Cookies and browser storage at www.teachpie.de and app.teachpie.de
As of October 1, 2026
This overview fully describes the information TeachPie currently stores on or reads from devices via cookies, local storage and session storage. The controller is Astep Ahead UG (haftungsbeschränkt). Data protection inquiries can be sent to datenschutz@teachpie.de be directed.
The essentials at a glance
- No analytics or marketing tracking: TeachPie currently does not use web analytics, advertising pixels, retargeting technologies, or embedded social media trackers.
- No selection required in the cookie banner: TeachPie uses only technically necessary storage or storage triggered by a feature you explicitly request. That’s why no consent banner is shown when you visit the site.
- Marketing page: Simply visiting www.teachpie.de currently does not set cookies or create entries in Local Storage or Session Storage.
- Web app: Cookies and browser storage are created on app.teachpie.de depending on the feature used, especially when signing in, during “Learn with class” rounds, security checks and when saving local work or display states.
1. Technically necessary web app cookies
The following cookies are not set automatically when the login page is opened. They are only created when the relevant feature is used. Retention periods are maximum periods; logging out, completing a process or earlier technical deletion may shorten the storage period.
1.1 Sign-in and session
tp_session– signed session metadata for server-side verification of a sign-in. Provider: app.teachpie.de. Protection: HttpOnly, Secure in production, SameSite=Lax. Maximum duration: 90 days.tp_access_token,tp_id_token,tp_refresh_token– Sign-in and renewal tokens for the authenticated session. Provider: app.teachpie.de. Protection: HttpOnly, Secure in production, SameSite=Lax. Maximum duration: 90 days;tp_refresh_tokenis set only if a renewal token is present.TeachPieAuth.<Client-ID>.<Nutzerkennung>.accessToken,.idToken,.refreshTokenandTeachPieAuth.<Client-ID>.LastAuthUser– temporary compatibility storage for the existing client-side sign-in flow. Provider: app.teachpie.de. Secure and SameSite=Lax in production; readable by the web app for technical reasons. Maximum duration: 90 days. This transitional storage is intended to be removed once the auth migration is complete.
1.2 Security and external sign-in
csrf_token– Protection against unwanted cross-session requests. Provider: app.teachpie.de. Protection: HttpOnly, Secure in production, SameSite=Strict. Duration: 5 minutes for session-bound use, otherwise no more than 1 hour.oauth_state,oauth_verifier,oauth_redirect,oauth_origin,oauth_callback,oauth_providerand depending on the processoauth_popup,oauth_account_typeandoauth_nonce– Protection, association and secure return during a login explicitly initiated via Google, Microsoft or Eduplaces. Provider: app.teachpie.de. Protection: HttpOnly, Secure in production, SameSite=Lax. Duration: no more than 10 minutes; normally deleted when the process is completed.tp_email_verification_state– app-signed state, nonce, and PKCE binding for a registration, resend verification email, or email sign-in explicitly initiated by the user; during the subsequent verification process, also bound to the expected Keycloak identity. Provider: app.teachpie.de. Protection: host-only, HttpOnly, Secure in production, SameSite=Lax, Path/api/auth. Duration: no more than 15 minutes per phase; deleted earlier upon successful completion or explicit cleanup.tp_school_first_login_completed– short-term marker so the completion of school-related initial registration can be recognized immediately. Provider: app.teachpie.de. In production: Secure, SameSite=Lax. Duration: 60 seconds.
1.3 Learning with the class
tp_room– A session for a child without an account in a “Learn with your class” round opened by a teacher. Contains only a random identifier; only its hash is stored on the server. Provider: app.teachpie.de. Protection: HttpOnly, Secure in production, SameSite=Lax. Duration: up to twelve hours after the round ends; deleted immediately when leaving the round.
