Jalees

Cookie Policy

Effective date:

1. What this policy covers

This policy explains the cookies and similar browser-storage technologies Jalees uses on the marketing site (jalees.io) and in the application (app.jalees.io). It supplements our Privacy Policy.

2. Categories of cookies

We group cookies into three categories:

Essential
Required to deliver the Service. They keep you signed in, protect signup and login forms from automated abuse, and remember your cookie choices. These cannot be turned off through the cookie banner without breaking the Service.
Analytics
Help us understand which features are used and where the Service is slow or broken. Off by default; loaded only after you opt in.
Marketing
Reserved for any future personalised outreach. Currently unused; would be off by default and require opt-in if ever introduced.

3. Cookies we set

The table below lists the cookies that Jalees and its processors may set in your browser. Provider-set cookies are listed with their typical name; exact names can vary slightly between versions of the underlying SDK.

Name Purpose Category Duration Party
jalees_refresh HttpOnly, SameSite=Lax session refresh token. Required to keep you signed in. Essential Up to 30 days First-party
jalees_oauth_state HttpOnly anti-CSRF state for "Sign in with Google". Set when you start the OAuth flow and cleared when you return. Essential 5 minutes First-party
PARAGLIDE_LOCALE Remembers which UI language (English or Arabic) you last selected, so the app renders in that language on your next visit. Set by the Paraglide i18n runtime when you change the language. Essential (preference) Up to 400 days First-party
cf_chl_*, __cf_bm Cloudflare cookies. cf_chl_* holds Turnstile challenge state and is set when you complete a challenge on signup or login. __cf_bm is Cloudflare's bot-management cookie and is set on requests through their network generally, not only when you submit a form. Both keep automated abuse off the service. Essential Up to 30 minutes Third-party (Cloudflare)
ph_jalees (or ph_*) PostHog anonymous distinct identifier. Set only after you opt in to analytics; used to stitch your visits into a single funnel. Analytics Up to 365 days First-party
posthog-session-id PostHog session identifier. Set only after opt-in; expires after 30 minutes of inactivity. Analytics 30 minutes (idle) First-party

4. Browser storage we use

Besides cookies, the app keeps things in your browser's own storage — localStorage, sessionStorage, IndexedDB and Cache Storage. Like cookies, these stay on your device and can be cleared from your browser's site-data controls. Almost all of it exists so the app works the way you left it; none of it is used for advertising. Keys shown with <…> have one entry per book, video, note or pane.

Your cookie choices

jalees:consent:v1
Your cookie choices and when you made them, so the banner is not shown again on every page.

Record of your consent choices

The entry above is not the only copy. If you are signed in when you answer the banner, we also keep that answer on your account, so that we can demonstrate the consent was given and so that you are not asked again on every device. It is kept even if you clear your browser storage, and it is deleted when you delete your account. Section 2.5 of the Privacy Policy sets out exactly what each entry holds. If you are not signed in, your choice stays on this device only.

Signing in

jalees.link_token
A short-lived token used while linking a sign-in method. Kept in sessionStorage, so it is discarded when you close the tab — not in localStorage.

Things you have written

jalees.notes.draft.<note>
Unsaved note drafts, one entry per note, kept so a reload does not lose them. This is your own writing rather than a setting: clearing site data discards it.
jalees.siglum.ctan-proxy-version
The LaTeX package-cache generation, used to discard incompatible cached compiler packages after an upgrade.
siglum-ctan-cache
LaTeX packages downloaded for a project, cached in IndexedDB so later previews do not download them again.

Where you had got to

jalees.reader.state.<book>
Your position in a book, one entry per book.
jalees.video.position.<video>
Your position in a video, one entry per video.
jalees.subjects.recent
Recently opened subjects.
jalees.workspace.last
The layout you last had open.
jalees.workspace.split.<pane>
How you sized a split pane.

How the app looks and behaves for you

jalees.sidebar
Sidebar expanded or collapsed.
jalees.reader.fontScale
Reader text size.
jalees.reader.toc
Reader table of contents expanded or collapsed.
jalees.editor.fontScale
Note and source editor text size.
jalees.editor.wrap
Source editor word wrap on or off.
jalees.app.fontScale
App text size.
jalees.chat.wide
Chat panel wide or narrow.
jalees.chat.width
Chat panel width.
jalees:chat:model
Which assistant model you picked.
jalees:chat:effort
Which response effort you picked.
jalees.chatBubble.placement
Where you dragged the chat bubble.
jalees:video-sync-layout
Video/transcript layout.
jalees:video-pip-placement
Where you dragged the picture-in-picture window.
jalees.calculator.open
Calculator open or closed.
jalees.calculator.placement
Where you dragged the calculator.
jalees.calculator.angle
Degrees or radians.
jalees.calculator.memory
The value in calculator memory.
jalees.calendarPanel.open
Calendar panel open or closed.
jalees.calendarPanel.placement
Where you dragged the calendar panel.
jalees.calendarPanel.size
Calendar panel size.
jalees.calendarPanel.deadlinesOnly
Calendar filter: deadlines only.
jalees.calendarPanel.hideDeclined
Calendar filter: hide declined.
jalees.tips.seen
Which tips you have already been shown.

Offline copies you asked for

jalees-offline
An IndexedDB database holding content you downloaded for offline use.
jalees-downloads
Cache Storage: the files behind a download you started.
jalees-api
Cache Storage: recent API responses, so downloaded content opens without a network.
jalees-blocks
Cache Storage: parts of large files, fetched in blocks.
jalees-shell-<build>
Cache Storage: the application itself, so it loads offline. One entry per released build; older ones are removed.

Analytics, only if you accept it

PostHog keys
If you accept analytics, PostHog keeps its own identifiers in localStorage, including its record of your opt-in. Removed when you withdraw consent.

Your sign-in credential is not in any of these. On the web it is an HttpOnly cookie your browser sends but scripts cannot read; in the mobile apps it is held in the device keystore (iOS Keychain, Android EncryptedSharedPreferences).

5. How to manage cookies

You can change your cookie preferences at any time by opening the cookie settings panel from the link in our footer ("Cookie settings"). You can also block or delete cookies in your browser's settings, but doing so for essential cookies will prevent you from signing in.

Analytics is provided by PostHog (PostHog Inc.), processed in the EU region at eu.i.posthog.com. We honour the Do Not Track browser signal: if your browser sends DNT, PostHog will not be initialised.

6. Changes to this policy

We may update this policy to reflect changes to our cookie usage. When we do, we will update the effective date above. Material changes that affect how we use non-essential cookies will be re-surfaced through the cookie banner so you can review and re-confirm your choices.