Cookie Policy

Last updated: August 26, 2026

This Cookie Policy explains how Zimphy LLC (“Zimphy,” “we,” “us,” “our”) uses cookies and similar technologies on our website at https://zimphy.com, including the teacher dashboard, the lesson authoring tools, and the student lesson player.

In short

Zimphy uses a small number of first-party cookies. Most are strictly necessary to operate the site: to keep you signed in, to keep a student connected to the classroom session they joined, and to protect the sign-in process. Two more remember a display setting, and are only set if you change one.

We do not use cookies for advertising. We do not allow third parties to serve advertising or targeting cookies through our website. We do not use tracking pixels or web beacons.

Our website analytics do not use cookies and do not track individuals across websites.

What cookies are

Cookies are small text files that a website stores on your device. They allow a site to remember things between page loads, for example that you have already signed in.

Cookies set by the website you are visiting are called first-party cookies. Cookies set by other companies whose content appears on that site are called third-party cookies. Most cookies on our site are set by Zimphy directly. One is set by our consent manager’s script. No third party sets advertising or tracking cookies through our website.

Similar technologies include browser local storage, which stores data on your device but is not transmitted with every request.

The cookies we use

Most cookies below are set by Zimphy directly. One is set by our consent manager’s script. None are used for advertising, profiling, or tracking you across other websites.

Strictly necessary

These cannot be switched off without breaking core functionality.

Strictly necessary cookies
CookiePurposeDuration
sessionKeeps a signed-in teacher, administrator, or staff user authenticated between page loads. Without it you would be signed out on every request.7 days, renewed each visit
escape_student_sessionKeeps a student connected to the classroom session they joined using the code their teacher gave them. It contains no name, email, or account identifier.30 days
google_oauth_stateA short-lived security value used only during "Sign in with Google" to protect against cross-site request forgery. Discarded once sign-in completes.10 minutes
google_oauth_redirectRemembers which page to return you to after you sign in with Google. Discarded once sign-in completes.10 minutes
pending_planRemembers which subscription plan you selected so that we can take you to checkout once you have confirmed your email address.24 hours

Preferences

These remember a display choice you made. They are set only when you change the relevant setting, never automatically, and they are not used for advertising, profiling, or cross-site tracking.

Preference cookies
CookiePurposeDuration
zimphy_themeRemembers whether you chose light or dark appearance.1 year
zimphy_sidebarRemembers whether you collapsed or expanded the dashboard sidebar.1 year

Consent management

This cookie is created by our consent manager’s script rather than by Zimphy.

Consent management cookies
CookiePurposeDuration
csrf_tokenA security token created by our consent manager's script. It performs no function on our site.30 days

We will update these tables if we add or change any cookie.

Analytics without cookies

We use Vercel Web Analytics to understand which pages are visited and how the site performs. It does not set cookies, does not use device fingerprinting, and does not follow visitors across other websites. It records the page visited, an approximate location derived from the network connection, the referring site, and general device type.

Vercel Web Analytics does not run on the student lesson player. No analytics of any kind load on pages students use.

Identifier-shaped values in page addresses, such as account, lesson, and token identifiers, are removed before any analytics record is created.

Local storage and session storage

Separate from cookies, our site stores some information in your browser’s own storage. Unlike a cookie, this is not attached to every request; the page reads it when it needs it. There are two kinds, and they last for different lengths of time:

  • Local storage has no expiry date. It stays until you clear your browsing data.
  • Session storage is cleared as soon as you close the browser tab.

Our consent manager. Termly, the consent management provider we use, stores your cookie choice in local storage rather than in a cookie. It records which categories you accepted, whether you set a Global Privacy Control or do-not-sell preference, the version of the policy document you were shown, and per-document banner state, so that a banner you have already dismissed is not shown again. That consent record is stored for a maximum of 12 months, after which you are asked again. Local storage has no expiry of its own, so the entry stays on your device until Termly replaces it or you clear your browsing data.

Termly also assigns your browser a persistent visitor identifier: a randomly generated value stored in local storage under __tluid and repeated inside the consent record. It is not a setting you chose. It is a durable identifier for your browser that stays until you clear your browsing data, and it is what allows a consent choice to be recognised as coming from the same browser on a later visit. It is created whether or not you interact with the banner. It is not connected to a Zimphy account. It does not leave your browser, and it cannot be read by any other website, because local storage is restricted to the site that created it. Our consent manager sets no cookie of its own that could link your visits across the sites that use it, and we never send Termly your name, email address, or account identifier.

