:-) I like your writing style.
You appear to use a session identifier as the sole means of authentication. There is little you can do to limit people this way, because they will simply clean their cookies and come back for another go.
Your site will need a signup, login, and logout page where you can turn that session id into something meaningful, and match it against a session identifier in a central location. Once you've got a login system, you will be able to limit daily time.
Here is a simplistic algorithm:
1) User logs in
2) Timer starts
3) User does a bunch of stuff
4) If time is up, redirect to logout
5) User logs out
6) Timer stops
7) user attempts to log in with no time
8) User is told to skidaddle until tomorrow
9) Nightly script runs at midnight to reset the timers
There are better ways, but you'll still have to get your authentication system up and running. There are countless examples on the net for this.
Good luck. --Brian Zab