Cookies notice
This notice carries a version number. That number, and the date the version was published, are published in this page's metadata. Each version applies from the moment it is published.
This notice explains how Studee uses cookies and similar technologies (such as web beacons) on studee.com and in the University Application Workspace, how you can control them, and what each one is for. Cookie use is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426) ("PECR"), as amended by the Data (Use and Access) Act 2025, read with Article 7 of the UK General Data Protection Regulation (UK GDPR) on consent. Where the data involved is personal data, the UK GDPR and the Data Protection Act 2018 also apply.
Cookies are small data files sent by a website's server to a web browser and stored there. They can be used for a range of purposes, such as customising a website for a particular user, helping a user navigate a website, improving that user's experience, and storing that user's preferences and sign-in information.
We use cookies to provide a better user experience, to deliver a personalised experience, and to analyse how well our website works so that we can keep improving it. We also look at how visitors move through the site, so that we can understand the problems you may meet and improve how the site behaves.
Your choice
When you first visit studee.com, you see a cookie banner with two equally prominent actions:
- Accept all - we load cookies in all the categories described below.
- Manage preferences - you choose which categories to allow.
No non-essential cookie set by Studee's own code is placed on your device before you make a choice. Video embedded from YouTube behaves differently; see Embedded video.
To refuse every non-essential cookie, follow these two steps.
- Click Manage preferences. The panel opens with preferences, analytics and marketing all off.
- Click Save preferences without turning any of them on.
We then load only the cookies that are strictly necessary for the site to work. The panel never turns a category on for you.
Marketing cookies can only be turned on together with analytics cookies. Both are loaded by the same Google Tag Manager container, and that container only loads once you have allowed analytics, so a marketing-only choice would be a setting we could not act on. In the preferences panel the marketing switch stays off and disabled until analytics is on, with the hint "Turn on analytics to choose this". Turning analytics off again also turns marketing off. Preferences cookies are independent of both.
Google's own tags inside that container are told, category by category, what you allowed, and they follow that signal. We are completing the work that applies the same per-tag control to every other tag in the container. Until that work is finished, allowing analytics may load a marketing tag from one of the advertising companies named under Marketing, even if you have not allowed marketing.
Your choice is recorded in a first-party cookie called studee_consent, set for 12 months. It is set with path=/, so it applies across the whole site, and with SameSite=Lax, so it is sent when you open a studee.com page yourself but not when another website loads studee.com content in the background. It records the categories you allowed, the version of the cookie policy you were shown, and the date and time you made the choice.
Click Cookie preferences in the site footer to change your choice at any time.
Categories
Essential
These cookies are always on. We do not ask for your consent to them, because regulation 6(4)(b) of PECR exempts storage that is strictly necessary to provide the service you have asked for. Their purposes and lifetimes differ, so each one is listed with its own lifetime below.
studee_consent, studee_sessionid, studee_session_resolution and StudeeActivity are always on because the site cannot serve you a working page, or honour the cookie choice you made, without them. studee_browserid is a 12-month identifier our API issues so that the requests your browser makes can be linked to one record across visits, which is how the site keeps your context when you come back to it. We treat it as necessary to run and secure the service, and we keep that classification under review. It is never used for advertising, for cross-site tracking, or to build a profile of you.
All five are first-party cookies set by studee.com. The essential cookies Studee's own code writes to your browser are:
studee_consent- records your cookie choice, the policy version and when you made the choice. Set when you make a choice. Lasts 12 months.studee_browserid- first-party browser identifier issued by our API, used to link the requests your browser makes so your context is kept between visits. Lasts 12 months.studee_sessionid- first-party session identifier that keeps your context across page loads within one visit. Lasts until you close your browser.studee_session_resolution- hands the session details worked out on our server to the app in your browser on first paint. Lasts until you close your browser.StudeeActivity- holds the time you were last active, so your session can be kept in a sensible state. Lasts until you close your browser.
In addition to cookies, we use your browser's session storage - a related technology that, unlike cookies, is never sent to our servers and is cleared when you close the tab - to remember short-lived interface choices such as your selected currency (studee-preferred-currency). This is not used for tracking.
Preferences
Preferences cookies remember small interface choices you have made on the site, for example that you dismissed a promotional banner, so we do not show it again. They are not used for tracking, profiling or measurement. If you refuse preferences, this cookie is not set and the banner appears again.
We ask for your consent to this cookie, rather than treating it as essential, because it is set on a public marketing page you have not signed in to and the page works without it. Interface choices you make inside the signed-in University Application Workspace are handled differently, and the University Application Workspace section below explains why.
The preferences cookie Studee's own code writes to your browser, once you allow preferences, is:
studee_show_programs_universities_hero- remembers that you dismissed the promotional hero on the find-universities page. Lasts until you close your browser.
Analytics
Analytics cookies help us understand how visitors use the site so that we can improve it: which pages are popular, which journeys cause friction, and where errors happen. We use these aggregated insights to decide what to fix, not to identify individual visitors. If you refuse analytics, none of these cookies are set.
