1. What a cookie is

A cookie is a small text value that a website or related service can ask a browser to store. Cookies can be used for necessary functions, preferences, security, analytics, advertising or other purposes. Similar storage can include localStorage, sessionStorage, device identifiers or server-side identifiers.

2. Current production state

The current larexod.top code does not intentionally set analytics, advertising or personalisation cookies. Google Analytics 4, Google Tag Manager, Cookiebot and reCAPTCHA are not active because no valid identifiers were provided. Google Maps is not configured. No affiliate tracking URL is active.

3. PHP sessions

The contact form does not start a PHP session and therefore does not intentionally require a PHP session cookie. The form uses server-side validation, a hidden honeypot field and a timestamp field instead.

4. localStorage and sessionStorage

The interactive habit checklist and resource filters are implemented in JavaScript but are not persisted to localStorage or sessionStorage. Selections disappear when the page is refreshed or closed. The site does not currently use browser storage to profile reading behaviour.

5. Essential infrastructure

A hosting provider, CDN, firewall or security service may use strictly necessary technical cookies or identifiers outside the codebase delivered here. Those provider-level settings were not supplied, so this policy does not invent their names or durations. The operator should review the live hosting stack before publication and update this page if necessary.

6. Analytics cookies

No GA4 Measurement ID is configured, so Google Analytics scripts are not loaded. If GA4 is enabled later, the site should determine the appropriate consent and data-protection configuration for Kenya and any other relevant jurisdiction before loading analytics for users.

7. Tag management

No Google Tag Manager container ID is configured, so GTM is not loaded. Tag managers can deploy many different technologies; therefore the privacy and cookie impact depends on the tags actually placed inside the container. A future GTM deployment must be audited rather than described generically.

8. Advertising and affiliate tracking

The business model is identified as affiliate publishing, but no active affiliate partner or URL is present. This version does not set affiliate cookies or tracking parameters. If future partner links use cookies, click identifiers, server-to-server tracking or another attribution mechanism, this policy and the Affiliate Disclosure should describe the actual implementation.

9. Cookiebot and consent platforms

No Cookiebot Domain Group ID has been provided, so Cookiebot is not active. A consent platform should not be loaded with a fake ID. If a platform is added, categories and declarations must match the real technologies on the site.

10. reCAPTCHA

No reCAPTCHA site key has been provided. The contact form therefore uses local anti-spam measures rather than loading Google reCAPTCHA. If reCAPTCHA is enabled in future, the Privacy Policy and this page should be updated to reflect the related third-party processing.

11. Google Maps

Google Maps is not embedded. The website can display the provided address as text without loading a map service. This avoids describing map-related data transfers that do not occur.

12. Browser controls

Browsers usually allow users to view, block and delete cookies. Blocking all cookies can break features on websites that require them. On the current Larexod codebase, the main content and contact form are designed not to depend on non-essential cookies.

13. Consent and withdrawal

Because no non-essential cookie technologies are enabled in this version, there is no cosmetic consent banner pretending to control services that are not present. If non-essential technologies are introduced, the operator should add an appropriate consent mechanism where required and make withdrawal as straightforward as giving consent.

14. Changes

This Cookie Policy must be reviewed when analytics, advertising, affiliate tracking, embedded media, maps, reCAPTCHA, user accounts or new storage technologies are added.

15. Contact

Questions about cookies or browser storage can be sent to [email protected].

16. First-party and third-party technologies

A first-party cookie is generally set in the context of the domain you are visiting; a third-party technology is provided by another service. The current site code does not intentionally deploy non-essential first-party analytics cookies or third-party advertising cookies. If that changes, the operator should list the actual provider, purpose, category and relevant duration instead of using a generic cookie table.

17. Typical cookie duration categories

Cookies are often described as session cookies, which normally expire when a browsing session ends, or persistent cookies, which remain until a set expiry time or deletion. Because the current code does not intentionally set non-essential cookies, this page does not invent expiration periods. Provider-level infrastructure should be reviewed on the live host before publication.

18. Server-side identifiers are not always cookies

Some systems can recognise requests using server logs, security tokens, URL parameters or network-layer identifiers without storing a traditional browser cookie. Cookie compliance should therefore be based on the real technical architecture, not only on a browser's cookie list.

19. Email links and telephone links

Clicking a mailto or telephone link can open software on your device. Larexod does not use those links as advertising trackers in the current code. Your email or phone application may process data under its own settings and provider terms.

20. Embedded media

The current site does not embed YouTube, social-media feeds or other third-party players that automatically load external tracking code. If embedded media is added later, it should be audited because simply displaying a third-party player can create new requests, identifiers or cookies before the user interacts with it.

21. Consent categories if non-essential technology is introduced

A future consent interface should use categories that match real technologies—for example necessary, preferences, analytics and advertising—rather than offering meaningless switches. Technologies that require consent should remain blocked until the relevant choice has been made where applicable.

22. Consent Mode

Google Consent Mode does not have a standalone measurement ID. If Google tags and a consent-management platform are later enabled, the implementation should set appropriate consent states for analytics storage, ad storage, ad user data and ad personalisation according to the site's actual legal and technical configuration.

23. Global Privacy Control and browser signals

Browsers and extensions may send privacy preference signals. The current site does not run advertising or behavioural profiling code that would create a separate opt-out workflow. If targeted advertising or sale/sharing concepts become relevant in another jurisdiction, those signals should be reviewed as part of the compliance design.

24. Clearing stored data

Users can generally remove cookies through browser privacy settings, site-data controls or private-browsing modes. Clearing storage can sign users out of sites or reset preferences. On the current Larexod build, the main educational content does not depend on saved preferences.

25. Auditing after deployment

The operator should check the live site with browser developer tools or a suitable cookie scanner after deployment, because hosting layers, security products and later configuration changes can introduce requests not visible in the source package. The published policy should match what the browser actually receives.

26. Contact and preference questions

If you believe the live site is setting a cookie or similar identifier that is not described here, contact [email protected] with the page address and, if possible, the cookie name or provider. That makes it easier to investigate the actual behaviour rather than guess.