None of this loads on the pages students use.

On the teacher dashboard. If you use the optional class periods feature, the period names and student names you enter are kept in local storage and stay there. When you create a class session or generate student links, only a randomly generated period identifier and a slot number are sent to our servers. The names appear in the roster views on your screen, in files you choose to export, and in PDFs your browser generates, all of which are produced on your device. Display settings such as sound and music volume are also kept in local storage.

In the lesson authoring tools. Text you have typed into an authoring field is kept in session storage, so it survives a page reload but is discarded when you close the tab. That text is sent to our servers when you run the action it belongs to.

On the student lesson player. The player keeps two things in local storage on the student’s device:

  • A reconnect value issued by our server, which lets a student rejoin the same session after a page reload or a closed laptop lid. It holds nothing but that value. It is sent back to our live session service when they reconnect.
  • A saved progress record, so a student can resume where they left off. It holds their score, items collected, choices made, the display name shown on their screen, and any written answers they typed. It is discarded automatically if the teacher republishes the lesson.

The saved progress record is also sent to our servers. Written answers a student types, the display name shown on their screen, and the choices they make are sent to us as they play and are stored with their anonymous session record. In live and whole-class lesson modes, the group name a student types and their answers are also sent to our live session service, which is operated by Cloudflare.

Students and the lesson player

Students do not create accounts. They join a classroom session using a short code provided by their teacher.

On the pages students use:

  • No analytics, advertising, or marketing technology loads.
  • The only cookie we set is escape_student_session, which keeps them connected to the session they joined.
  • No consent banner is shown, and no optional cookies are set.
  • Cookies set elsewhere on our site are still sent with requests to these pages, because they were set for the whole site. On a shared device where a teacher signed in earlier, that includes their sign-in and display-setting cookies, and any recorded cookie choice. Nothing on these pages reads or replaces them.
  • The player keeps a reconnect value and a saved progress record in the browser’s local storage, described under Local storage and session storage above.

What students type is sent to our servers. In lessons that ask for written reasoning, the text a student types is sent to us and stored with their anonymous session record. In live and whole-class lesson modes, the group name a student types and the choices they make are sent as they play.

Two of our infrastructure providers necessarily receive technical connection data when a student’s browser loads lesson content, in the same way any website’s hosting and content-delivery providers do. Neither sets cookies on our behalf, and neither receives a name, email address, or account identifier for a student:

  • Vercel hosts the website and receives the IP address, browser user agent, and requested page address for each request.
  • Cloudflare delivers lesson media (images, panoramas, audio, video) and receives the IP address, browser user agent, and requested file paths. In live and whole-class lesson modes, a Cloudflare service also runs the session itself and receives the group name a student types, the choices they make, and any written reasoning they enter during the activity.

More detail about what we collect and how long we keep it is in our Privacy Policy.

Advertising and tracking technologies

We do not serve advertising on Zimphy. We do not sell or share personal information for cross-context behavioral advertising. No advertising network, data broker, or social media platform has an advertising or tracking presence on our website.

We do not use web beacons, tracking pixels, or clear GIFs on our website. Our transactional emails (account, billing, and classroom notifications) contain no tracking pixels, and we do not measure opens or clicks on them.

Managing cookies

Cookie preferences. You can review and change your cookie preferences at any time using the Cookie Preferences link in our website footer, or from Privacy and cookies in your dashboard settings. Our preference center lists several standard categories, but we do not place cookies in the advertising, analytics, performance, or social media categories. It will reflect any change to that.

Browser controls. Every major browser lets you block or delete cookies through its settings: look for “Cookies,” “Site data,” or “Privacy” in your browser’s settings or help documentation. Clearing cookies will also reset your appearance and sidebar preferences to their defaults.

Blocking cookies on our website will prevent you from signing in and will prevent students from joining classroom sessions, because the cookies we use are the mechanism by which those things work.

Global Privacy Control. We honor the Global Privacy Control signal where applicable law requires it. Because we do not sell or share personal information for advertising, the signal does not change what we collect.

Changes to this policy

We will update this policy when the cookies or technologies we use change, or for legal or operational reasons. The date at the top shows when it was last revised. Material changes will be noted on the website.

Contact

Questions about this policy or our use of cookies:

Email
support@zimphy.com
Post
Zimphy LLC
7901 4th St N, Ste 300
St. Petersburg, FL 33702
United States
Phone
(561) 444-7211
Cookie Policy | Zimphy · Zimphy