Last updated: September 13, 2026
Cookie Policy
This page explains which cookies and similar storage technologies Trafikpilot uses, why we use them, and what choices you have. Cookies required to run the service are always on. Analytics cookies — Google Analytics — are only ever set if you accept them, and you can withdraw that consent at any time.
What is a cookie?
A cookie is a small text file the website saves in your browser. Similar technologies such as localStorage and sessionStorage work the same way and are covered by this policy.
Cookies let us, among other things, keep you signed in, remember your preferences, and process payments securely.
Essential cookies we use
Sign-in (Firebase Authentication): we store a short token in your browser so you remain signed in between page views. Without this cookie you cannot log in.
Language preference: your selected locale (Swedish, English, …) is stored so we can show the right language on your next visit.
Theme: your light/dark preference is stored locally so the interface doesn't change appearance between visits.
Security (Firebase App Check): a short reCAPTCHA v3 attestation that helps us prevent automated abuse of our APIs.
Payment cookies (checkout only)
When you go to checkout or manage your subscription you are redirected to Stripe. Stripe sets its own cookies to protect the payment against fraud and to make your session work. We do not have access to the cookies Stripe sets.
More information is available in Stripe's cookie policy at stripe.com/cookie-settings.
Analytics cookies (only with your consent)
If you accept the Analytics category we load Google Analytics 4 through Firebase. It tells us which pages and features get used, how far people get through a mock exam, and where they drop off. We use it to decide what to build next.
It sets a first-party _ga cookie holding a randomly generated ID. That ID is not your name or your email address, and we never upload your account details to Google Analytics.
We run it with Google Consent Mode v2: before you accept, Google's tag is not downloaded at all. After you accept, it runs with ad storage and ad personalisation signalled as denied unless you also accept Marketing.
Google LLC is the processor and data may be processed in the United States under the EU-US Data Privacy Framework. See the Privacy Policy for the transfer safeguards.
You can withdraw at any time via 'Cookie preferences' in the footer. We stop collecting immediately and delete the _ga cookies from your browser.
What we DO NOT use today
We do not use advertising cookies, and we do not track you across other websites.
We never sell your data, and we do not share analytics data with ad networks — Google Signals and ad personalisation are switched off on our Google Analytics property.
Analytics is the only optional category we actually use today. It stays off until you accept it on the banner, and switching it off again under Cookie preferences stops collection and deletes the _ga cookies from your browser.
Detailed cookie + storage inventory
_ga. Google Analytics client ID. Distinguishes one browser from another so a repeat visit isn't counted as a new person. Set on the trafikpilot.se domain only after you accept the Analytics category. Expires after 2 years, or immediately when you withdraw consent.
_ga_<measurement id>. Google Analytics session state. Keeps track of the current session so a visit spanning several pages is counted once. Same consent gate and same deletion as _ga. Expires after 2 years.
iko_sess. Session hint cookie. Tells our pages whether a user is signed in so the first paint shows the right header without an extra round trip. First-party, expires after 1 year.
trafikpilot:lang-prompt-dismissed. LocalStorage. Remembers that you dismissed the suggestion to switch language, so it is not shown again. Holds only a flag, nothing about you. First-party, no expiry.
ikorkort:cookie-consent. LocalStorage. Records which cookie categories you accepted on the banner and when. First-party, no expiry (cleared when you reset browser data or change your preferences).
ikorkort:sessionId. LocalStorage. A random per-device identifier so we can enforce the 2-concurrent-session limit on a Premium account. First-party, no expiry.
firebase:authUser:*. LocalStorage / IndexedDB. Set by the Firebase Web SDK to remember your sign-in. First-party, managed by Firebase.
Stripe checkout cookies. Set by stripe.com only while you're on the hosted checkout or customer-portal page. Required to protect the payment against fraud. We do not have access to them; see stripe.com/cookie-settings for details.
Managing cookies in your browser
You can clear or block cookies at any time via your browser's settings. Note that if you block essential cookies you will no longer be able to sign in or use the core features of the service.
You can also reopen the consent banner via the 'Cookie preferences' link in the site footer to change which optional categories are allowed.
Help for the most common browsers is available at support.google.com/chrome, support.apple.com/safari and support.mozilla.org/firefox.
Contact
Questions about this document? Email support@trafikpilot.se and we'll get back to you in reasonable time.