Last updated 6 October 2026
This policy covers the EdCal website (edcal.co.uk) and the EdCal application that institutions use to publish course calendars.
In short: we don't use cookies or browser storage to track you, to build a profile of you or for advertising. The website stores nothing in your browser. The application uses one essential cookie on its sign-in service, and stores only what it needs to keep you signed in and to remember a few display choices you make.
The website
The EdCal website sets no cookies and uses no local or session storage. We measure how the site is used, such as which pages are visited, without cookies, storage or identifiers, so we can't use it to identify you. Our privacy notice explains this in more detail.
The EdCal application
Everything listed below is essential: it's needed to sign you in and provide the service, or it remembers a choice you've made.
Cookies
| Cookie | Type | Set by | How long | What it's for |
|---|---|---|---|---|
| __Host-edcal-origin | Essential | Our sign-in service (id.edcal.co.uk) | 30 days | Remembers which institution's EdCal service you last signed in through, so if you go to the sign-in address directly you're sent back to it. It holds that service's web address only, nothing about you |
Browser storage
The application uses your browser's local storage and session storage for the items below. Local storage stays until you sign out, clear it, or the application replaces it. Session storage is cleared when you close the browser tab.
| Item | Where | What it's for |
|---|---|---|
| AccessToken, RefreshToken | Local storage | Keep you signed in. Removed when you sign out |
| pkce_pending_verifiers | Local storage | A one-time check that protects your sign-in. Each entry is removed once used, or after 10 minutes |
| code_verifier, pkce_exchanged_codes | Session storage | The same sign-in check, for the current tab |
| calendar-view-type, calendar-start-date, calendar-end-date | Local storage | Remember the calendar view and dates you last looked at |
| adminPermissionsPageSize, orgUnitHierarchyPageSize | Local storage | Remember how many rows an administrator chose to see in a report |
| hideAdminVideo | Local storage | Remember whether an administrator hid the introductory video |
| edcal.versionReload, edcal.staleBuildReload | Session storage | Reload the page once after we release an update, without looping |
If the application meets an error, it sends us a technical error report so we can fix the problem. Error reporting is set up to use no cookies and no browser storage, and it identifies you only by an internal account number, never by your name or email address.
Signing in with Microsoft or Google
You sign in to the application through your institution's Microsoft or Google account. Microsoft and Google set their own cookies on their own sign-in pages. Those cookies are covered by their policies, not ours.
Why we don't show a cookie banner
The UK's Privacy and Electronic Communications Regulations 2003 (regulation 6) require consent before a website stores information on your device, except where that storage is strictly necessary to provide a service you've asked for.
Everything this policy lists falls within that exception. We don't use cookies or browser storage for analytics, marketing or advertising, and we don't use any third-party tracking. So there's nothing to ask your consent for, and we don't show a cookie banner.
If we ever add anything that isn't essential, we'll ask for your consent first and update this policy.
Removing stored items
Signing out removes the sign-in items. You can remove everything by clearing this site's data in your browser settings. You'll need to sign in again, and the application will forget your display choices.
Contact
Questions about this policy: enquiries@edcal.co.uk. EdCal Ltd, company number 16186215, 128 City Road, London EC1V 2NX.