Cookies are files on the users computer. The cookie can expire or be made permanent but the user can delete the cookie. A session holds data with that session. The length of time a session is open can be changed. But after the session is finished the data is destroyed.