Last updated: 13 August 2026

Cookie policy

KINTAVOR uses technical mechanisms to maintain secure sessions, remember the main device and retain browser preferences.

Current inventory

Necessary first-party cookies: KINTAVOR_PYTHON_AUTOMATION_SESSION for sessions and CSRF, and KINTAVOR_PYTHON_AUTOMATION_DEVICE for the authorised device. Both use Secure, HttpOnly and SameSite=Lax.

The session and main device are security mechanisms. The lab and interface may use browser local storage to retain code, notes and preferences on that device.

The measurement preference is stored in kintavor_google_consent_v2. After a confirmed purchase, an irreversible transaction identifier is stored locally to prevent duplicates; it contains no email address, name or readable Stripe reference.

First-party analytics acceptance is stored separately in kintavor_measurement_consent_v1: previous Google consent does not activate it on its own. kintavor_measurement_anonymous_v1 and kintavor_measurement_anonymous_created_v1 store the browser pseudonym and its creation date, with a non-renewable 90-day expiry. kintavor_measurement_session_v1, kintavor_measurement_session_seen_v1 and kintavor_measurement_session_anonymous_v1 link the analytics session to the pseudonym and record its latest activity; the session changes after 30 minutes of recorded inactivity.

kintavor_measurement_pending_revocations_v1 retains a maximum of 20 pending deletion requests, each with the pseudonym and its original creation and expiry dates. Its sole purpose is to retry remote deletion: it is never reused for analytics. Each request is removed when the server confirms deletion or 90 days after the original creation date; withdrawing permission does not extend that period. Expiry is checked while using the website; if the browser is closed, expired storage is cleared when it is reopened.

Optional measurement is disabled

First-party analytics, Google Analytics and advertising measurement are currently disabled on this UK course. Only necessary security, learning and preference storage is used.

Changing your preference

You can open “Manage cookies” in the footer and choose “Necessary only” to withdraw measurement consent. You can also remove website data through your browser settings. Blocking necessary cookies may prevent sign-in, CSRF protection or main-device control.

When you choose “Necessary only”, the browser removes active analytics identifiers and retains the pseudonym, if it has not expired, solely in the deletion queue until the server confirms deletion or the original expiry date arrives. The server can then remove all its analytics contexts even if the access session has expired. Offline withdrawal takes effect locally at once, but remote deletion requires a request to arrive; the dashboard updates at the next valid synchronisation. This does not delete accounts, purchases or enrolments.