Walnut Institute Cookie Policy
Walnut Institute Inc. (“Walnut,” “we,” “us,” or “our”)
Last Updated: September 6, 2026
This policy describes the cookies and similar browser-storage technologies the current Walnut website and learning platform use.
Current position
Walnut currently uses only technologies needed for authentication, security, requested payment services, preferences, cart state, and reliable learning-progress synchronization. Walnut does not currently use third-party analytics, advertising, remarketing, or cross-site behavioural tracking cookies. Because there are no optional analytics or advertising cookies to accept, Walnut does not currently display an optional-cookie consent banner.
1. What These Technologies Are
Cookies are small text files a website stores in your browser. Local storage is browser storage that can keep limited information on a device without sending it automatically with every request. Similar security technologies can use temporary identifiers or browser and device signals.
Some technologies are first-party, meaning Walnut places or reads them on its own domain. Others are provided by Stripe or Cloudflare when you use a payment or security feature.
2. First-Party Cookies
| Cookie | Purpose | Typical duration |
|---|---|---|
| next-auth.session-token or secure-prefixed equivalent | Keeps an authenticated account signed in and protects account access. | Session or a limited persistent sign-in period. |
| next-auth.csrf-token or secure-prefixed equivalent | Protects sign-in and account requests against cross-site request forgery. | Session or short-lived. |
| next-auth.callback-url or secure-prefixed equivalent | Returns a user to the appropriate Walnut page after authentication. | Session or short-lived. |
| sidebar:state | Remembers whether the account sidebar is open or collapsed. | 7 days. |
Cookie names can receive security prefixes or change when authentication libraries are updated, but their purposes remain as described. Blocking authentication or security cookies can prevent sign-in and protected features from working.
3. Local Browser Storage
| Storage item | Purpose | Duration |
|---|---|---|
| walnut_cart | Keeps a guest shopping cart on the device and supports merging it after sign-in. | Until checkout, removal, or browser-data deletion. |
| pendingEnrollCourseId | Remembers a requested enrollment while the user signs in or creates an account. | Until the enrollment flow completes or browser-data deletion. |
| completionQueue | Queues learning-progress updates temporarily when they cannot be sent immediately. | Until synchronization succeeds or browser-data deletion. |
| completedSections / completedLessons | Maintains local completion state for responsive course navigation and recovery. | Until replaced or browser-data deletion. |
| theme | Remembers the selected light, dark, or system appearance. | Until changed or browser-data deletion. |
| Limited administrator display flags | Remember dismissed notices or temporary interface state in administrator tools. | Until replaced or browser-data deletion. |
Walnut may remove legacy quiz-related local-storage entries left by older versions of the platform.
4. Stripe Payment Technologies
When you proceed to Stripe-hosted Checkout or open Stripe's Payment Element to save a card, Stripe may use cookies, local storage, browser signals, and device information needed to operate checkout, authenticate transactions, remember payment-session state, prevent fraud and loss, and provide Stripe's services and analytics.
These technologies are controlled by Stripe and may vary by device, location, payment method, and risk signals. Review Stripe's Cookie Policy and Privacy Policy. Avoiding Stripe's technologies means paid checkout and saved-card features may be unavailable.
5. Cloudflare Turnstile Security
Walnut uses Cloudflare Turnstile on selected forms, including account and inquiry flows, to identify automated abuse. Turnstile evaluates browser and device signals and returns a temporary security token that Walnut verifies with Cloudflare. Cloudflare describes Turnstile's signals as strictly necessary to provide the security service.
Turnstile may use ephemeral identifiers and, if Cloudflare's pre-clearance feature is enabled in the future, a short-lived clearance cookie. Walnut's current integration does not intentionally use Turnstile for advertising or visitor analytics. See Cloudflare's Privacy Policy.
6. Services That Do Not Set Browser Cookies Through Walnut
Walnut's OpenAI API, database, object storage, email-delivery, and background-job requests are ordinarily server-to-server and do not themselves place cookies in your browser through Walnut. Those providers still process information as described in the Privacy Policy.
7. Your Controls
You can delete or block cookies and site storage in your browser settings. You can also use a private-browsing session. Blocking necessary cookies or clearing local storage can sign you out, empty a guest cart, remove preferences, or interrupt progress synchronization and payment or security flows.
Walnut does not currently provide a separate Cookie Settings control because the current platform does not deploy optional analytics or advertising cookies. If Walnut introduces optional tracking, it will update this policy and provide consent or opt-out controls before activation where required by law.
8. Do Not Track and Global Privacy Control
Because Walnut does not currently sell personal information or use cross-site behavioural advertising, there is no advertising sale or sharing to opt out of through browser signals. Browser Do Not Track signals do not have a uniform legal or technical standard. Walnut will assess and honour legally recognized signals if future processing makes them applicable.
9. Changes to This Policy
We may update this policy when technologies, providers, or laws change. The date above shows the latest revision. If Walnut begins using optional analytics, advertising, or materially different tracking, it will update the inventory and provide any required notice and choice.
10. Contact
Questions or privacy requests: privacy@walnutinstitute.com