Cookie Policy
Last Updated: August 16, 2026
1. What this page covers
Cookies are small text files a website stores on your device. This page explains which cookies Tingyin sets, what they are for, and how long they last. It also covers the other browser storage Tingyin uses, because the same privacy law covers it.
2. Strictly necessary cookies
These two cookies make signing in and keeping your session safe possible. Tingyin cannot work without them, and they are always set when you use an account.
| Name | Purpose | Duration |
|---|---|---|
accessToken | Keeps you signed in across visits. HttpOnly, so page scripts cannot read it. | 1 year |
_csrf | A security token that protects against cross-site request forgery. | Session |
3. Analytics cookies
Tingyin uses PostHog to understand how the app is used and to catch errors. PostHog runs in your browser and stores a first-party cookie on this site. These cookies are not set until you accept analytics cookies on the banner or on the cookie preferences page. If you reject, PostHog does not run at all.
| Name | Purpose | Duration |
|---|---|---|
ph_<key>_posthog | PostHog product analytics: remembers the visitor and the session so usage can be measured. | 1 year |
__ph_opt_in_out_<key> | Set only if you turn analytics off after having accepted: it records that choice so PostHog stays off on later visits. | 1 year |
4. Browser storage Tingyin uses
Progress, preferences, and the analytics choice are kept in your browser's local or session storage. These are not cookies, but they are listed here for completeness.
| Key | Purpose | Type |
|---|---|---|
tingyin.progress.v1 | Your training progress when you train without an account. This is how “no account, progress kept on this device” works. | Local storage |
tingyin.progress.outbox.v1 | Answered items waiting to be synced once you sign in and enable progress sync. | Local storage |
tingyin.cookie-consent.v1 | Your cookie consent choice. | Local storage |
tingyin:blog-reaction:<slug> | Remembers whether you reacted to a blog post. | Local storage |
vl_blog_*_dismissed_<slug> | Remembers that you dismissed a blog call-to-action. | Session storage |
5. Cookies set by third-party services
Third-party services we use may store their own cookies when you interact with them.
| Service | When it loads | Cookie |
|---|---|---|
| Google reCAPTCHA | Only when you submit the sign-in or sign-up form, to check the submission is not automated abuse. | _GRECAPTCHA |
| Apple Sign-In | On the sign-in page, to offer signing in with Apple. | Cookies Apple sets on its own domains |
| Google Sign-In | On the sign-in page, to offer signing in with Google. | Cookies Google sets on its own domains |
We do not control these cookies. Google's policy is at policies.google.com/privacy and Apple's at apple.com/legal/privacy.
6. Changing your choice
You can change whether analytics cookies are set at any time on the cookie preferences page. You can also clear cookies and site data in your browser settings. Blocking the strictly necessary cookies will stop you from signing in, but the training page works without an account.
7. Contact
Questions about this policy? Contact us at kubo5922@gmail.com.
Related: Privacy Policy | Terms of Service | Cookie Preferences