The essentials
Almost everything we store in your browser is ours and exists to make the site work. What depends on your permission is reading analytics and — today bundled into the same button — campaign attribution.
There are no ad networks on Pareto Learn, no tracking pixels, and no third-party cookies following you from site to site. Strictly necessary cookies do not require your consent: without them we could not even keep you signed in.
This policy covers cookies and also browser local storage, which is not a cookie but serves a similar function and deserves the same transparency.
Cookies we use
| Name | What it does | Duration | Origin | Consent required? |
|---|---|---|---|---|
pl_reads | It stores the current month and which explanation you unlocked, so the free one-per-month limit can be applied and so that reopening that same explanation doesn't cost you another read. It is signed and not readable by scripts. It carries no name or email, but it does record which explanation you opened in this browser. | 62 days | First party | No — strictly necessary |
sb-…-auth-token | Keeps your session open after you sign in. Without it you would have to retype your password on every page. | 8 hours | First party | No — strictly necessary |
pl_ref | Stores the invitation code you arrived with, so the referral can be attributed if you sign up. It is only created if you arrive through an invitation link. The last column currently treats it as functional, and it should not: attributing a referral is neither a technical purpose nor a service you asked for, so it ought to depend on your permission. It is stored before we ask you, and we are fixing that. | 30 days | First party | No — functional |
i18n_locale | Remembers whether you prefer the site in Spanish or English. | 1 year | First party | No — functional |
Note: The exact name of the session cookie includes an identifier for our Supabase project, in the form sb-…-auth-token, and it may appear split in two if the contents are long.
Browser local storage
These are not cookies: they are not sent to the server with every request. They stay in your browser until you clear them.
| Key | What it does | Consent required? |
|---|---|---|
pl_analytics_consent | Stores your decision about analytics, so we don't ask again on every visit. | No — strictly necessary |
pl_anon_id | A pseudonymous identifier that links your reads from this browser to each other. It is only created if you accept analytics, and it is deleted if you decline. If you read while signed in, those reads are also tied to your account and stop being anonymous. | Yes |
nuxt-color-mode | Remembers whether you prefer light or dark mode. | No — functional |
pl_reading_theme · pl_reading_justify · pl_reading_scale | Remember your reading theme, whether you prefer justified text, and the font size you chose. | No — functional |
pl_free_reads | Intended as a local copy of the monthly read counter, so we could warn you about your limit without asking the server. It is not actually created today: the code that wrote it ended up unused, and the limit is always enforced server-side. We leave it listed while that leftover is still in the product, because we would rather declare one key too many than have you find one we had not declared. | No — functional |
pl_bookmarks_v1 | Stores your reading bookmarks while you don't have an account. If you sign up, they are uploaded to your profile. | No — functional |
Analytics: what we measure and why we ask
We measure how the texts are read so we can decide what to write next. Nothing else.
We use two things, and both wait for your answer to the banner. The first is Plausible, hosted on our own server at a.idonia.tech: it uses no cookies, does not cross-reference data between different sites, and is shared with nobody else. The second is our own reading measurement, which also creates a pseudonymous identifier in your browser. If you choose “Essentials only”, neither of them loads: not a single measurement request leaves your browser.
What we measure with your permission: how long you actually spend reading — the clock stops if you switch tabs or stop interacting — how far down the text you get, which sections you reach, which page you came from, which campaign brought you, what kind of device you use and which country you visit from. Plus product events: views, clicks and searches.
What we never do: targeted advertising, selling data, or cross-site tracking. And two caveats, because an absolute “never” would be inaccurate: Plausible tells visits apart using a value derived from your IP address and your browser that is recalculated and discarded every twenty-four hours — it is not a profile that follows you over time, but it is not nothing either — and if you accept analytics we do build internal activity statistics per registered user.
Legal basis: Art. 5(3) of Directive 2002/58/EC and its national implementing laws; arts. 6(1)(a) and 7 GDPR; art. 14, third paragraph, of Mexico's 2011 LFPDPPP implementing regulation, whose status is uncertain.
Resources the page loads from other domains
Two resources: Google's fonts, which we are removing, and our own analytics script, which only loads if you accept analytics.
The site's fonts are currently served from Google's CDN. It is not a cookie, but the effect is similar and that is why it belongs here: when any page loads, your browser requests those files from Google, and your IP address travels with that request, along with your browser type and the page making it. It happens before you get to decide anything, so we do not rest it on your consent: we rest it on our legitimate interest in delivering the page with the typeface it was designed with (art. 6(1)(f) GDPR). And here is the uncomfortable part: that basis is arguable, because the same typeface can be served from our own domain, and where a less intrusive alternative exists the balancing test tends to fail. This is not fixed by winning the argument; it is fixed by removing the request.
We are migrating the fonts to our own domain. Once we finish, that request will disappear, and with it the only transmission of data to an independent third party that currently happens without you being able to prevent it. The request to our own analytics instance, described just below, will still go out — but only if you accept analytics. Until then, the only way to block the Google one from your side is a browser extension that stops resources loading from fonts.googleapis.com and fonts.gstatic.com.
