Cookie Policy

Effective Date: 26 May 2026  |  Last Updated: 17 June 2026  |  Version: 1.6

1. Introduction

KarmaPSC Coaching ("KarmaPSC", "we", "us", or "our") uses cookies and similar technologies on karmapsc.com, karmapsc.com/learn, and qr.karmapsc.com to operate logins, protect sessions, support mock tests and assessment papers, remember consent preferences, and measure site usage where the User has permitted analytics. Transactional email delivery providers, including Resend SMTP, do not set browser cookies through the Platform merely because an account email is sent.

This Cookie Policy explains what cookies are, which cookies we use and why, how consent works, how cookies are scoped across the Platform's domains and subdomains, and how the User can manage preferences.

This Policy is intended to align with India's digital personal data and electronic-record framework, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.

This Policy should be read together with our Privacy Policy and Terms of Service.

2. What Cookies Are

Cookies are small text files stored in a browser or device when a website is visited. They help the website remember a session, preserve preferences, keep the User signed in, or measure how the site is used.

Similar technologies may include local storage, session storage, pixel tags, and browser identifiers. This Policy uses the term "cookies" to include those technologies where they perform a similar function.

3. Domain and Subdomain Scope

The Platform operates across multiple origins that are all routed through Cloudflare's global network:

  • www.karmapsc.com — the main website, hosted on Vercel.
  • karmapsc.com/learn — the learning portal, hosted on Cloudflare Pages and reverse-proxied to the main domain via a Cloudflare Worker routing rule. This path shares the same domain scope as the main site, so cookies set at the domain level apply to it.
  • qr.karmapsc.com — the QR code and link infrastructure subdomain. Cookies set with a domain attribute of .karmapsc.com also apply here.

Consent preferences stored in a first-party cookie at the .karmapsc.com domain level are therefore recognized across the main site, the learning portal, and qr.karmapsc.com. Infrastructure cookies set by Cloudflare operate across all subdomains as part of the CDN and security layer.

Supabase Auth cookies are scoped by the Supabase client and are the primary session cookies for public accounts and linked student accounts. To prevent session mismatch and protect account privacy, signing out clears Supabase session cookies and auth destination hints together.

If additional subdomains are introduced in the future (such as a user account portal), this Policy will be updated to reflect any changes in cookie scope.

4. How Consent Works

Strictly necessary cookies, including Cloudflare infrastructure cookies and session management cookies, are active by default because they are required for core platform operation, security, login, and mock test and assessment paper functionality.

Non-essential cookies, including analytics cookies, are disabled until the User gives explicit consent through the cookie banner or cookie settings interface.

The User may accept all cookies, reject non-essential cookies, or customize preferences separately for analytics and future marketing cookies. The User can withdraw or modify their consent at any time, with the ease of doing so being comparable to that with which such consent was originally given.

Consent is stored in a first-party consent cookie so the same preference is recognized across the main site and all paths and subdomains that share the .karmapsc.com domain scope.

5. Cookie Categories We Use

5.1 Cloudflare Infrastructure Cookies

These cookies are set automatically by Cloudflare as part of its content delivery network, DDoS protection, and bot-management services. They are strictly necessary and operate at the infrastructure level before any Platform application code runs. They cannot be disabled without disabling access to the Platform entirely.

  • __cf_bm: Used by Cloudflare's bot management system to distinguish legitimate users from automated traffic. Session-scoped; expires within 30 minutes of activity.
  • cf_clearance: Set after a Cloudflare security challenge is successfully passed, allowing continued access. Expires after a defined session period.
  • __cflb: Used by Cloudflare for load balancing to route requests to the same server within a session. Session-scoped.

Cloudflare's own cookie and privacy practices are governed by Cloudflare's privacy policy, available at cloudflare.com/privacypolicy.

5.2 Strictly Necessary Platform Cookies

  • Keep the User signed in where authentication is enabled.
  • Preserve session state and security controls.
  • Store Supabase Auth session cookies for public accounts and linked student accounts using email/password, phone/password, phone-triggered OTP, or Google login. These cookies are strictly necessary for dashboards, onboarding, analytics, rankings, and mock test attempt saving.
  • Store lightweight first-party auth destination hints (karma_auth_hint, karma_dashboard_href, and karma_is_student) so header and learning portal login buttons can instantly show the correct Dashboard link without making extra authentication API calls. These cookies do not grant access and are checked only as interface hints; protected areas still verify sessions server-side.
  • Save active mock test and assessment paper progress and platform state during an ongoing session.
  • Store the cookie consent choice itself so the banner does not reappear on every visit.

5.3 Analytics Cookies

  • Help us understand aggregate usage patterns, page visits, and performance trends across the Platform.
  • Remain disabled unless the User has explicitly opted in through the cookie consent interface.
  • Currently processed through Google Analytics where enabled by consent. Google Analytics is configured with IP anonymization enabled and Google signals / ad personalization signals disabled.

5.4 Preference Cookies

  • Remember interface and consent choices.
  • Improve consistency across sessions and across the main site and learning portal.

5.5 Marketing Cookies

  • Reserved for future promotional, remarketing, or advertising features.
  • Disabled by default and not currently used for browser-based remarketing. Optional public account marketing consent for WhatsApp, phone call, SMS, or email is stored in the public profile database, not as a marketing cookie.

