Cookie Policy
Every cookie Sijil sets, why it exists, how long it lasts, and which ones you can refuse without losing anything.
- In effect from
- 2026-08-28
- Last updated
- 2026-08-28
Most cookie policies are written to make a banner legal. This one is written so that you can compare it against your own browser and find it accurate. There are nine cookies in total. Eight of them make signing in and staying signed in work, and one measures how the product is used — that last one is the only one you are asked about, and it is off until you say otherwise. Measurement also leaves four things behind that are not cookies at all, and they are named here too, because a document that stops at the word “cookie” is not a description of what is on your device.
3. Measurement, and the one thing you are asked
We do want to know which parts of the product are used and which are quietly ignored, because that is how the next thing gets built for the madrasa in front of us rather than for the one in our heads. But we are not willing to collect that by default from a school full of children’s records, so it is a question with a real answer rather than a banner that only has one button.
The measurement script is not loaded and then held back — it is not fetched at all until you choose to allow it. If you refuse, or if you simply close the banner without answering, no measurement cookie is ever created and no page view is ever sent. You are not asked again on that browser for a year, and everything in the product keeps working exactly as before.
| What is stored | Where it is kept | Why it exists | How long it lasts |
|---|---|---|---|
| ph_…_posthog | Cookie | Counts a return visit as the same visit rather than a new one, so usage figures are not inflated | 1 year |
| ph_…_posthog | Browser storage | The same measurement state kept a second time, so that it survives the cookie being lost | No expiry — until you withdraw, or clear the site’s data |
| ph_…_posthog | Tab storage | The part of that state which belongs to this one visit rather than to the whole browser | Until the tab is closed |
| ph_…_window_id | Tab storage | Tells one open tab apart from another, so two tabs are not counted as one visit | Until the tab is closed |
| ph_…_primary_window_exists | Tab storage | Marks that one of our tabs is already open, so a second tab does not repeat the same setup | Until the tab is closed |
Two notes for checking that table against your own browser. The ph_ names each carry our measurement project’s key in the middle, and the … stands for it: you will see the full name, identical apart from that part. And “browser storage” and “tab storage” are what your browser’s inspector lists as Local Storage and Session Storage — the same five items under their technical names. Withdrawing at the foot of this page deletes all five, not only the cookie.
4. What the measurement actually sees
On the public website — the pages anyone can read without signing in — measurement means pages viewed, the link that brought you, the browser and the country. Nobody there has a name to attach it to.
Inside the portal it is not anonymous, and calling it anonymous would be the easiest lie in this document to tell. If a member of staff has allowed measurement, what is sent is tied to their account: the account identifier, their name, their role and their madrasa’s name. The address of each page is sent too, and portal addresses contain the identifiers of records — a class, a student. So the provider holds a trail of which staff member opened which record, even though it never receives the record itself: no name of a child, no attendance mark, no fee amount, no photograph, no phone number.
Two smaller pieces load along with the measurement. One can put a short question on the screen inside the product, so a survey can appear on a page without the page itself being changed. The other records clicks that did nothing — a tap on something that looks like a button and is not — which is how a confusing screen gets found without anybody having to write in about it. Both belong to the same permission, and neither is fetched before you give it. A screen recorder is not among them: our measurement provider offers one, and our own code refuses it. It is listed with the other checked absences below.
Separately from any of that, the company that runs our servers records the requests that reach them — the address asked for, the IP address it came from, the browser. Every website on the internet has an equivalent of that log; it is how a server answers a request at all, and it cannot be switched off by refusing a cookie. Our hosting provider also offers its own traffic measurement, and that part is gated by your answer along with everything else, so you do not have to take our word for what it does or does not set — before you agree, its script is not on the page to inspect.
Answer no and none of it loads, so a refusal here is complete rather than partial. Two things follow, and we would rather write them down than wait to be asked. The first is that switching the screen recorder off is a line in our own code and not only a setting in the provider’s dashboard — which matters because a dashboard setting is a switch on somebody else’s server that you have no way to inspect, whereas our code refuses the recorder whichever way that switch is left. The second is our own advice, and it survives the recorder being gone: if you work inside the portal, answer no on the devices you open the register on. The addresses of portal pages carry the identifiers of records, so allowing measurement still leaves a trail of which member of staff opened which class and which child’s page, and that trail is worth more to us than the measurement is.
5. The one script that is not ours
On the pages where a madrasa applies to join Sijil, and only there, the form is checked by Google reCAPTCHA. It is invisible: there is no puzzle to solve. Its job is to tell a madrasa administrator filling in an application from a script filling in a thousand of them, and it is the reason an application form can occasionally refuse a perfectly genuine submission.
