UTalento uses a small number of cookies and similar technologies. Some are necessary for the platform to work. The rest are analytics, and they are optional.
Analytics does not run until you choose. Google Analytics is not loaded before you opt in, so no script is fetched from Google and no request, IP address or identifier reaches Google or PostHog. If you do nothing, analytics stays off.
Strictly necessary (always on)
These cookies are required for UTalento to work. They are not used to track you across other websites, and they are not used for advertising.
| Name | Purpose | Set by | Kept for |
|---|---|---|---|
| sb-…-auth-token | Keeps you securely signed in, so you do not have to log in again on every page | Supabase | Your sign-in session (refreshed while you stay signed in, cleared when you sign out) |
| NEXT_LOCALE | Records the language you chose, so the site opens in it again | UTalento | Your browser session (no expiry date is set) |
| utal_admin | Authenticates our internal admin panel. Set only for our own team, not for students, teachers or employers. Not readable by scripts (httpOnly) | UTalento | 8 hours |
| ea_pass | Holds your early-access place while you finish signing up. Not readable by scripts (httpOnly) | UTalento | The length of your claim window |
| __cf_bm, cf_clearance | The anti-bot check on the sign-up screen. Which of these is set depends on the check Cloudflare runs | Cloudflare | Set by Cloudflare, from 30 minutes up to a year |
The anti-bot check is run by Cloudflare, a US company. When you create an account, your browser loads Cloudflare’s challenge and we send your IP address to Cloudflare to confirm the check was solved by a real browser. Cloudflare receives your IP address, your browser type and the signals from that check, on the sign-up screen only. See our Privacy Policy for what that transfer rests on.
Two things are stored in your browser’s local storage rather than in a cookie. Your cookie decision is stored under the key utalento_cookie_consent_v2, which is how we remember your answer without asking again on every page. Parts of your progress and profile are stored there as well, so the app can resume where you left off on your device. When you are signed in, a copy of that profile is also saved to your account, as described in our Privacy Policy. The local copies stay on your device and are removed when you clear your browser.
Analytics (only with your consent)
Analytics helps us understand how UTalento is used so we can improve it. Nothing in this section runs unless you opt in.
UTalento runs no advertising or ad-targeting tags, and Google’s advertising signals (ad_storage, ad_user_data, ad_personalization) are denied at all times.
| Name | Purpose | Set by | Kept for |
|---|---|---|---|
| _ga, _ga_* | Tells one browser apart from another, so we can count visitors and see which pages help | Google Analytics (measurement ID G-TXLHYE3PLQ) | Up to 2 years (Google’s default) |
| ph_<project-key>_posthog | Recognises the same browser between visits, so we can see which dashboard features get used and where people get stuck | PostHog (hosted in the EU) | 1 year |
PostHog runs in the Space and University sections of the site, including the account gate you see before signing in. It does not load on our public pages, and it does not load on the class-student or teacher dashboards. It is hosted on PostHog’s EU cloud, and requests are proxied through our own domain (/ingest) rather than sent directly to a third-party host. Autocapture and session recording are switched off, so it does not record your screen and does not capture the text of the elements you click. It is linked to your account’s random user id once you are signed in, and to a random device id before that, never to your name or email address.
Activity data in your account
Separately from cookies, UTalento records what you do inside the product: which activities you open, complete and save. This is not a cookie, it is stored in your account, and it is not covered by the analytics choice above. It is used to show you your own progress and to build the aggregated insights described in our Privacy Policy, which also sets out the legal basis for it and how long we keep it.
Your choice
Declining is as easy as accepting. Both are a single click, side by side, with the same visual weight. Closing the banner or ignoring it counts as a decline.
You can change your decision at any time from this page, with the button below, or through “Cookie settings” in the footer. Withdrawing takes a single click, the same as accepting.
If you decline, or if you accept and later withdraw, we stop collecting and also remove what was already stored. We delete the analytics cookies on your device (_ga, _ga_*, _gid, _gat and ph_*), clear PostHog’s entries from your browser’s local and session storage, and switch Google Analytics off in the page you are on, so it stops sending data to Google even if its script has already loaded.
We keep a record of the decision itself: a random consent id, whether analytics was accepted, which version of the banner was shown, in which language, when it was decided, your browser’s user-agent string, and your user id if you were signed in. We keep this so we can demonstrate that consent was given or withdrawn, as the law requires. No IP address is stored.
The decision is versioned. If we add a new analytics tool or a new purpose, the previous answer no longer applies and you are asked again.
Declining analytics does not change what UTalento does for you. The necessary cookies keep working and no feature is withheld. You can also clear and block cookies in your browser settings.