Studee's own code writes no analytics cookies. The cookies in this category, for example Google Analytics' _ga and _ga_<measurement id>, are set by tags loaded from our Google Tag Manager container, and only after you have allowed analytics. Google Analytics data is kept for up to 14 months, and the _ga cookie itself lasts for up to 2 years. The names above are examples rather than a complete list; we are working through a full inventory of the third-party cookies our container can set and will list them here.
Embedded YouTube videos are not controlled by your analytics choice. See Embedded video below for what happens with them.
Marketing
Marketing cookies are set by advertising companies so that they and we can measure our campaigns and show you our adverts on other websites. Those companies - Google, Meta, LinkedIn and Microsoft - also use what they collect for their own purposes, such as building advertising audiences and showing you advertising across other sites, under their own privacy notices rather than under this one. They are not acting only for us. If you refuse both analytics and marketing, none of these cookies are set. As explained under Your choice, marketing can only be allowed together with analytics, and until our per-tag control work is finished, allowing analytics may load one of these tags even if you have not allowed marketing.
Studee's own code writes no marketing cookies. The cookies in this category, for example Google Ads' _gcl_au, Meta's _fbp, LinkedIn's bcookie and Microsoft's _uetsid, are set by tags loaded from our Google Tag Manager container, which loads only after you have allowed analytics. As above, these names are examples rather than a complete list, and we will list them in full once the inventory work is finished.
These companies are based outside the United Kingdom, so allowing marketing means information about your visit is sent outside the UK and handled under their own safeguards. Their privacy notices explain what they do with it:
Embedded video
Some of our pages include video hosted by YouTube, which is provided by Google. Because that video comes from YouTube rather than from us, it is worth explaining separately what happens.
The player is served in YouTube's privacy-enhanced mode from youtube-nocookie.com. It loads when the page loads, whatever cookie choice you have made, and your cookie choice on studee.com does not control it. Loading it is a request to YouTube, so YouTube receives your IP address, the address of the page you are viewing, and basic information about your browser, even if you never press play. The cookie banner does not prevent this.
In privacy-enhanced mode, YouTube does not store cookies on your device unless you play the video. If you do play it, you may see names such as VISITOR_INFO1_LIVE, YSC, VISITOR_PRIVACY_METADATA, __Secure-YEC, __Secure-YNID and __Secure-ROLLOUT_TOKEN. The exact set can vary. Anything YouTube stores, and everything it receives, is governed by Google's privacy policy rather than by this notice.
Skip pages with video, or block third-party content from youtube-nocookie.com, to avoid contacting YouTube at all.
University Application Workspace
The University Application Workspace is our separate, signed-in application for students and staff of participating schools. It is reached at /workspace today, and this section applies to it wherever it is served from. Public studee.com pages are covered by the sections above.
The Workspace loads no analytics or marketing tags, and stores two kinds of thing of its own in your browser.
The first is what we need to sign you in and run your account: your session, your sign-in choices, and the checks the service depends on. That storage is strictly necessary to provide the service you have asked for, so it is exempt from the consent requirement under regulation 6(4)(b) of PECR.
The second is a small interface choice you made yourself inside the Workspace - which list page to return to, which panel you collapsed, which Scheme of Learning year to open. We store those only because you made the choice, never for tracking, profiling or measurement, and nothing non-essential is loaded alongside them. They are held in your browser and are never sent to our servers. The ones that survive closing the tab stay until you clear your browser data, and clearing your browser data removes them. This is why the promotional-banner cookie on the public site is gated behind your consent while these are not: that cookie is set on a public page you have not signed in to, and these are choices you made inside a service you asked us to run for you.
Alongside those, the essential cookies listed under Essential above are set for the whole of studee.com with path=/. Where your browser already holds them from the public site, they are sent with your requests to the Workspace as well, and they do the same jobs there. They are always on, they carry no advertising or tracking purpose, and no consent control applies to them. studee_consent is the one the Workspace also writes, as the next paragraph explains.
Where the stored data is personal data, the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025 apply, as described in our Privacy notice, which covers the website and the Workspace.
The Workspace reads and writes the same studee_consent cookie as the public site, because your cookie choice is one choice for the whole of studee.com. You are offered that choice in two places in the Workspace: in the "Essential cookies and your choices" section of the review screen you see when you first sign in and again whenever you are asked to accept a new version of the Terms and conditions, and from the Cookie preferences link in the Workspace footer. A choice you make in either place also applies on the public site, and a choice you made on the public site is shown to you in the Workspace. Allowing analytics or marketing changes nothing inside the Workspace itself, because the Workspace loads no tags in either category.
Click Cookie preferences in the Workspace footer to review or change your choice at any time.
If we ever add a non-essential cookie, storage item or tag to the Workspace, we will add a consent control for it and describe it in this notice in the same release.
Authentication cookie
studee-auth-website- set by the Studee API when you sign in. It holds your session token and is what keeps you signed in. It isHttpOnly(the Workspace's own code cannot read it),Secure(sent only over an encrypted connection), and set withSameSite=Noneandpath=/so that the Workspace and the Studee API, which sit on different web addresses, can both use it. It lasts 60 minutes from the moment it is set and is re-issued each time the Workspace refreshes your session, which happens while you are active or, if you chose Stay signed in, on a schedule. It is deleted when you sign out.