That script is Google’s, and whatever it stores in the browser is Google’s to set, name and change — which is exactly why it is not in either table above. We are not going to print a cookie name and a duration for something we do not control and cannot promise will still be true next month. What we can tell you is where it appears and why: two pages, before any account exists, to stop the application form from being abused. It is not measurement, it is not gated by the consent question because it is protecting a form you have chosen to submit, and it plays no part in the portal, the parent view or the public madrasa pages.
Administrators sign in with Google as well, which means Google necessarily knows that an account of theirs was used to sign in to something. That is the trade for never holding an administrator’s password ourselves, and it happens on Google’s own sign-in page rather than on ours.
6. What is kept on your device, which is more than cookies
Sijil is built for a madrasa where the signal comes and goes, so a teacher can mark attendance with no connection at all and the marks travel later. That is only possible because the class list, the students in it, the timetable and the attendance being marked are held in the browser’s own storage on that device. The parent view does the same with the small bundle about that family’s own children. None of it is a cookie, and no consent banner controls it — it is the feature working.
This is the part worth acting on rather than only reading. What is stored on a device stays there until it is cleared, so a phone that has been used to mark a class register keeps that class list until the teacher signs out or the browser’s data for the site is cleared. If a device is shared, or is sold, or leaves the madrasa with someone, signing out is the step that matters — not closing the tab. Opening a register still needs the teacher’s PIN, but the sensible assumption about any shared device is that whatever was put on it is still on it.
Alongside it, the app’s own files — the layout, the fonts, the code — are cached so that it opens on a slow connection instead of showing a blank screen. Those are files, not records, and they say nothing about any person.
7. What is not here at all
A list of absences is only worth printing if each one was checked rather than assumed. Each of these was checked against the code:
- No advertising or marketing cookies, anywhere. There is no advertising pixel, no conversion tag and no ad network in this product, on the public site or inside the portal.
- No screen recording. Our measurement provider sells a recorder that replays what was on the screen, and the option that switches it off is set in our own code, so it stays off whatever that provider’s dashboard is set to. Nobody replays a register.
- Nothing embedded from another website — no video players, no maps, no social widgets, no comment systems. Apart from the measurement described in section 4, which does not arrive until you allow it, the only script on any page that is not ours is the reCAPTCHA on the two application pages named above.
- No cookie that follows you to other websites. What is set here is set by sijil.pk and by your madrasa’s own address, and no other site can read it.
- No record of a child is ever put in a cookie. What the essential cookies hold is a signed session token, a random device identifier, a language choice, short-lived verification marks for the sign-in and class-access steps, and your answer about measurement — no attendance mark, no fee figure, no photograph, no phone number, no student’s name. A name appears in exactly one of them: the five-minute cookie that carries an administrator through Google. If one account administers more than one madrasa, that cookie holds their own Google address and the names of the madrasas they administer, so the page that asks which one they are entering can offer them — and it is gone the moment they choose.
- Nothing is sold or handed to a data broker, an advertiser or an “analytics partner”. What measurement collects is used by us to decide what to build next, and that is the end of it.
- No cookie wall. Refusing measurement withholds no feature, delays nothing and does not bring the question back the next time you visit.
8. Changing your answer
Withdrawing permission has to be as easy as giving it, or the permission was never worth much. At the foot of this page there is a control that hands the choice back to you: press it and the question returns immediately, on this browser, whichever way you answered the first time. If your answer was yes, pressing it also deletes all five of the items in the measurement table above and loads the page again without the measurement script — a script that is already running cannot be unloaded any other way, and stopping it honestly means starting the page over without it. Nothing else about your account changes.
Your answer is remembered per browser and per device, not per person, because a cookie is all there is to remember it with. Saying yes on the office computer says nothing about a teacher’s phone, and each will ask once on its own.
Your browser’s own settings work too: clearing this site’s data removes every cookie in both tables, and the four measurement items that are not cookies along with them, and the measurement question comes back on the next visit. Blocking all cookies is also your right, but be clear about the consequence — the sign-in cookies are in the essential table for a reason, and with cookies blocked the portal cannot keep you signed in from one page to the next.
We do not read the browser’s “Do Not Track” signal, and it makes no difference here: measurement is off until you switch it on, so there is nothing for that signal to switch off.
9. Questions, and where to send them
This document covers the storage side only. What we hold, why we hold it, how long it stays and what rights you have over it are in the privacy policy, which is the fuller answer and is linked at the foot of this page.
There is no madrasa-wide switch for measurement: each browser answers for itself. If your madrasa would rather the answer were no everywhere, as a matter of policy, write to us. That is a reasonable thing to ask for and we would treat it as a change to make rather than a question to deflect.
Anything about this page, including “I cleared my cookies and now the site is asking me again” — which is exactly what it should do — goes to contact@sijil.pk, or +92 371 2633733 if you would rather say it than type it. Urdu or English, whichever you prefer.
Your answer on this browser
Checking this browser…
The answer is kept in one cookie on this browser, so another browser or another phone will ask again.