Cookie Policy
Effective Date: July 27, 2026 · Last Updated: July 27, 2026
This Cookie Policy explains how Lyon Innovations, LLC ("AtListen", "Company," "we," "us," or "our") uses cookies, browser local storage, and similar technologies on AtListen.com and in the AtListen application (collectively, the "Website"). It supplements, and should be read together with, our Privacy Policy, which explains more broadly how we collect, use, and protect personal information.
What Are Cookies and Similar Technologies?
A "cookie" is a small text file that a website asks your browser to store, typically containing an identifier or preference value, so the site can recognize your browser on later visits. Browser "local storage" and "session storage" (accessed through the localStorage/sessionStorage APIs) work similarly in that they persist small pieces of data on your device, but that data is read only by the site's own code rather than being sent automatically to a server with every request. This policy uses "cookies" as shorthand for all of these technologies, consistent with common usage, and calls out below where AtListen specifically relies on local storage rather than a traditional cookie.
AtListen Sets Very Few Traditional Browser Cookies
AtListen.com is a static website with no server-rendered sessions. Apart from the analytics identifiers described under "Analytics" below, we do not write our own first-party document.cookie entries. Instead, your signed-in session, preferences, and in-progress app data are handled through:
- Firebase Authentication, which keeps you signed in using your browser's local storage/IndexedDB rather than a cookie;
- Our own use of
localStorage, described in the categories below, for preferences and app functionality; and - Firestore (our database), which stores your account data on our servers and is not itself a browser cookie.
So where this policy (and common privacy terminology) refers to "cookies," the underlying mechanism on AtListen is, in most cases, local storage rather than a classic HTTP cookie. The practical effect is the same either way — small values are stored in your browser and cleared the same way — and the "clear cookies and site data" option in your browser clears both.
Categories of Cookies and Local Storage We Use
Strictly Necessary
These are required for the Website's core security and sign-in functionality, and cannot be disabled without breaking that functionality:
- Firebase Authentication session data — keeps you signed in between visits so you are not asked to log in on every page.
atlisten_device_id— a random identifier we generate and store in local storage to recognize a browser as a previously-verified "trusted device." This lets us ask for an emailed 6-digit verification code only on a new/unrecognized device or after 30 days, rather than on every sign-in.
Functional
These remember your choices and in-progress work so the Website behaves the way you left it. Examples of what we currently store in localStorage for this purpose include:
- Theme preference (
atlisten-theme) — your light/dark mode choice. - AI provider selection (e.g.
atlisten_chat_model,atlisten_agent_model) — which AI provider (Gemini, ChatGPT, or Claude) you last selected in a given chat interface. - Chat history cache (e.g.
atlisten_agent_chats_<your account ID>) — a local copy of your AtListen Agent chat sessions, so conversations remain available across page reloads. This is a convenience cache, not the only copy of your data — study materials you generate or save are stored in your account. - Onboarding and profile cache (e.g.
atlisten_onboarding_complete,atlisten_preferences,atlisten_user) — a local copy of basic profile or preference information also stored on your account, used so the app does not need to re-fetch it on every page load. - Unsaved draft and session recovery (e.g.
edit_backup_<id>,atlisten_pending_session) — short-lived local backups so an edit in progress, or a study session in progress, is not lost if a tab is closed before it can be saved to your account.
None of this functional local storage is used for advertising, and none of it is sold or shared with third parties.
Analytics
We use two analytics services to understand aggregate site usage, such as which pages are visited and how often:
- Google Analytics, loaded through Firebase Analytics/
gtag.jsfromgoogletagmanager.com. This may set cookies (Google's standard visitor and session identifiers, named_gaand_ga_<id>) to distinguish visitors between sessions and to send usage events to Google's analytics endpoints. - HeyCatch (
heycatch.ai), a product-analytics service built on PostHog, which receives events atin.heycatch.ai. It sets one first-party cookie plus matching local storage and session storage entries, all namedph_<identifier>_posthog, to recognize a returning browser and group its events into a session. Session recording, surveys and feature-flag polling are switched off in our configuration, so HeyCatch does not record your screen or keystrokes and does not receive the content of your uploads, study materials or chats.
If you are signed in, we associate these analytics events with your account identifier, so that we can understand how the product is used by real accounts rather than by anonymous browsers. Where an account belongs to a child under 13, we deliberately send only the account identifier and plan name — never the child's name or email address — and while such an account is still awaiting verifiable parental consent we do not send an account identifier at all. See our COPPA Children's Privacy Policy.
We have not enabled Google Analytics advertising features, such as remarketing or ads personalization, on this property, and we do not use either analytics service for advertising. Our Website's Permissions-Policy header also disables the browser Topics API (interest-cohort=()), which opts out of Chrome's cookie-alternative ad-interest tracking mechanism.
Third-Party Cookies
A few features hand off to a third party's own domain, where that third party may set its own cookies under its own privacy policy, not this one:
- Google Sign-In. Signing in with Google involves a popup or redirect through
accounts.google.comand our Firebase authentication domain, which may set cookies as part of that sign-in handshake. - Stripe. Subscription checkout and billing management happen entirely on Stripe-hosted pages (Stripe Checkout and the Stripe Billing Portal) — we never embed Stripe's client-side scripts or handle card data ourselves. Stripe's hosted pages may set their own cookies while you are on a
stripe.compage, governed by Stripe's own privacy policy.
Do Not Track and Similar Signals
Some browsers offer a "Do Not Track" setting or a Global Privacy Control signal. We do not currently change our behavior in response to these signals. As explained in our California Privacy Policy, we do not sell personal information or share it for cross-context behavioral advertising in the first place.
How to Control or Disable Cookies and Local Storage
Most browsers let you review, block, or delete cookies and site data through their settings (often found under "Privacy," "Site Settings," or "Clear browsing data"). Your browser's developer tools also let you inspect or clear a specific site's local storage directly. Please keep in mind:
- Blocking or clearing storage for AtListen.com will sign you out and reset preferences such as your theme and AI provider choice — Firebase Authentication cannot keep you signed in without it.
- Your account data itself — study sets, flashcards, progress, and billing information — lives in our database, not in your browser, so clearing local storage does not delete your account or its content.
- Blocking third-party cookies may interfere with the Google Sign-In popup flow; signing in with email and password avoids that dependency.
Children's Privacy
See our Privacy Policy for Children Under the Age of 13 for how we handle accounts belonging to users under 13, including verifiable parental consent. The cookies and local storage described in this policy are used in the same way for all accounts, including those subject to that policy.
Changes to This Cookie Policy
We may revise this Cookie Policy from time to time, including as we add or change features that rely on cookies or local storage. We will update the "Last Updated" date above when we do. Your continued use of the Website after a revised policy is posted means you accept the change.
Contact Us
If you have questions about this Cookie Policy, please contact us at:
Lyon Innovations, LLC
9465 Counselors Row, Suite 200
Indianapolis, IN 46240
hello@atlisten.com