There is a second resource loaded from another domain, and it is worth saying exactly what it is: the Plausible script served by our own instance at a.idonia.tech. IDONIA hosts it on our behalf and under our instructions — it is a processor, not someone deciding what to do with your data — but the request still leaves your browser, carrying your IP address, your browser type and the page you are looking at. That request is only made if you accept analytics: if you choose to keep only the essentials, the script never loads. Beyond those two — Google's fonts and our own Plausible instance — we load no script, iframe, map or image from any other domain. One more thing belongs here, since this section's title promises the full picture: when you sign in or save your progress, your browser talks directly to Supabase, our database, which is also a processor. It is not a resource the page loads, but it is another request leaving your browser for another domain, so we name it here; the detail is in the privacy notice.
Note: Links to Amazon and other bookstores load nothing until you click. When you do, you leave our site and enter theirs, with their own cookies and their own policy.
Legal basis: Arts. 6(1)(f) and 13(1)(c) GDPR; judgment of the Court of Justice of the European Union in Fashion ID, C-40/17, of 29 July 2019; judgment of the Regional Court of Munich I (Landgericht München I) of 20 January 2022, case 3 O 17493/20, which rejected legitimate interests for embedding Google fonts where self-hosting was available. It is a first-instance ruling in another jurisdiction and does not bind us; we cite it because it points the right way.
How to control all this
Today it's done from your browser or by writing to us. The preferences screen is being built.
To change your decision about analytics right now: clear paretolearn.com's site data from your browser settings. When you come back, the notice reappears and you can choose “Essentials only”. You can also write to contact@paretolearn.com and we'll do it for you.
You can block or delete cookies from your browser settings. If you block the strictly necessary ones, sign-in and the read counter will stop working properly; the rest of the site will still display.
Local storage is cleared through the same “clear site data” option in your browser.
What doesn't exist yet
There is no cookie preferences screen reachable from every page yet. The GDPR requires that withdrawing consent be as easy as giving it, and clearing site data is not that. And if you withdraw it that way, no signal reaches us, so the deletion of the earlier records — the one the privacy notice promises within thirty days — does not start on its own: for that you have to write to us. We are building that screen; until it exists, this section describes what you can genuinely do today.
Legal basis: Art. 7(3) GDPR; art. 7, sixth paragraph, and art. 15 section IV LFPDPPP; art. 21 of the 2011 LFPDPPP implementing regulation, whose status is uncertain and on which we rest no obligation by itself.
Changes to this policy
If we add, remove or change the purpose of any cookie, we update this table and the date above. If the change affects something that requires your consent, we will ask you again.
How to verify what this document says
Every rule we cite was checked against its official text on the date of this version. These are the texts and their dates:
- Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) — a new law published in the Official Gazette on 20 March 2025, in force since 21 March 2025, last amended 14 November 2025. It repealed the 2010 law, and the article numbering changed.
- Mexico's Federal Consumer Protection Law (LFPC) — last amended in the Official Gazette on 12 December 2025, adding sections VIII and IX to art. 76 BIS on subscriptions with recurring charges.
- Mexico's Federal Copyright Law (LFDA) — published in the Official Gazette on 24 December 1996, last amended in the Official Gazette on 14 May 2026.
- Regulation (EU) 2016/679 (GDPR) — consolidated text, including the corrigendum published in OJ L 127 of 23 May 2018.
- Directive 2002/58/EC on privacy and electronic communications, as amended by Directive 2009/136/EC, and its national implementing laws.
- Directive 2011/83/EU on consumer rights, as amended by Directive (EU) 2019/2161.
- California Civil Code § 1798.82 — as amended by Senate Bill 446, approved by the Governor on 3 October 2025 and in force since 1 January 2026, which replaced the “without unreasonable delay” standard with a thirty-calendar-day deadline from discovery for notifying consumers and added a fifteen-calendar-day deadline for the sample copy to the Attorney General.
- California Online Privacy Protection Act — Cal. Bus. & Prof. Code §§ 22575–22579, with no applicability threshold.
- California Consumer Privacy Act — Cal. Civ. Code § 1798.140(d), text in force. The revenue threshold in the definition of “business” is adjusted by the California Privacy Protection Agency every odd-numbered year under § 1798.199.95(d): 26,625,000 dollars from 1 January 2025, against the 25,000,000 the text of the section still states.
- Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries — published in OJ L 199 of 7 June 2021.
Two points we do not treat as settled
- Mexico's 2011 implementing regulation was never expressly repealed, but it develops a law that was, and the new regulation has not been published. We use it as an interpretive guide where it does not contradict the law in force, and we do not rest any obligation on it alone.
- The 2021 EU Standard Contractual Clauses do cover an exporter that, like us, is not established in the Union but falls within the GDPR through its article 3(2): Clause 13(a) says so expressly. What is still open is something else: that clause makes the competent supervisory authority the one of the Member State where our representative in the Union is established, and we have not designated one yet, so Annex I.C is not settled. The additional set of clauses the Commission announced in 2022 addresses a different situation — an importer whose processing is already directly subject to the GDPR — we have no record that it was adopted, and we understand it does not concern us. We say it this way rather than claim the chain is seamlessly covered.