Legal

Cookie Policy

Every cookie we set, what it does, how long it lasts, and which ones wait for your permission. This page is generated from the same list our code uses, so it matches what the code does.

Effective 2026-09-04Version 1.2Companion to the Privacy Policy

Your choice on this browser

Reading your current setting

The page reloads so your change applies immediately.

01

How this works

A cookie is a small text record your browser stores for a website and sends back on later visits. It has a name, a value, an expiry and a set of flags that decide who can read it. Browsers also offer local storage and IndexedDB, which are similar but never leave your device on their own.

We sort every cookie into one of three groups. Necessary cookies keep you signed in, protect your account and record the decision you made on our banner. Functional cookies remember something you did, such as choosing Korean or clicking one of our campaign links. Everything else waits for your consent and stays off until you give it.

We do not run Google Analytics, advertising audiences, session replay, or any cookie of our own that follows you across other websites. The Meta and Naver cookies in Section 3 load only with your consent. Section 2 lists every cookie by name.

  • Necessary

    Set without asking. Needed to sign in, protect your account or record your banner choice.

  • Functional

    Set when you do something that needs them, such as picking a language or clicking one of our links.

  • With consent

    Set only after you press Accept on the banner or Turn on above.

02

Cookies we set

This table is rendered from the same list our code uses. If you find a cookie under tieroneenglish.com that is not here, tell us at privacy@tieroneenglish.com and we will investigate.

  • better-auth.session_tokenNecessary

    Keeps you signed in

    Created by our sign-in library when you sign in. It identifies your session so you are not asked for your password on every request. Refreshed while you keep using the service.

    Set by
    Tier One English
    Lasts
    7 days
    Hidden from page scriptsNamed __Secure-better-auth.session_token on the live site
  • pipa-consentNecessary

    Carries your sign-up consents between steps

    Set when you tick the consent boxes on the sign-up form, at checkout, or when joining a waitlist, to remember them (Privacy Policy, Terms, third-party transfers, marketing) until your account exists. Deleted as soon as those consents are stored with your account.

    Set by
    Tier One English
    Lasts
    30 minutes
  • tt_consentNecessary

    Remembers your answer to the cookie banner

    Stores granted or denied. Every page reads it to decide whether the consent-only scripts may load. Without it we would have to ask on every visit.

    Set by
    Tier One English
    Lasts
    365 days
  • tt_vidNecessary

    Anonymous id for the consent log

    Issued on your first page view, before you answer the banner. A random identifier that on its own identifies nobody. It links your banner decision to the entry in our consent log, which is how we can show what you chose and when if you ever ask.

    Set by
    Tier One English
    Lasts
    365 days
    Hidden from page scripts
  • NEXT_LOCALEFunctional

    Your language choice

    Written when you switch language yourself, or copied from your account preference when we redirect you to your preferred language on a device that has no cookie yet. Lets us open the site in that language next time, including on the dashboard.

    Set by
    Tier One English
    Lasts
    365 days
  • phone-gate-snoozeFunctional

    Remembers that you postponed phone verification

    Set only for signed-in students who chose to add a phone number later. Stops the same prompt appearing on every page for 3 days. Its value is your account id, so it silences the prompt only for you on this device.

    Set by
    Tier One English
    Lasts
    3 days
  • anonDiagnosticSessionIdFunctional

    Links a free diagnostic to the account you create

    Set when you save the result of a diagnostic test you took before signing up. Read at sign-up or sign-in to attach that result to your account and deleted once it is attached. If there is nothing to attach it simply expires after 30 days.

    Set by
    Tier One English
    Lasts
    30 days
    Hidden from page scripts
  • sidebar_stateFunctional

    Remembers whether you collapsed the dashboard sidebar

    Written when you open or close the sidebar so the layout comes back the way you left it. Contains only the word true or false.

    Set by
    Tier One English
    Lasts
    7 days
  • __ttrkFunctional

    Which campaign link you arrived from

    Set when you open one of our campaign links (addresses starting with /r/). If you sign up within 30 days we credit that campaign. Deleted at sign-up.

    Set by
    Tier One English
    Lasts
    30 days
    Hidden from page scripts
  • tier_sessionFunctional

    Groups your campaign clicks into one visit

    A random session id set on the first campaign link you open. It lets us see that several clicks in one visit belonged together. Never linked to a name unless you sign up.

    Set by
    Tier One English
    Lasts
    30 days
    Hidden from page scripts
  • utm_attrFunctional

    The ad or post that brought you here

    Keeps the utm_source, utm_medium, utm_campaign, utm_term and utm_content values from the link you clicked. It is not shared with anyone else; we only read it when you sign up.

    Set by
    Tier One English
    Lasts
    30 days
  • _fbpWith consent

    Meta Pixel browser id

    Set by Meta's script under our domain after you accept. Meta uses it to tell whether an Instagram or Facebook ad led to a sign-up.

    Set by
    Meta
    Lasts
    90 days
    Only after Accept
  • _fbcWith consent

    Meta ad click id

    Set by Meta's script only when you arrive from a Facebook or Instagram ad (the address contains fbclid). Pairs the click with what you do next.

    Set by
    Meta
    Lasts
    90 days
    Only after Accept
  • NaPmWith consent

    Naver ad attribution

    Set by Naver's analytics script after you accept. Lets Naver match a search ad click to a sign-up. Naver publishes its own lifetime for this cookie.

