// DOCUMENT SPECIFICATION
Cookie & Local Storage Policy
Disclosures on session tokens, draft marks cache, and local storage technologies
EXECUTIVE SUMMARY & SCOPE
Transparency statement on essential authentication cookies (__session), Firebase JWT local storage, and offline workbench marks draft caching with zero third-party advertising trackers.
03. How We Use Storage Technologies
We categorize the storage technologies used across our portal into the following functional types:
3.1 Strictly Necessary (Essential) Technologies
These are required for the security, authentication, and core operation of the platform. The platform cannot function properly without them:
__session(Session Cookie): Contains an encrypted Firebase Authentication session token used by our server middleware to verify user identity, role permissions (e.g., School vs. Examiner vs. Admin), and prevent unauthorized access.- Firebase Auth Tokens (IndexedDB / Local Storage): Cryptographic JSON Web Tokens (JWT) used by the client-side Firebase SDK to maintain your active login status without requiring you to re-enter credentials on every page refresh.
- CSRF & Anti-Bot Honeypots: Temporary cryptographic nonces and time-delta verification tokens to prevent spam bot submissions on forms.
3.2 Functional & Operational Preferences
These technologies enhance user experience and remember your workspace state:
- Draft Marks Cache (Session Storage): Temporarily retains draft marks entry input in the workbench to prevent accidental loss if your internet connection experiences momentary disruption.
- UI State (Local Storage): Remembers collapse/expand states of navigation sidebars and table filter settings.
3.3 System Performance & Error Monitoring
- Anonymous application incident logs (error boundary telemetry) to rapidly identify client-side script errors and database timeout events. No sensitive candidate marks are transmitted in error telemetry.