Necessary account security
Authenticated service uses server-managed session and CSRF cookies when enabled. Authentication tokens are not stored in browser local storage.
Draft for owner review
The current preview does not include advertising trackers. Future analytics or marketing technology must remain consent-aware and separate from required account security.
Authenticated service uses server-managed session and CSRF cookies when enabled. Authentication tokens are not stored in browser local storage.
Marketing and advertising technology will not be treated as necessary, and behavioral advertising is prohibited in student portals.
A reviewed notice, categories, purposes, retention, providers, withdrawal control, and locale-specific settings must exist before optional tracking is enabled.