Hola25
Hola25 Logo
Hola25
Available users

Cookie policy

Last updated: August 4, 2026

This policy explains technologies stored or read on your device when you use the Hola25 website and app: cookies, localStorage, sessionStorage, browser databases, and mobile-app identifiers. We do not describe technologies strictly necessary for a requested service as consent-based; analytics and marketing technologies are disabled by default and activate only after your choice. The strictly necessary category remains active because it supports the requested service and its security.

1. Necessary and functional technologies

These support authentication, security, payments, preferences, and functions you request. Blocking them at browser level may stop authentication or other core functions.

Name or familyTypePurposeDuration
Firebase Auth / Firebase App CheckIndexedDB/browser storage and Firebase Auth-managed mobile AsyncStorageAuthentication, session persistence, security, and abuse preventionSession or until sign-out/expiry; provider-defined storage may use its own duration
hola25-cookie-consentlocalStorageOptional-cookie choices and the policy versionUntil changed, cleared, or replaced by a new version
hola25_language, hola25_currencylocalStorage with TTL (web) / AsyncStorage (mobile app)Selected language and currencyWeb: 1 year; mobile: until the choice changes or app data is cleared
hola25_last_announcement_idlocalStorageThe last announcement read1 year
hola25_teacher_search_recentlocalStorageLocally keeps up to five destination identifiers for recent teacher searches; it does not keep the entered search textUntil browser storage is cleared
hola25_admin_search_recentlocalStorageLocally keeps up to five destination identifiers for recent admin searches; it does not keep the entered search textUntil browser storage is cleared
hola25_onboarding_seen, hola25_last_announcement_id (mobile)Mobile-app AsyncStorageGuide completion and the last announcement read on the deviceUntil overwritten or app data is cleared; the app applies no TTL
hola25_anon_idlocalStorage / mobile-app AsyncStorageSecurity and anti-abuse limits for contact and media access; presence and viewer-cap enforcement for public webinars without an accountUntil browser or app data is cleared
awardNudgeDismissed_*localStorage (web) / AsyncStorage (mobile app)Remembers the dismissed review notice for the exact lessonUntil sign-out, account change/deletion, or browser/app-data clearing
hola25_sf_seen_*localStorageRemembers progress notices already seenUntil sign-out, account change/deletion, or browser-data clearing
hola25_living_hidden_uidsMobile-app AsyncStorageLocally remembers users hidden in the live roomUntil sign-out, account change/deletion, or app-data clearing
persist:root, cachedUserProfile (old web/mobile copies)Web localStorage / mobile AsyncStorage; deletion migration onlyRemoves profile caches created by earlier releases; the current release no longer writes themThe app requests deletion at startup and on every sign-in, sign-out, account change, or account deletion; if storage denies removal, it retries at the next transition
panini_contest_announcement_v1localStorageRemembers banners you chose to dismissUntil browser data is cleared
hola25_session_idsessionStorageCorrelates pseudonymous technical events within one visitBrowser session
hola25_waitlist_popup_variant / dismissed / impressions / attributionsessionStoragePopup consistency, dismissal, and attribution within one visitBrowser session
hola25.lessonRoom.layout.v1localStorageSelected lesson-room layoutUntil browser data is cleared
hola25_trialNudge_*localStorageRemembers trial-lesson notices already dismissed or seenUntil sign-out, account change/deletion, or browser-data clearing

2. Analytics Service — only after opt-in

We use Google Analytics as the "Analytics Service". Its script does not load until you select "Analytics". Google Consent Mode starts with analytics and advertising values set to "denied". After opt-in, the Analytics Service may process pseudonymous identifiers, request metadata including the IP address, and usage reports. We do not describe these data as anonymous.

CookieProviderPurposeDuration
_gaGoogle AnalyticsPseudonymous identifier used to measure usageUp to 2 years
_ga_<ID>Google AnalyticsMaintains session state for the Analytics propertyUp to 2 years

3. Web marketing

The website does not currently load Google AdSense, Facebook Pixel, TikTok Pixel, or a remarketing script. The "Marketing" category is disabled by default, and selecting it does not currently authorise any such technology. If a marketing technology is introduced, it may load only after the affirmative choice applicable at that time.

4. Mobile app

The functional preferences and local identifiers listed above use web localStorage or mobile AsyncStorage, with the durations shown in the table; the mobile app applies no implicit TTL. Hola25 no longer writes public or private profile documents to its own cache. The profile is loaded from Firebase for the signed-in account, and the app requests removal of profile caches left by older releases and account-scoped local identifiers at startup and on authentication transitions. Firebase Auth session persistence remains separately managed by the SDK.

Mobile advertising is disabled in the current release. The iPhone app does not include Google Mobile Ads, UMP, or the ATT permission and does not read the advertising identifier; it therefore makes no ad request through those components.

5. Security providers and external services

  • Firebase/Google Cloud and reCAPTCHA Enterprise: authentication, storage, App Check, and abuse prevention;
  • Google Analytics: web analytics only after opt-in;
  • YouTube/Google: the player API from youtube.com and playback through youtube-nocookie.com when the YouTube video function is activated in the lesson room;

When YouTube playback is activated in the lesson room, Google may receive the IP address, device and browser data, the referring page, and player interactions, and may use cookies or local storage under the service configuration and your choices. The youtube-nocookie.com domain reduces storage before playback but does not mean that the provider receives no data when the function is loaded or used.

If you open a provider's external page, it may use its own technologies under its policy. Hola25 does not inventory here cookies set exclusively on that provider's domain.

6. Give or withdraw your choice

On your first visit, you can accept all optional categories, reject them, or customise them. Afterwards, use the cookie-settings control shown on the website to change your choices at any time. Withdrawal stops future loading and we attempt to remove known Google cookies on our domain; you can also clear storage in browser settings.

Rejecting optional categories does not block your account, listings, lessons, or Premium subscription. Blocking all browser storage may prevent authentication and security features.

7. Updates and contact

For a material change, we increase the policy version and the site asks again for your optional-category choices. For questions, email contact@hola25.com.