Google sign-in
The Workspace sign-in page offers Continue with Google alongside sign-in by one-time email code. Nothing is loaded from Google until you ask for it. When you click Continue with Google, a short notice tells you that Google will load its sign-in script and may set cookies on Google's own domains, and offers Continue and Cancel. Only if you click Continue do we load the Google Identity Services script from https://accounts.google.com/gsi/client, provided by Google LLC, to show the Google sign-in button and return a sign-in token to us. Loading that script is a request to Google, so Google receives your IP address, the address of the sign-in page and basic information about your browser, whether or not you go on to sign in with Google.
studee_workspace_google_signin- records that you confirmed that notice, so we do not ask again on this browser. Set only when you click Continue. Lasts 12 months.
Cookies and storage that Google sets on its own google.com domains when the script runs are governed by Google's privacy policy, not by this notice. We do not use the script for analytics or advertising. The script is not loaded when you open an invitation link, because invitations are completed with a one-time code only.
Click Cancel on that notice, then sign in with a one-time email code, to keep Google out of your sign-in.
Local storage
Local storage is a browser technology that, unlike cookies, is never sent to our servers. It stays until the Workspace removes it or you clear your browser data. The Workspace writes:
studee.website-auth.snapshot.v1- a cached copy of your session so the Workspace can restore it at start-up, before confirming it with the API. It holds your account reference and display name, your first and last name where we hold them, your student, school-user and school references, your role, your permissions, which service you signed in to, whether you signed in with Google, when you signed in, when the session expires, the session contract version, and the result of the legal-review check, including which version of the terms and conditions you still need to accept and which version of the privacy notice you were shown. Written at sign-in and at each refresh; removed when you sign out or when the session is found to be invalid; ignored once the session it describes has expired.studee.website-auth.inactivity.v1- the time of your last activity in the Workspace, shared between open tabs, so we can warn you and then sign you out after 60 minutes without activity, unless you chose Stay signed in. Removed when you sign out.workspace.auth.sessionLifecycleMode.v1- whether you chose Stay signed in when you signed in (standardorstay_signed_in) and when you chose it. Written at sign-in; removed when you sign out or if the sign-in fails.workspace.schemeOfLearning.lastYear.v1:<your student or school-user reference>- the Scheme of Learning year you last selected, keyed by your student or school-user reference, so the same year opens next time. Written when you pick a year; kept until you clear your browser data.workspace.legal.lastSeenPrivacyVersion.v1:<your account reference>- the version of the privacy notice you were last shown, keyed by your account reference, so we tell you about an update once rather than on every visit. Written when you are shown a privacy-notice update; kept until you clear your browser data.
Session storage
Session storage is like local storage, but it is cleared automatically when you close the browser tab, and it is never sent to our servers. The Workspace writes:
workspace.students.listReturnContext.v1- the students list page you came from, with its filters and sort order, so the list is restored when you go back from a student record.workspace.documents.listReturnContext.v1- the same for the documents list.panel-collapse:student-profile-tasks-notes,panel-collapse:student-application-tasks-notesandpanel-collapse:document-properties-tasks-notes- whether you collapsed the side panel on the student profile, student application and document screens. The key names keep an older label for that panel.workspace.legal.privacyNoticeDismissed.v1- that you dismissed the banner telling you the privacy notice has been updated, so it stays hidden for the rest of the browser session.
Changing your preferences
You can change your choice on studee.com at any time.
- Click Cookie preferences in the site footer.
- Turn on the categories you want to allow.
- Click Save preferences.
When you withdraw a category we had already loaded, we delete the cookies for that category that were set on studee.com, and we reload the page so that the site renders again without that category's tags. Cookies that a provider set on its own web address - for example on google.com or linkedin.com - are not ours to delete. To remove those, and any cookie we have already set, clear your browsing data in your browser with the cookies option selected.
You can also control cookies in your browser. Most browsers let you block all cookies, including essential ones. Note that if you block all cookies, our site will not work or display properly.
The links below explain how to change these settings in some of the most commonly used browsers:
Some browsers, such as Chrome and Firefox, offer a private or incognito mode, which limits what is stored on your machine and deletes cookies placed during that session when you close it. There are also many third-party browser add-ons that block or manage cookies.
Visit tools.google.com/dlpage/gaoptout to opt out of Google Analytics across all websites.
Updates to this notice
If we make a material change to this notice or to the cookie consent policy, for example adding a category or a new cookie, we raise the policy version. A new version applies as soon as it is published; there is no later date on which it starts. When the choice we have stored for you was made under an older version, the banner appears again so that you can make a fresh choice. We never apply an old choice silently to a new policy.
Questions
The Categories section above lists every first-party cookie that Studee's own code writes, grouped by category, and the University Application Workspace section lists everything the Workspace itself stores and says which site-wide essential cookies also reach it. Third-party cookies set by tags in our Google Tag Manager container are described in the same sections, with names given where the inventory work is complete.
Email [email protected] with any question about a specific cookie or this notice.
For anything wider, see Studee's Privacy notice, which covers the website and the Workspace, and our Terms and conditions.