Cookies and Storage

AgentChamp Cookies and Storage Policy

Effective 25 August 2026


The short version

AgentChamp uses two cookies and a set of values stored in your browser. Every one of them is there to make the service work - to keep you signed in, to remember your reading settings, and to stop you losing progress if your connection drops.

We use no advertising cookies, no analytics, no tracking pixels, and no third-party tracking scripts of any kind. There is no Google Analytics, no Meta pixel, no session recording, no heatmapping and no error-reporting service in AgentChamp. Not disabled - absent. There is nothing to opt out of, because there is nothing collecting anything about you for anybody's benefit but your own.

Because everything we store is strictly necessary to provide the service you asked for, UK law (the Privacy and Electronic Communications Regulations, regulation 6(4)) does not require us to ask your permission for it. It does require us to tell you clearly what we store and why, which is what this page is for.

What a cookie is, and what "storage" means here

A cookie is a small file a website asks your browser to keep and send back on later visits. Local storage and session storage are similar, but the values stay in your browser and are never sent anywhere automatically - our own code reads them to draw the page.

Most of what AgentChamp keeps is the second kind. It never leaves your device.

Cookies

Both are set by us. Neither can be read by any script, including ours - the browser will only hand them back to our own sign-in endpoints.

NamePurposeWhy it is necessaryLifetime
sc_refreshKeeps you signed in between visits and lets your session be renewed without typing your password againWithout it, every reader - including a seven-year-old - would have to log in again every time their access token expired7 days for adults, 30 days for pupils
sc_child_refreshThe same, for a child session a parent has started on their own device. Both can exist at once, so a parent does not get signed out when their child starts readingWithout it, a parent would be logged out every time they handed the tablet over30 days

Both are HttpOnly (no JavaScript can read them, which is what protects them from cross-site scripting attacks), SameSite=Lax, Secure in production, and scoped to our sign-in path only. No Domain attribute is set, so they are never shared with any other site.

There are no other cookies. No third party sets a cookie on any page a child can reach.

Local storage

Kept on your device, never transmitted, cleared when you sign out.

Your session and identity
KeyWhat it holdsWhy
userThe signed-in account: id, role, first and last name, avatar name, school and class. For a pupil this includes their real nameSo the page can greet the reader and draw the right navigation instantly, instead of showing an empty shell while it asks the server who you are
parent_userThe parent's own account, held while a child session is active on the same deviceSo the parent is still signed in when the child finishes reading
childMode_childNameThe child's display name during a parent-started sessionSo the screen shows whose reading is on display

The short-lived token used to authorise each request is not stored on disk at all - it is held in memory and disappears when the tab closes.

Reading and display preferences

readerSettings, readingUISettings, pageFlipConfig, epicUIPreferences, agentChamp_themePreference, agentChamp_soundEnabled

Font choice (including the OpenDyslexic, Atkinson Hyperlegible and Lexend accessibility options), text size, page-turn animation, colour theme and whether sound is on. Stored locally so a child who has set up a comfortable reading view keeps it, on that device, without needing an account setting to sync.

Reading progress
KeyWhat it holds
progress-queueReading progress recorded while the connection was down, waiting to be sent. This is what stops a child losing a completed chapter on a patchy school connection
favouriteBooks:<user id>, recentlyOpenedBooks:<user id>The reader's own shortlists, so the library opens where they left off
unlockedAchievements, champion-words-<book id>Local copies of achievements and vocabulary discovered, so a celebration is not shown twice
streak-overlay-last-shown-<user id>, streak-overlay-last-tier-<user id>When the reading-streak message was last shown, so it is not repeated on every page
Technical

FEATURE_FLAG_PAGE_FLIP_ENABLED, FEATURE_FLAG_PAGE_FLIP_DESKTOP_ENABLED, FEATURE_FLAG_PAGE_FLIP_MOBILE_ENABLED, debugEndings - internal switches used to turn features on for testing. They hold no personal data.

agentChamp_storageNoticeAck - records that you have seen the notice explaining this page, so it is not shown on every visit.

Session storage

Cleared automatically when the browser tab closes.

quiz-session-stats-<story id>, quiz-journey-<story id>, story-completed-<story id> - the state of a quiz in progress, so a mis-tap on the back button does not lose a half-finished quiz.

Third-party resources

On pages a child can reach: none from anyone but us. Fonts, scripts and interface graphics load from our own application origin. Story covers and audio load from our own Cloud Storage buckets at storage.googleapis.com - our hosting provider, listed in the Sub-Processor Inventory, seeing the request the same way it sees every other request to our servers.

No advertiser, analytics company, font host or CDN sees a child's device, IP address or browser at any point.

On adult checkout pages only, your browser loads Stripe's payment form directly from Stripe (js.stripe.com, hooks.stripe.com, m.stripe.network). That form includes Stripe's fraud-detection component, which examines the device to help tell a genuine payment from a stolen card. Stripe's own privacy policy governs it. It never loads anywhere a child can go, and we keep it enabled because it is what protects cardholders from fraud.

Until 25 August 2026 this was not the case: display typefaces loaded from Google Fonts and accessibility typefaces from the jsDelivr CDN, on every page including children's, and one fallback graphic came from a placeholder image service. All of those files are now served from our own infrastructure.

Controlling what is stored

You can clear cookies and site data at any time through your browser settings, and you can set your browser to refuse cookies altogether.

Be aware of what that means here: AgentChamp uses this storage to hold your session and your reading progress. If you block it, you cannot stay signed in - there is no version of the service that works without somewhere to keep a session. We are not using that as leverage to extract consent for tracking, because there is no tracking to consent to; it is simply how signing in works.

Signing out clears everything listed above.

Changes

If we ever add a cookie or a stored value, this page is updated before it ships. If we ever added anything that was not strictly necessary - which we have no plans to do - we would ask for your consent first, properly, with a real choice to decline.

Contact

Questions about anything on this page: privacy@agentchamp.co.uk

AgentChamp Ltd, company number 17176256, ICO registration ZC230270 1434 London Road, Leigh-on-Sea, Essex, England, SS9 2UL

AgentChamp keeps you signed in and remembers your reading settings using cookies and browser storage. What we store, in full.