Legal information
Cookies and Trackers Policy
Last updated: 29 August 2026
1. Scope and Principles
This policy covers tralo.fr and help.tralo.fr. The term “tracker” covers HTTP cookies but also local storage (localStorage), session storage (sessionStorage) and any technique making it possible to read or write information on your device.
Tralo does not use advertising cookies, advertising networks or advertising profiling tools.
2. Strictly necessary cookies on tralo.fr
• Tralo session cookies: names of the form __Secure-tralo.session_token and __Secure-tralo.session_data, httpOnly cookies set on the .tralo.fr domain: keeping you signed in, renewing the session and securing access to the account. They cannot be read by page scripts. Duration: rolling session of no more than 7 days, closed on sign-out; the second is an encrypted session cache with a short expiry. A temporary verification cookie may be added for the duration of a two-step sign-in.
• Guided tour state: name of the form tralo:onboarding:[user], local storage: avoiding restarting a tour already completed and ensuring continuity if the profile is temporarily unavailable. Duration: until local data is cleared or the account is deleted.
• Interface transaction markers: local storage used to avoid repeating certain idempotent operations, for example sending the welcome email. Duration: for as long as the account concerned is used on the device.
• Loading safeguards: session storage used to prevent a reload loop when an older application resource is out of date. Duration: the tab session, then automatic deletion.
• Access to a protected story: short-lived technical storage where applicable: avoiding asking again immediately for a code already validated. Duration: limited to the session or to the planned access period.
• Language choice: TRALO_LOCALE cookie: serve every page in the language chosen or detected, including on return from the payment page. Duration: one year.
• Reading preferences: name tralo:reader-prefs:v1, local storage: remember the theme, higher contrast, text size, dyslexia-friendly font and simplified display chosen on this device. Duration: until cleared by the browser.
3. Payment-related storage
• Stripe elements: cookies or storage set by Stripe only when you open payment for a subscription: displaying the secure form, preventing fraud, remembering the payment step and offering the methods compatible with your device. Their duration is set by Stripe according to their function. Tralo cannot process the payment without these elements.
4. Help centre storage
• Article vote: name of the form tralo_help_vote_[article], local storage: remembering the “helpful” or “not helpful” choice after your click and avoiding a further vote on the same device. Duration: until cleared by the browser.
These markers are not used to track your browsing across sites. The vote or the search may however be sent to support together with technical information, as explained in the privacy policy.
5. Convyra chat widget
The Convyra widget uses a random technical token stored under a convyra_widget_[project] key. It contains no direct personal data and maintains conversation continuity and visitor presence. Depending on the project setting, it is created when the widget loads or on the first interaction and remains until browsing data is cleared. Tralo also stores convyra_first_open_[project] so that first-open context is sent only once.
Convyra tracks the current URL and referrer, including navigation without a page reload. Depending on the enabled context mode, the first opening may also send the page title, dimensions, scroll position, language, time zone, browser and device. The widget never reads form fields. A capture is sent only after an explicit choice in the browser sharing dialog. The widget is not loaded on Reader links.
6. Audience measurement
Umami measures traffic across the site and the application: which pages are viewed, which page the visit came from, and what screen size is used. This measurement is used to improve the service, never for advertising, profiling or tracking a person from one site to another.
The tool sets no cookies and writes nothing to your browser storage. It only reads the umami.disabled key, which switches it off. The following is sent to its server: the address and title of the page, the page the visit came from, the screen resolution, the browser language, together with the IP address and browser that any request reveals.
Usage events. While an account is being set up, the application also sends Umami events describing the step reached and the profile declared by the Author: profile type, teaching level, target audience, objective, chosen creation path, language, device type, account type and role within the organisation. The list of properties that may be sent is closed in the code: nothing else leaves. These events concern the Author, never a Reader.
Never on Reader links. No audience measurement is loaded on the reading pages intended for pupils (/story, /cards, /play and the /s and /c shortcuts). A second safeguard cancels any send relating to one of those addresses.
If your browser sends the Do Not Track signal, no measurement is sent. The provider, Umami Software, Inc., is established in the United States, so this measurement involves processing outside the European Economic Area.
7. Changes to this list
The list is updated whenever a tracker, its purpose or its duration changes. A new non-essential tracker is not activated on the basis of an earlier consent that did not cover it. For any question, or to report a discrepancy between this list and your browser: contact@tralo.fr.