Cookie and Storage Policy
Last updated 4 September 2026
IELPS uses the term “storage technology” for cookies, local/session storage, SDK storage, pixels and similar device identifiers. The machine-readable storage inventory is the authority for name, host, provider, purpose, fields, lifetime, party, lawful basis, consent category, age rule and evidence.
Default behaviour
Analytics mode defaults to off. Unknown storage is blocked. Strictly necessary storage may operate only for security, authentication, load balancing, fraud prevention, user-requested settings or checkout. Non-essential analytics, personalisation or marketing storage cannot be set before the required consent. Child surfaces prohibit advertising storage, cross-context tracking and session replay.
Query strings, tokens, email addresses, account/child identifiers, free text, lesson answers and audio must be removed before telemetry. IP handling, truncation and retention must follow the approved inventory. Consent withdrawal stops future non-essential collection and creates an audit event; it does not falsify historical consent evidence.
User controls
The consent interface must offer equally accessible accept, reject and granular choices where consent is required. Essential storage cannot be disabled through the preference tool but must be explained. Changing a storage purpose, provider, lifetime or data field requires a new inventory version and, where legally required, renewed consent.
Inventory
The published policy must be generated from approved storage inventory records, not hand-written duplicates. It must show technology name, host/provider, purpose, category and lifetime, plus the policy effective date and contact route. Empty or unverified inventories fail publication.