    Set by
    Naver
    Lasts
    Set by vendor
    Only after Accept

Cookies marked "hidden from page scripts" carry the HttpOnly flag, so browser extensions and page scripts cannot read them. All cookies we set ourselves are marked Secure and SameSite=Lax, which means they are only sent over HTTPS and not on requests another site makes in the background.

Our sign-in library also sets short-lived state cookies for a few minutes while you sign in with Google or Kakao. They exist only to complete that sign-in securely and expire on their own.

04

Storage on your device

Some features keep data in your browser without a cookie. Unlike a cookie, it is not attached to every request; a few items (campaign parameters, a pending diagnostic, recordings waiting to upload) are sent when you submit something. It is read and written by code running on your device and cleared when you clear site data.

Local storage

  • Practice and exam progress: your in-progress answers and the end time of any countdown, so a refresh or dropped connection does not lose your work.
  • Drafts of things you are writing: assignment answers (14 days), practice runs, an unsent message to your teacher, and your onboarding answers.
  • Summaries of free practice tests you finished before signing up (score and date, 90 days). The full runs are in IndexedDB below.
  • A copy of dashboard data you have already seen (profile, schedule, group chat, results) so pages open faster. Kept for up to 24 hours, keyed to your account, removed when you sign out. We also keep the id of the last account signed in on this browser.
  • An anonymous device key for free practice, so a later sign-up can claim the history saved on this browser.
  • A diagnostic test you took before signing up (its anonymous session id and the result), waiting to be attached to the account you are about to create.
  • Campaign parameters from the link you arrived on, kept for 30 days or until you sign out.
  • Display preferences: theme, sidebar and pane sizes, audio volume and mute, reading font size and skim speed, camera appearance in live classes, which result tab you last opened, which assistant conversation you last opened, whether you have seen a tutorial or left the assistant panel open.
  • A marker used only while a staff member views your dashboard on your behalf, so the two sessions are never mixed up.

Session storage

  • A note that your diagnostic result has already been verified in this tab, so the check does not run again on every refresh.
  • A flag that we already warned you about recording limits on iOS Safari.
  • If you join a live class as a guest, a ticket for your place in the waiting room.

Cleared when the tab closes.

IndexedDB

  • Full free practice runs you complete on this browser before signing up, kept for up to 180 days or until you sign out.
  • Audio you record during a timed exercise, so a refresh does not lose it. Removed when you submit or, for a test taken before signing up, once it has been attached to your account. Recordings older than 24 hours are cleared when your browser runs low on space.
  • Speaking recordings that are waiting to upload. If an upload fails, the recording is kept for up to 7 days and sent the next time you open the dashboard, then removed.

Apart from the items above, we do not store your profile, group membership or other account details in the browser. Anything not listed here is fetched fresh from our servers each time.

05

Other services with their own cookies

A few features embed another company's page or player. That company may set cookies on its own domain under its own privacy policy. We do not read those cookies and cannot control them.

Toss Payments
At checkout you are sent to Toss's payment page, and on the Mock Pass page Toss loads its card payment widget. Either may set cookies on tosspayments.com for fraud prevention and session continuity.
Google Sign-In
If you sign in with Google, Google sets its own cookies during its sign-in flow. We only receive the identity token that completes the sign-in.
Kakao Sign-In
Same as Google. Kakao sets its cookies on kakao.com and we never see them.
Bunny.net video
Recorded classes, lesson videos and the sample lesson on our marketing pages stream through Bunny.net. Its player may set short-lived cookies for signed links and player state, scoped to its own domain. If a lesson embeds a YouTube or Vimeo video instead, that company sets its own cookies.

Our hosting (Vercel), database (Neon), cache (Upstash) and error reporting (Sentry) set no cookies on your device. Error reports have cookies and sign-in credentials stripped in your browser before they are sent.

07

Where the data goes

Our own cookies are read by servers hosted in Singapore (Vercel, Neon, Upstash). The Privacy Policy's section "Transfers outside Korea" describes these transfers, the safeguards in place and your rights.

Cookies set by Toss, Google, Kakao and Bunny.net stay with those companies. Meta and Naver receive the events described in Section 3 only after you have accepted.

08

Managing cookies in your browser

Every major browser lets you view, block and delete cookies per site or globally. The official guides:

Blocking the sign-in cookie signs you out and prevents signing back in. Blocking the sign-up consent cookie means you are asked to accept the terms again right after signing up. Deleting the banner cookie simply means we ask again.

Private or incognito windows discard all cookies when closed. The service works fully in that mode; you will be signed out and asked about cookies each time.

09

Changes to this policy

We update this page when we add or remove a cookie, change a vendor, or when the law changes. The date at the top always shows the current version. If a change materially affects your rights, we notify you inside the service or by email before it takes effect.

Version 1.2 (September 2026) added the Naver script and the language, campaign-parameter, diagnostic result hand-off, sidebar and phone verification cookies, corrected the sign-up consent cookie lifetime, and corrected the storage durations in Section 4.

10

Contact

Questions or complaints about cookies go to our privacy inbox below. We answer within 10 days.

LORA English Remote Academy (Tier One English)

Business registration 650-94-02234

Representative: Chanhee So

2nd floor, Room 2525, 19 Hakdong-ro 2-gil (Nonhyeon-dong, Sail Building), Gangnam-gu, Seoul, Republic of Korea
Chat with us