What cookies are
Cookies are small text files a website asks your browser to store. Similar technologies, such as local storage and the scripts and frames that other companies serve into a page, work in comparable ways, and this policy covers them too. This policy explains which ones pedagogyfutures.org uses. It sits alongside our Privacy Policy.
How we ask for your choice
When you first visit, a banner asks whether to allow the optional categories below. Nothing optional is loaded until you choose to allow it: "Reject all" and closing the banner both leave them off, and you can still use the whole site. Strictly necessary cookies are always on, because the site cannot work without them.
We ask again when this policy changes or twelve months after your last choice. You can change your mind at any time with the "Cookie settings" link at the bottom of every page, or with the button on this page. If your browser sends a Global Privacy Control signal, analytics stays off unless you switch it on yourself.
Strictly necessary
These keep you signed in, keep forms safe, protect the site from bots and abuse, and remember your cookie choices. The law allows them without consent because the site needs them to do what you ask. The whole site is served through Cloudflare, which provides our content delivery network, DNS, and security; the Cloudflare cookies below are set by that service, and cf_clearance appears only if you are asked to complete a security check.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| authjs.session-token (on HTTPS: __Secure-authjs.session-token) | PedagogyFutures | Keeps you signed in. Holds a signed, encrypted session token. | 30 days |
| authjs.csrf-token (on HTTPS: __Host-authjs.csrf-token) | PedagogyFutures | Protects the sign-in forms against cross-site request forgery. | Until you close the browser |
| authjs.callback-url (on HTTPS: __Secure-authjs.callback-url) | PedagogyFutures | Remembers which page to return you to after you sign in. | Until you close the browser |
| pf_consent | PedagogyFutures | Remembers your cookie choices and the policy version you made them against. | 12 months |
| __cf_bm | Cloudflare | Set by Cloudflare, which sits in front of the whole site, to tell people from bots and protect the site from abuse. | 30 minutes |
| _cfuvid | Cloudflare | Set by Cloudflare to apply rate limits fairly to visitors who share an IP address. | Until you close the browser |
| cf_clearance | Cloudflare | Set only after you pass a Cloudflare security check, so you are not asked to pass it again on every page. | Up to 1 year, as configured in Cloudflare |
| Cloudflare Turnstile | Cloudflare | Checks that a form is being sent by a person rather than a bot. Runs in a frame served from challenges.cloudflare.com, which may use its own cookies or storage. | Set by Cloudflare |
| Stripe Checkout | Stripe | Only when you choose to pay or donate: you are sent to checkout.stripe.com, which sets its own cookies for payment security and fraud prevention. | Set by Stripe |
Analytics
With your permission, we use Google Analytics to understand how people use the site: which pages are visited, how visitors arrived, and roughly where they are (country and region). We set Google Analytics up with Consent Mode, so its script is not loaded at all until you allow analytics. IP anonymization is on, Google signals and advertising features are off, advertising storage and ad personalization are always denied, and its cookies expire after 13 months. Google Analytics never runs on our staff administration pages.
With the same permission, we also count which files are downloaded and how much of each recorded webinar is watched, using our own first-party cookie; no IP address is stored for that.
Without your permission the browser loads no analytics script, sends nothing, and no analytics cookie is set. If you withdraw permission later, we switch Google Analytics off and delete its cookies from your browser, and we expire pf_vid.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| pf_vid | PedagogyFutures | A random ID that lets us count file downloads and recording views without counting one person as many. Set only if you allow analytics. | 12 months |
| _ga | Google (Google Analytics) | Distinguishes one visitor from another so Google Analytics can count visits and pages viewed. Set only if you allow analytics. Advertising features and Google signals are off. | 13 months |
_ga_ plus our measurement ID, for example _ga_ABC123 | Google (Google Analytics) | Keeps the state of your current visit for Google Analytics, such as when it started. Set only if you allow analytics. | 13 months |
Functional (content from other companies)
Some pages include videos hosted by Vimeo or YouTube, and signed-out visitors may be offered Google's sign-in card. These load content from another company, which receives your IP address and may use its own cookies. They stay off until you allow "Embedded content and sign-in". Until then, each video shows a placeholder, and you can load a single video with its "Play video" button without changing your choice for the rest of the site.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| Vimeo player | Vimeo | Plays recorded webinars. Loaded with Vimeo's do-not-track setting, and only after you allow embedded content or press play. Vimeo receives your IP address and may set cookies on its own domain. | Set by Vimeo |
| YouTube player (youtube-nocookie.com) | Plays some embedded videos. Uses YouTube's privacy-enhanced mode, and loads only after you allow embedded content or press play. Google receives your IP address and may store information once you play a video. | Set by Google | |
| Google sign-in prompt (accounts.google.com) | Shows the "Sign in with Google" card on our pages if you are signed in to Google. Loads Google's script, which reads Google's own cookies on its domains. The regular "Continue with Google" button works without this. | Set by Google |
What we do not use
We do not use advertising cookies, tracking pixels, or social media widgets, and Google Analytics is never used for advertising. Our fonts are served from our own domain. Error monitoring (Sentry) does not set cookies. We do not store anything in your browser's local storage or session storage.
Managing cookies in your browser
Besides the "Cookie settings" link, you can block or delete cookies in your browser's settings. If you block strictly necessary cookies, signing in will not work. Deleting the pf_consent cookie means we will ask for your choice again.
Contact us
Questions about cookies go to team@pedagogyfutures.org.