AtListen
Home Features How It Works Use Cases Pricing About Contact
Get Started
Home Features How It Works Use Cases Pricing About Contact Get Started

Cookie Policy

Effective Date: July 27, 2026 · Last Updated: July 27, 2026

This Cookie Policy explains how Lyon Innovations, LLC ("AtListen", "Company," "we," "us," or "our") uses cookies, browser local storage, and similar technologies on AtListen.com and in the AtListen application (collectively, the "Website"). It supplements, and should be read together with, our Privacy Policy, which explains more broadly how we collect, use, and protect personal information.

What Are Cookies and Similar Technologies?

A "cookie" is a small text file that a website asks your browser to store, typically containing an identifier or preference value, so the site can recognize your browser on later visits. Browser "local storage" and "session storage" (accessed through the localStorage/sessionStorage APIs) work similarly in that they persist small pieces of data on your device, but that data is read only by the site's own code rather than being sent automatically to a server with every request. This policy uses "cookies" as shorthand for all of these technologies, consistent with common usage, and calls out below where AtListen specifically relies on local storage rather than a traditional cookie.

AtListen Sets Very Few Traditional Browser Cookies

AtListen.com is a static website with no server-rendered sessions. Apart from the analytics identifiers described under "Analytics" below, we do not write our own first-party document.cookie entries. Instead, your signed-in session, preferences, and in-progress app data are handled through:

  • Firebase Authentication, which keeps you signed in using your browser's local storage/IndexedDB rather than a cookie;
  • Our own use of localStorage, described in the categories below, for preferences and app functionality; and
  • Firestore (our database), which stores your account data on our servers and is not itself a browser cookie.

So where this policy (and common privacy terminology) refers to "cookies," the underlying mechanism on AtListen is, in most cases, local storage rather than a classic HTTP cookie. The practical effect is the same either way — small values are stored in your browser and cleared the same way — and the "clear cookies and site data" option in your browser clears both.

Categories of Cookies and Local Storage We Use

Strictly Necessary

These are required for the Website's core security and sign-in functionality, and cannot be disabled without breaking that functionality:

  • Firebase Authentication session data — keeps you signed in between visits so you are not asked to log in on every page.
  • atlisten_device_id — a random identifier we generate and store in local storage to recognize a browser as a previously-verified "trusted device." This lets us ask for an emailed 6-digit verification code only on a new/unrecognized device or after 30 days, rather than on every sign-in.

Functional

These remember your choices and in-progress work so the Website behaves the way you left it. Examples of what we currently store in localStorage for this purpose include:

  • Theme preference (atlisten-theme) — your light/dark mode choice.
  • AI provider selection (e.g. atlisten_chat_model, atlisten_agent_model) — which AI provider (Gemini, ChatGPT, or Claude) you last selected in a given chat interface.
  • Chat history cache (e.g. atlisten_agent_chats_<your account ID>) — a local copy of your AtListen Agent chat sessions, so conversations remain available across page reloads. This is a convenience cache, not the only copy of your data — study materials you generate or save are stored in your account.
  • Onboarding and profile cache (e.g. atlisten_onboarding_complete, atlisten_preferences, atlisten_user) — a local copy of basic profile or preference information also stored on your account, used so the app does not need to re-fetch it on every page load.
  • Unsaved draft and session recovery (e.g. edit_backup_<id>, atlisten_pending_session) — short-lived local backups so an edit in progress, or a study session in progress, is not lost if a tab is closed before it can be saved to your account.

None of this functional local storage is used for advertising, and none of it is sold or shared with third parties.

Analytics

We use two analytics services to understand aggregate site usage, such as which pages are visited and how often:

  • Google Analytics, loaded through Firebase Analytics/gtag.js from googletagmanager.com. This may set cookies (Google's standard visitor and session identifiers, named _ga and _ga_<id>) to distinguish visitors between sessions and to send usage events to Google's analytics endpoints.
  • HeyCatch (heycatch.ai), a product-analytics service built on PostHog, which receives events at in.heycatch.ai. It sets one first-party cookie plus matching local storage and session storage entries, all named ph_<identifier>_posthog, to recognize a returning browser and group its events into a session. Session recording, surveys and feature-flag polling are switched off in our configuration, so HeyCatch does not record your screen or keystrokes and does not receive the content of your uploads, study materials or chats.

If you are signed in, we associate these analytics events with your account identifier, so that we can understand how the product is used by real accounts rather than by anonymous browsers. Where an account belongs to a child under 13, we deliberately send only the account identifier and plan name — never the child's name or email address — and while such an account is still awaiting verifiable parental consent we do not send an account identifier at all. See our COPPA Children's Privacy Policy.

We have not enabled Google Analytics advertising features, such as remarketing or ads personalization, on this property, and we do not use either analytics service for advertising. Our Website's Permissions-Policy header also disables the browser Topics API (interest-cohort=()), which opts out of Chrome's cookie-alternative ad-interest tracking mechanism.

Third-Party Cookies

A few features hand off to a third party's own domain, where that third party may set its own cookies under its own privacy policy, not this one:

  • Google Sign-In. Signing in with Google involves a popup or redirect through accounts.google.com and our Firebase authentication domain, which may set cookies as part of that sign-in handshake.
  • Stripe. Subscription checkout and billing management happen entirely on Stripe-hosted pages (Stripe Checkout and the Stripe Billing Portal) — we never embed Stripe's client-side scripts or handle card data ourselves. Stripe's hosted pages may set their own cookies while you are on a stripe.com page, governed by Stripe's own privacy policy.

Do Not Track and Similar Signals

Some browsers offer a "Do Not Track" setting or a Global Privacy Control signal. We do not currently change our behavior in response to these signals. As explained in our California Privacy Policy, we do not sell personal information or share it for cross-context behavioral advertising in the first place.

How to Control or Disable Cookies and Local Storage

Most browsers let you review, block, or delete cookies and site data through their settings (often found under "Privacy," "Site Settings," or "Clear browsing data"). Your browser's developer tools also let you inspect or clear a specific site's local storage directly. Please keep in mind:

  • Blocking or clearing storage for AtListen.com will sign you out and reset preferences such as your theme and AI provider choice — Firebase Authentication cannot keep you signed in without it.
  • Your account data itself — study sets, flashcards, progress, and billing information — lives in our database, not in your browser, so clearing local storage does not delete your account or its content.
  • Blocking third-party cookies may interfere with the Google Sign-In popup flow; signing in with email and password avoids that dependency.

Children's Privacy

See our Privacy Policy for Children Under the Age of 13 for how we handle accounts belonging to users under 13, including verifiable parental consent. The cookies and local storage described in this policy are used in the same way for all accounts, including those subject to that policy.

Changes to This Cookie Policy

We may revise this Cookie Policy from time to time, including as we add or change features that rely on cookies or local storage. We will update the "Last Updated" date above when we do. Your continued use of the Website after a revised policy is posted means you accept the change.

Contact Us

If you have questions about this Cookie Policy, please contact us at:

Lyon Innovations, LLC
9465 Counselors Row, Suite 200
Indianapolis, IN 46240
hello@atlisten.com

AtListen

Where education meets AI.

Product
  • Features
  • Pricing
  • How It Works
  • Use Cases
Company
  • About
  • Contact
Resources
  • Help Center
  • API Docs
  • Study Guides
  • Community
Legal
  • Terms of Use
  • Privacy Policy
  • Children's Privacy Policy
  • California Privacy Rights
  • Copyright Policy
  • Cookie Policy
  • Security
  • Accessibility

© 2026 AtListen. All rights reserved.