Cookie policy
Cookies are small files a website saves in your browser. Local storage is similar, but stays on your device and isn't sent to us automatically. We use as few as we can.
Our default is essential only. Nothing optional is switched on until you choose "Analytics" or "Analytics + ads". Turning it off again is as easy as turning it on. Turning ads off deletes the ad cookies we can reach straight away; reload any open BudgetUp tab to stop the tags completely.
Strictly necessary
These make BudgetUp work: signing in, keeping your account secure and saving your progress. The law (the Privacy and Electronic Communications Regulations, PECR) lets us use them without asking, because the service can't work without them. You can block them in your browser settings, but parts of the site will stop working.
| Name | Provider | Type | Purpose | Duration | Category |
|---|---|---|---|---|---|
better-auth.session_token (__Secure- prefix on our live site) | BudgetUp (first party) | Cookie | Keeps you signed in and protects your account | 30 days, refreshed when you use the site | Essential |
Sign-in state cookies set by our authentication library | BudgetUp (first party) | Cookie | Security checks during sign-in (for example with a magic link or Google) | Session, or up to 15 minutes | Essential |
ll_gid | BudgetUp (first party) | Cookie (httpOnly) | Guests only: a random ID the server can use to apply free-play rules fairly. It isn't linked to your name, email or any other site, and it's not used for analytics or advertising | Up to 13 months. Not used once you sign in | Essential |
ledgerline:cookie-consent | BudgetUp (first party) | Local storage | Remembers your cookie choice (essential, analytics, marketing) and which version of this policy you agreed to | Until you change it or clear your browser storage | Essential |
ledgerline:progress, ledgerline:economy, ledgerline:onboarding, ledgerline:account, ledgerline:avatar | BudgetUp (first party) | Local storage | Saves your game progress, coins, onboarding answers and avatar on your device, so guest play works without an account | Until you clear your browser storage. Copied to your account when you sign up | Essential |
ledgerline:arcade:<game> | BudgetUp (first party) | Local storage | Saves each game's best score, unlocks and any run in progress so you can carry on where you left off | Until you clear your browser storage. Synced to your account when signed in | Essential |
ledgerline:srs, ledgerline:badges, ledgerline:run:<level>, ledgerline:lesson-game:<id>, ledgerline:map-seen, ledgerline:map-chests, ledgerline:arcade-paid, ledgerline:mpr-last | BudgetUp (first party) | Local storage | Your review cards, badges you've seen, a lesson in progress, saga-map state and which arcade rewards have been paid, so nothing is lost or paid twice | Until you clear your browser storage. Synced to your account when signed in | Essential |
ledgerline:play-prefs, ledgerline:audio-volumes, ledgerline:caption, ledgerline:arcade-a11y, ledgerline:*-intro, ledgerline:map-intro, ledgerline:coach:<game> | BudgetUp (first party) | Local storage | Your settings (sound, captions, no time limit, accessibility options) and which intros and tips you've already seen | Until you change them or clear your browser storage | Essential |
ledgerline:checkup-snooze, ledgerline:email-nudge-dismissed, ledgerline:add-email, ledgerline:interop-dispatch, ledgerline:brand | BudgetUp (first party) | Local storage | Remembers that you dismissed a prompt, and your institution's colours and logo, so they aren't fetched or shown again | Until you clear your browser storage | Essential |
ledgerline:sync-meta, ledgerline:merged:<account> | BudgetUp (first party) | Local storage | Device-only bookkeeping for automatic saving: when each item last changed and whether this device's guest progress has already been added to your account | Until you clear your browser storage | Essential |
ll_nation | BudgetUp (first party) | Cookie | Remembers which UK nation you live or study in (England, Scotland, Wales or Northern Ireland) so lessons open with the right rules for you | Up to 13 months, or until you change it in Settings | Essential |
ledgerline:nation, ledgerline:nation-server, ledgerline:nation-checked | BudgetUp (first party) | Local storage | The nation you chose (and, when signed in, the one on your account or set by your university or college), so lessons and games show your nation's rules | Until you change it, sign out or clear your browser storage | Essential |
ledgerline:age-band, ledgerline:age-server, ledgerline:age-checked | BudgetUp (first party) | Local storage | Remembers the age range you chose (never your date of birth) so under-18 protections apply straight away, including before you sign in | Until you change it, sign out or clear your browser storage | Essential |
ledgerline:pwa-install | BudgetUp (first party) | Local storage | Remembers if you said "Not now" to adding BudgetUp to your home screen, so we don't keep asking | Until you clear your browser storage | Essential |
Service worker caches (ll-pages-*, static-art, serwist-precache-*) | BudgetUp (first party) | Cache storage | Keeps the app's code, artwork and the lessons you've opened on your device so they load fast and work offline. Never contains your account details or answers | Replaced with each new version of the app; art kept up to 30 days | Essential |
Analytics (optional, off by default)
If you say yes, we use product analytics to understand which games and lessons work and where people get stuck, and we send error reports when something breaks. Analytics is PostHog's EU Cloud (Frankfurt, Germany), reached through our own web address so it is only ever loaded after you agree; error reports go to Sentry's EU region (Germany). Every word on screen and everything you type is masked in session recordings, and recordings never cover Settings, admin pages, the AI coach or parent links. Neither tool is used for advertising or shared with anyone. We don't use analytics or browser error reports for anyone in under-18 mode, and we respect your browser's Global Privacy Control and Do Not Track signals.
