Most cookie pages are long because the site is doing a lot it would rather not spell out. This one is short because Mara sets a single cookie, and that cookie is the thing that keeps you signed in.
We use one cookie, and it exists to keep you signed in. We run no analytics, no advertising pixels, no tag manager and no cross-site tracking of any kind. Nothing about your browsing is sold, shared or profiled.
Because the only cookie we set is strictly necessary to deliver a service you asked for, UK law does not require us to ask your permission for it, and we do not put a consent banner in your way pretending otherwise.
| Name | What it does | Type | Lifetime |
|---|---|---|---|
| mara_srt | Holds your session refresh token so you stay signed in between visits, including when Mara is added to a phone home screen. Set by our server as HttpOnly, Secure and SameSite=Lax, which means no page script can read it and it is never sent to another site. | Strictly necessary | Up to 400 days, or until you sign out |
Signing out clears it immediately.
The legal basis is regulation 6(4) of the Privacy and Electronic Communications Regulations 2003: storage that is strictly necessary to provide a service the user has requested. It is not exempt because it is convenient for us; it is exempt because without it you would be signed out.
Mara also keeps some information in your browser's local storage. This is not a cookie: it never travels to a server with a request, and it is not readable by any other site.
| What | Why |
|---|---|
| Your authentication token, held by our authentication provider | To keep your session alive in the tab you are working in |
| Your first name, avatar and language preference | So the interface is right the moment it loads, before anything is fetched |
| Which room you were last in, and how far through a programme you are | To put you back where you were |
| Whether you have seen the welcome tour, the instructions and the consent screen | So you are not shown them again |
| A draft profile, before you have finished creating an account | So a half-finished sign-up is not lost |
Clearing your browser data removes all of it. You will be signed out and shown the welcome screens again, and nothing else is lost — your account and your work live on the server.
Three providers can set their own cookies, and only on the pages where you actually use them:
| Provider | When | What for |
|---|---|---|
| Stripe | Only on a payment or checkout page | Fraud prevention and completing the payment. Strictly necessary to the transaction you started. |
| Zoom | Only if you use Meeting Observer with Zoom | Running the Zoom meeting component inside Mara. |
| Google Fonts | On page load | Serving the typefaces. No cookie is set; your IP address reaches Google as part of the request. |
None of these is used by us to build a profile of you, and none of them is an advertising integration.
Mara registers a service worker so the interface loads quickly and survives a poor connection. It caches static assets only — icons, the manifest, the shell of the page. It never caches your session content, your recordings or your scores. You can remove it by clearing site data in your browser.
Questions: privacy@thesessionlab.com. See also the Privacy Notice.