Cookies explained: the memory notes worth teaching accurately
Every child who browses meets the popup: "We use cookies!" Most adults clicking past it couldn't say what a cookie is — which is precisely why the consent-industrial complex works. The concept is genuinely simple, the crucial distinction takes one minute, and a child who holds both stops being the popup's easiest customer.
What a cookie is
A cookie is a small note a website asks your browser to keep, which the browser then shows back to that site on every future visit. That's the whole mechanism — no program, no camera, no rummaging through your files. The note typically holds an identifier: "visitor #48291." Everything else follows from who reads the note and what they write down next to that number.
The useful kind is everywhere: the note that keeps you signed in (a session often lives in one), remembers your cart, your language, your volume setting. Sites without memory would be unusable — you'd sign in on every click.
The distinction that carries all the weight
- First-party cookies belong to the site you're visiting. Its notes about you concern your dealings with it. Mostly the useful kind.
- Third-party cookies are set by other companies whose invisible content is embedded in the page — advertisers most of all. Here's the trick worth teaching slowly: if the same ad company is embedded in thousands of sites, and your browser shows it its note on every one of them, then that company sees "visitor #48291 read this article, then browsed those shoes, then visited that health page…" — one notebook, filled in across the whole web. That's tracking: not one site knowing its own visitors, but one company following a visitor across everyone's sites. It's why the consent popups legally must ask, and what "Accept all" mostly accepts.
Worth adding for accuracy (and because children will encounter the claims): browsers have been retiring third-party cookies for years — Safari and Firefox block them by default; the industry's responses (fingerprinting, server-side tracking, "hashed email" identity networks — the same trick we document elsewhere) mean the notebook survives the cookie. The durable lesson is the notebook concept, not the cookie technology.
What the evidence doesn't say
- Cookies aren't viruses, don't "slow your computer," and can't read your files — teaching inaccuracies costs credibility exactly when the accurate story is strange enough.
- Deleting cookies isn't a privacy ritual worth teaching children — it signs you out of everything while modern tracking barely notices.
- "Never accept cookies" is wrong twice: the necessary kind makes sites work, and blanket refusal teaches the shrug. The teachable act is the choice — necessary yes, following no (the gates, made playable).
In the classroom
- Teach the note metaphor first, the notebook-across-the-web second — in that order; the second lands only when the first is concrete.
- Open a real cookie list (browser devtools, any big site) on the projector — seeing dozens of entries from companies nobody visited makes third parties real in one glance.
- Reframe the popup as a real question: "who gets to keep a notebook on you?" is answerable by a nine-year-old; "manage your preferences" is not.
- Connect to the ad-funded web honestly — sites are free because the notebook has buyers; children reason well about this trade once it's stated plainly instead of hidden.
How Wiz Kids applies this
Our safety realm teaches the note/notebook distinction, then the browser realm makes it practice: simulated consent gates with the real dark patterns — the glitter button, the settings maze with pre-ticked "share with 214 partners," the beg-again nag — where choosing well is the task and every pattern is safe to fail against. And the product itself is the counterexample children are using while they learn: no cookies, no trackers, no third-party requests at all (the inventory) — which makes a nice classroom question: why doesn't this site have the popup?
References
- The mechanics: HTTP State Management Mechanism (RFC 6265) — the actual specification, for teachers who want ground truth.
- UK ICO — guidance on cookies and the Privacy and Electronic Communications Regulations (the legal reason popups ask).
- Englehardt, S., & Narayanan, A. (2016). Online tracking: A 1-million-site measurement and analysis. ACM CCS — the empirical map of third-party tracking's reach.
- Browser vendors' tracking-prevention documentation (Safari ITP, Firefox ETP) — the retirement of third-party cookies and what replaced the arms race.
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.