| Name | Provider | Type | Purpose | Duration | Category |
|---|---|---|---|---|---|
ph_<project>_posthog | PostHog Inc (EU Cloud, Frankfurt), via our own address /ingest | Local storage | A random ID that lets product analytics count visits, which lessons and games people finish or abandon, button taps (text hidden), page speed and, for about 1 in 4 visits, a masked session recording. No cookie, no IP address stored, never shared with advertisers | Until you withdraw consent (we delete it straight away) or clear your browser storage | Analytics (consent) |
__ph_opt_in_out_<project>, ph_<project>_window_id, ph_<project>_primary_window_exists | PostHog Inc (EU Cloud) | Local / session storage | Remembers that you opted in, and which tab a recording belongs to | Until you withdraw consent, or the tab closes | Analytics (consent) |
ledgerline:analytics-first-seen, ledgerline:analytics-opened-day, ledgerline:analytics-signup:<account> | BudgetUp (first party) | Local storage | Lets analytics count whether people come back after a day, a week and a month, and count a new sign-up once, without tracking what they do in between | Until you withdraw consent or clear your browser storage | Analytics (consent) |
ll-sub-started | BudgetUp (first party) | Session storage | Counts a new Plus subscription once even if you refresh the welcome page | Until the tab closes | Analytics (consent) |
Error reports (Sentry, EU region) | Functional Software Inc (Sentry, de.sentry.io) | No storage | If something crashes, we send a technical error report (page address without any codes or links, browser, error message) so we can fix it. No name, email, IP address or answers | Reports deleted after 90 days | Analytics (consent) |
Marketing (optional, off by default)
Only if you choose "Analytics + ads": Google Analytics 4, Google Ads (with Google Consent Mode, everything denied until you agree) and the LinkedIn Insight Tag help us see which of our adverts bring people to BudgetUp. They load only on our public pages (home, pricing, games overview, library, help, trust and the pages for organisations) and never inside lessons, games, onboarding, your account, settings, admin pages or the AI coach, so nothing about your learning reaches an advertising platform. They never run in under-18 mode or when your browser sends Global Privacy Control or Do Not Track. For this ad measurement Google and LinkedIn are independent controllers and their own privacy policies apply.
| Name | Provider | Type | Purpose | Duration | Category |
|---|---|---|---|---|---|
_ga, _ga_<id> | Google LLC (Google Analytics 4) | Cookie (first party) | Distinguishes visitors to our public pages so we can see which ads and campaigns bring people to us. Google signals are off | 2 years | Marketing (consent) |
_gcl_au, _gcl_aw, _gcl_dc | Google LLC (Google Ads) | Cookie (first party) | Links a click on one of our Google ads to a sign-up or enquiry (conversion measurement). No enhanced conversions: we never send your email or name | 90 days | Marketing (consent) |
IDE, test_cookie, ar_debug (doubleclick.net); NID (google.com) | Google LLC | Cookie (third party, set by Google's own domains) | Google's advertising cookies, used to measure and personalise Google ads. We can't read or delete these: use the cookie settings to stop new ones, and Google's ad settings (adssettings.google.com) | Up to 13 months | Marketing (consent) |
li_fat_id, li_sugr, _li_ss | LinkedIn Ireland (Insight Tag) | Cookie (first party) | Links a visit from a LinkedIn ad to a sign-up or enquiry, and gives us grouped statistics about the kinds of organisations that visit (never who you are) | 30 to 90 days | Marketing (consent) |
bcookie, lidc, UserMatchHistory, AnalyticsSyncHistory, li_gc | LinkedIn Ireland | Cookie (third party, set by linkedin.com) | LinkedIn's own cookies for ad measurement and its consent record. We can't read or delete these: use the cookie settings to stop new ones, and your LinkedIn ad settings | 1 day to 1 year | Marketing (consent) |
ledgerline:ads-pending | BudgetUp (first party) | Local storage | If you've chosen "Analytics + ads" and sign up inside the app, where ad tags never run, this remembers the word "signup_completed" so it can be counted the next time you're on one of our public pages. No ID, no details | Until it's sent, you withdraw consent, or you clear your browser storage | Marketing (consent) |
We'll update these tables before we switch on any new tool, and ask you again if the purposes change. We last asked again in October 2026, when the optional marketing category was added.
What we don't use
- No ads inside BudgetUp, and no advertising tags anywhere in the learning app
- No Meta (Facebook, Instagram) or TikTok pixels
- No enhanced conversions or uploads of your email or name to Google or LinkedIn
- No selling of cookie data
Links to other sites
We link to help services such as MoneyHelper, StepChange and Citizens Advice. When you visit them, their own cookie policies apply.
Changing your mind
Use the "Cookie settings" link at the bottom of every page, or the button above. You can also clear cookies and local storage in your browser settings. That will also remove any guest progress you haven't saved to an account.
Questions? Email [email protected] or read our privacy notice.