1.4 Language settings
teachpie-locale– records an explicitly selected language for the marketing website and its public tools. Provider: www.teachpie.de. Browser-readable, host-only, HTTPS Secure, SameSite=Lax, path/. Duration: no more than 365 days or until the website data is deleted. The first language is selected from the browser's language settings without storing anything; no IP geolocation takes place.NEXT_LOCALE– remembers a specifically selected interface language. Provider: app.teachpie.de. Browser-readable, host-only, Secure over HTTPS, SameSite=Lax, Path/. Duration: no more than 365 days or until the website data is deleted.
2. Local Storage and Session Storage
§ 25 TDDDG covers more than just cookies. That's why other browser storage is also listed transparently.
2.1 Local storage
Local Storage generally remains until the application removes the entry or the browser storage is cleared. TeachPie uses it for specific functions, including:
- Account limits and local work-in-progress: user-specific keys following the pattern
tp:v1:user:<Nutzer-ID>:…as well astp:v1:auth:lastUserId. They prevent local state from getting mixed up between accounts and, for example, store work, tasks, whiteboard, learning path or lecture states. Account-related entries are removed when switching accounts or during scheduled cleanup. - Display and interaction preferences: for example, the state of the sidebar in the classroom area, recently used learning areas, and dismissed notices, tours, and welcome messages. The sole purpose is to locally remember display or interaction choices made explicitly by the user.
- Microphone and audio choice:
audioConsent_<Nutzer-ID>locally records the consent granted or withdrawn by the user for an audio feature they started, including the time and version. The entry is removed when consent is withdrawn.
2.2 Session Storage
Session storage is limited to the respective browser tab and is usually deleted when the tab is closed. TeachPie uses it for:
- Sign-in security: PKCE and status values such as
auth_pkce_verifier,auth_oauth_state_…andoauth_user_id, which are removed after use. - Temporary workflows: ongoing chat, task, whiteboard, and workspace states, a pending marketplace action, brief usage tips, and controlled retries of failed dynamic loads.
3. External services after a user action
TeachPie does not embed external tracking scripts on the initial website or sign-in page. For the following actions started expressly by the user, the user is redirected to a third-party service:
- Google, Microsoft, or Eduplaces: only after selecting the respective external sign-in option. The provider’s own cookies and storage policies may apply on its pages.
- Stripe: only after starting a checkout or billing portal process. The payment page is hosted by Stripe; Stripe may set necessary security, session, and fraud prevention cookies there. Stripe controls the specific names and durations. TeachPie itself does not store full card or bank account details. More information: Stripe Privacy Policy.
4. Technologies not used
TeachPie currently does not use cookies or similar technologies for Google Analytics, Matomo, Google Ads, Meta/Facebook Pixel, Hotjar, retargeting, personalized advertising or social media plugins. External social media links are regular outbound links, not embedded trackers.
5. Legal basis and consent
Storing information on an end device and accessing it generally require consent under § 25(1) TDDDG. For the storage described above, TeachPie relies on the exemption in § 25(2) no. 2 TDDDG, insofar as the respective storage is strictly necessary to provide a digital service explicitly requested by the user. Where personal data is processed in this context, the supplementary legal bases and purposes are set out in the Privacy policy.
As no optional analytics, marketing or advertising technologies are currently used, consent is not requested and no consent decision is stored. If a technology that is not strictly necessary is introduced in the future, it will be technically blocked until valid consent has been given, and this overview will be updated before rollout.
6. Old consent cookies
Previous versions of the website or web app included the entries cookieConsent, required and lastUpdate saved for a banner. These entries are no longer evaluated and expire no later than 180 days after they were last saved. They do not control analytics or marketing services.
7. Deletion and blocking
Cookies and Local and Session Storage entries can be deleted through the browser’s privacy or website data settings. Deleting necessary login or round session data will log you out or make you leave the round; deleting local work and display states will reset the respective local view or feature. Blocking necessary storage altogether may prevent login, security, participation in a round, or local work features.
8. Changes and contact
This overview is updated whenever there are changes to cookies, browser storage, embedded content, analytics, marketing, sign-in or payment services. Questions can be sent to datenschutz@teachpie.de must be directed. Provider details can be found in the Legal notice.