf_chl_*, __cf_bm | Cloudflare cookies. cf_chl_* holds Turnstile challenge state and is set
when you complete a challenge on signup or login. __cf_bm is Cloudflare's
bot-management cookie and is set on requests through their network generally, not only
when you submit a form. Both keep automated abuse off the service. | Essential | Up to 30 minutes | Third-party (Cloudflare) |
ph_jalees (or ph_*) | PostHog anonymous distinct identifier. Set only after you opt in to analytics; used to stitch your visits into a single funnel. | Analytics | Up to 365 days | First-party |
posthog-session-id | PostHog session identifier. Set only after opt-in; expires after 30 minutes of inactivity. | Analytics | 30 minutes (idle) | First-party |
4. Browser storage we use
Besides cookies, the app keeps things in your browser's own storage — localStorage, sessionStorage, IndexedDB and Cache Storage. Like cookies, these
stay on your device and can be cleared from your browser's site-data controls. Almost all of it
exists so the app works the way you left it; none of it is used for advertising. Keys shown with
<…> have one entry per book, video, note or pane.
Your cookie choices
jalees:consent:v1- Your cookie choices and when you made them, so the banner is not shown again on every page.
Record of your consent choices
The entry above is not the only copy. If you are signed in when you answer the banner, we also keep that answer on your account, so that we can demonstrate the consent was given and so that you are not asked again on every device. It is kept even if you clear your browser storage, and it is deleted when you delete your account. Section 2.5 of the Privacy Policy sets out exactly what each entry holds. If you are not signed in, your choice stays on this device only.
Signing in
jalees.link_token-
A short-lived token used while linking a sign-in method. Kept in
sessionStorage, so it is discarded when you close the tab — not inlocalStorage.
Things you have written
jalees.notes.draft.<note>- Unsaved note drafts, one entry per note, kept so a reload does not lose them. This is your own writing rather than a setting: clearing site data discards it.
jalees.siglum.ctan-proxy-version- The LaTeX package-cache generation, used to discard incompatible cached compiler packages after an upgrade.
siglum-ctan-cache- LaTeX packages downloaded for a project, cached in IndexedDB so later previews do not download them again.
Where you had got to
jalees.reader.state.<book>- Your position in a book, one entry per book.
jalees.video.position.<video>- Your position in a video, one entry per video.
jalees.subjects.recent- Recently opened subjects.
jalees.workspace.last- The layout you last had open.
jalees.workspace.split.<pane>- How you sized a split pane.
How the app looks and behaves for you
jalees.sidebar- Sidebar expanded or collapsed.
jalees.reader.fontScale- Reader text size.
jalees.reader.toc- Reader table of contents expanded or collapsed.
jalees.editor.fontScale- Note and source editor text size.
jalees.editor.wrap- Source editor word wrap on or off.
jalees.app.fontScale- App text size.
jalees.chat.wide- Chat panel wide or narrow.
jalees.chat.width- Chat panel width.
jalees:chat:model- Which assistant model you picked.
jalees:chat:effort- Which response effort you picked.
jalees.chatBubble.placement- Where you dragged the chat bubble.
jalees:video-sync-layout- Video/transcript layout.
jalees:video-pip-placement- Where you dragged the picture-in-picture window.
jalees.calculator.open- Calculator open or closed.
jalees.calculator.placement- Where you dragged the calculator.
jalees.calculator.angle- Degrees or radians.
jalees.calculator.memory- The value in calculator memory.
jalees.calendarPanel.open- Calendar panel open or closed.
jalees.calendarPanel.placement- Where you dragged the calendar panel.
jalees.calendarPanel.size- Calendar panel size.
jalees.calendarPanel.deadlinesOnly- Calendar filter: deadlines only.
jalees.calendarPanel.hideDeclined- Calendar filter: hide declined.
jalees.tips.seen- Which tips you have already been shown.
Offline copies you asked for
jalees-offline- An
IndexedDBdatabase holding content you downloaded for offline use. jalees-downloads- Cache Storage: the files behind a download you started.
jalees-api- Cache Storage: recent API responses, so downloaded content opens without a network.
jalees-blocks- Cache Storage: parts of large files, fetched in blocks.
jalees-shell-<build>- Cache Storage: the application itself, so it loads offline. One entry per released build; older ones are removed.
Analytics, only if you accept it
- PostHog keys
-
If you accept analytics, PostHog keeps its own identifiers in
localStorage, including its record of your opt-in. Removed when you withdraw consent.
Your sign-in credential is not in any of these. On the web it is an HttpOnly cookie your browser sends but scripts cannot read; in the mobile apps it is held in the device
keystore (iOS Keychain, Android EncryptedSharedPreferences).
5. How to manage cookies
You can change your cookie preferences at any time by opening the cookie settings panel from the link in our footer ("Cookie settings"). You can also block or delete cookies in your browser's settings, but doing so for essential cookies will prevent you from signing in.
Analytics is provided by
PostHog
(PostHog Inc.), processed in the EU region at eu.i.posthog.com. We honour the
Do Not Track browser signal: if your browser sends DNT, PostHog will not be initialised.
6. Changes to this policy
We may update this policy to reflect changes to our cookie usage. When we do, we will update the effective date above. Material changes that affect how we use non-essential cookies will be re-surfaced through the cookie banner so you can review and re-confirm your choices.