6. Cookies and Their Purpose

  • Consent cookie (karma_consent_state): stores the User's cookie decision, including which categories were accepted or rejected. First-party, path-scoped to the Platform, retained up to one year.
  • Supabase session / authentication cookies: support Supabase Auth login and protected public or linked student areas, including onboarding, dashboards, analytics, rankings, and saved mock test attempts. Cookie names may include Supabase project-specific prefixes such as sb-...-auth-token and related Supabase auth-token chunks used by the Supabase SSR client.
  • Auth destination hint cookies: karma_auth_hint, karma_dashboard_href, and karma_is_student are first-party, path-scoped interface cookies used to route Login/Dashboard buttons across karmapsc.com and karmapsc.com/learn. They may indicate whether the last known dashboard destination is public or student, but they are not authentication credentials and cannot unlock protected pages by themselves.
  • Mock test and assessment paper cookies: keep test state active while the User is taking a timed or multi-question assessment. Session-scoped.
  • Analytics cookies (_ga and _ga_*): collect aggregate usage data through Google Analytics only after explicit consent is granted. The current Google Analytics measurement ID is G-V3BXMJ063K.
  • Cloudflare security cookies (__cf_bm, cf_clearance, __cflb): infrastructure-level security and routing cookies set automatically by Cloudflare. Strictly necessary.

7. Cloudflare Turnstile

The contact form on the Platform uses Cloudflare Turnstile, a privacy-preserving bot detection system. Turnstile processes device signals, browser metadata, and IP-level information to verify that the contact form is being submitted by a human user and not an automated bot.

Turnstile is activated only when the User opens the contact form. It does not run passively on page load or on any other part of the Platform. Turnstile does not set a persistent tracking or advertising cookie. Any transient challenge tokens it uses are session-scoped and are not used for profiling or tracking.

This processing is strictly necessary for the security of the contact form feature and does not require separate cookie consent.

8. Third-Party Cookies

Some cookies are set by third-party services that we use for hosting, security, analytics, or related infrastructure. The key third-party cookie issuers are:

  • Cloudflare: infrastructure and security cookies as described in Section 5.1. Set automatically across all Platform domains.
  • Google Analytics: analytics cookies, loaded and active only after explicit consent is provided.
  • Supabase: authentication cookies and session storage for public accounts and linked student accounts. Google OAuth is used for sign-in and sign-up when selected by the User.
  • Resend SMTP: transactional email delivery for public account confirmation and password reset emails. Resend does not set browser cookies through karmapsc.com for these emails.

If the Platform adds video embedding, advertising pixels, or additional browser-based third-party features in the future, new third-party cookies may be introduced. This Policy will be updated before such cookies are activated, and where applicable, fresh consent will be requested.

Third-party providers are responsible for their own privacy terms. Users are encouraged to review those terms when interacting with their services directly.

9. How the User Can Change Cookie Settings

The User can change cookie preferences or withdraw consent at any time, with the same ease as providing consent, through the Cookie Settings button in the footer, through the cookie banner when it is visible, or by clicking the button below:

The User may also manage cookies from the browser itself, including blocking, deleting, or restricting cookies. Note that blocking Cloudflare infrastructure cookies at the browser level may prevent access to the Platform entirely, as those cookies are part of the delivery infrastructure.

Rejection of non-essential cookies such as analytics does not prevent access to public informational content or enrolled-student features, unless a specific feature requires a strictly necessary cookie to function.

10. What Happens If Cookies Are Disabled

If Cloudflare infrastructure cookies are blocked, the Platform may be inaccessible or degraded because they operate at the network delivery layer.

If strictly necessary Platform cookies (Supabase session authentication and auth destination hint cookies such as karma_auth_hint) are blocked or deleted, certain core features may stop working, including login, session persistence, Dashboard button routing, and active mock test and assessment paper sessions.

If analytics cookies are disabled, the User can still use the Platform fully. Analytics data will simply not be collected for that browser unless consent is later granted.

If preference cookies are disabled, the User may need to reselect options more frequently.

11. Data Retention

The consent cookie is retained for up to one year unless the User clears it, changes preferences, or the policy version changes materially in a way that requires fresh consent.

Cloudflare infrastructure cookies are session-scoped or expire within 30 minutes of inactivity depending on the specific cookie.

Session and security cookies are retained only for the duration necessary for the relevant session or security function. Supabase auth sessions follow Supabase's configured authentication lifetime and refresh-token handling. Auth destination hint cookies are retained only for the active dashboard-routing period and are cleared on sign-out.

Analytics retention depends on the analytics provider's configured retention settings and on the User's consent status.

12. Children and Minors

Where a minor uses the Platform, parental or guardian involvement is required as part of the enrollment process and as described in the Privacy Policy. Cookie preference management is treated as part of the overall platform privacy experience and follows the same consent model described in this Policy.

13. Security

We use reasonable technical and organizational safeguards for cookie-related preferences and session handling, including first-party storage, secure transport (TLS), Cloudflare-level security, and restricted access to administrative systems.

No browser-based storage method can be guaranteed to be completely free from risk.

14. Changes to This Policy

We may update this Cookie Policy from time to time to reflect changes in technology, the Platform, the cookies we use, third-party providers, legal requirements, or operational needs.

Material changes — such as the introduction of new non-essential cookie categories or new third-party issuers — may require the User to see the banner again and provide a fresh consent decision.

The most recent version will always be posted on this page with an updated date and version number.

15. Contact

For questions about this Cookie Policy or your cookie preferences, contact:

KarmaPSC Coaching
Varkala, Thiruvananthapuram, Kerala, India
Email: care@karmapsc.com

You may also review our Privacy Policy and Terms of Service.

Last Updated: 17 June 2026  |  Effective Date: 26 May 2026
Loading...
Sharpening Pencils
Brewing Coffee
Flipping Pages
Connecting Dots
Crunching Numbers
Activating Brain Cells
Igniting Curiosity
Untangling Wires
Herding Cats
Defying Gravity
Synthesizing Data
Consulting Oracles
Gathering Insights
Warming Up Engines
Optimizing Neurons
Loading Brilliance
Dusting Off Books
Aligning Planets
Calculating Odds
Mapping Synapses
Sharpening Pencils