> ## Documentation Index
> Fetch the complete documentation index at: https://docs.shieldlabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cookie & Tracking Policy

> The identifiers ShieldLabs uses, why, and how to manage them.

*Last updated: August 3, 2026 | Contact: [contact@shieldlabs.ai](mailto:contact@shieldlabs.ai)*

## 1. Scope

This Policy covers four distinct contexts, which use different technologies and are governed by different sections below:

* **(A) The ShieldLabs snippet/SDK on Customer websites and applications** — see §2.
* **(B) Our marketing website**, [https://shieldlabs.ai](https://shieldlabs.ai) (including our blog) — see §3.1 and §3.2.
* **(C) Our documentation site**, [https://docs.shieldlabs.ai](https://docs.shieldlabs.ai) — see §3.3.
* **(D) The customer portal**, our signed-in product at app.shieldlabs.ai — see §4.

## 2. SDK / Service Identifiers (on Customer properties)

We use strictly necessary and functional identifiers (including cookies and LocalStorage) to assign session or visitor IDs, link events and scoring results, and protect against abuse. We do not use advertising cookies through the Service SDK. Purposes: anti-fraud functionality, security, request attribution, performance, and stability.

This section covers the snippet as deployed by our Customers. Where we run the same snippet on our own websites, we are the controller and §3 applies instead.

Identifier lifetimes are determined by Customer's plan and project settings (typically up to 12 months) and may be shortened by Customer. The moment identifiers are set (on entry, after consent, or after sign-in) is determined by Customer policy and consent management configuration. Customer is responsible for obtaining any required end-user consent and providing proper disclosures.

## 3. Our own websites (shieldlabs.ai and docs.shieldlabs.ai)

### 3.0 What you can choose

Consent is asked for **per purpose**, not as a single switch. The banner's **Cookie settings** opens a panel with three categories, and the tables below say which tool sits in which:

| Category | Can you switch it off? | What it covers |
| - | - | - |
| **Necessary** | No | Delivery and security, staying signed in to the portal, our live chat, and remembering the choice you make here |
| **Analytics** | Yes | Google Analytics and PostHog on the marketing website; the documentation platform's own statistics, Plausible and Google Analytics on the documentation |
| **Advertisement** | Yes | Nothing at present. We set no advertising cookies and run no ad tags. The switch records your preference for the day that changes |

Pressing **Accept** grants both optional categories. Pressing **Decline** grants neither. **Cookie settings** is where you choose between them.

### 3.0.1 One thing sits outside those switches

**We run our own product on our own websites, and it identifies every visit.** The ShieldLabs snippet stores a `cookieID` in a cookie and in local storage for up to 2 years, and derives a device identifier and a risk score from device, browser and network signals. We use it to see how much of our own traffic reaches us through VPNs, proxies and anti-detect browsers.

It is **not** covered by the categories above and **runs for every visitor, including in the EU, the EEA and the United Kingdom, without asking first**. We would rather say that plainly here than imply a choice that does not exist. If you do not want it, block `cdn.shieldlabs.ai` in your browser or clear the `cookieID` cookie and the matching local-storage entry; on our Customers' own websites the snippet is governed by their consent settings, not ours (see §2).

### 3.1 What we use on the marketing website

| Tool | Purpose | Sets cookies / stores identifiers? | What it collects |
| - | - | - | - |
| **Plausible Analytics** | aggregate website statistics | **No** — cookie-free by design | page views, referrer, country, device type (aggregate, no cross-site identifier) |
| **Google Analytics 4** | website analytics | Yes, only once analytics storage is enabled | pages viewed, approximate location, device/browser, interaction events |
| **PostHog** | product and funnel analytics | Yes | pages viewed, interaction events (e.g. clicks on calls-to-action) |
| **The ShieldLabs snippet** | we run our own product on our own site, to measure how much of our own traffic arrives anonymised | Yes — a `cookieID`, stored in a cookie and in local storage for up to 2 years. **Set for every visitor, without prior consent** (see §3.0.1) | device, browser and network signals, used to derive a persistent device identifier and a risk score |
| **Cloudflare** | site delivery and security | **No** for measurement; strictly necessary cookies may be set for security and traffic management | request metadata needed to serve and protect the site |
| **Crisp** | live chat support | Yes — a session identifier, so that a conversation you start continues as you move between pages | the messages you send us and the page you started the chat from |

Strictly necessary cookies are also used for security and to remember your cookie choice. We treat the live chat as strictly necessary: it is how you reach us, it loads for every visitor, and it stores nothing until you use it.

**We do not use session recording.** No tool of ours records your screen, your mouse movements, or the text you type.

We do **not** use advertising cookies, and we do not use this data for cross-context behavioral advertising. Google Signals and Google Ads linking are disabled on our Google Analytics property, and ad personalization signals are switched off on the tag.

### 3.2 When each tool loads

* **Plausible** loads for every visitor. It sets no cookies and stores nothing on your device.
* **Google Analytics 4** loads for every visitor, but with storage denied by default (Google Consent Mode). Cookies are only set once analytics storage is enabled as described below.
* **In the EU, EEA and the United Kingdom**, Google Analytics storage and PostHog are blocked until you accept Analytics. We show a banner asking first.
* **Elsewhere (including the United States)**, they are enabled by default; we give notice through this Policy and our Privacy Policy, and you may opt out at any time (see §5).
* If your browser sends a **Global Privacy Control (GPC)** signal, we treat it as an opt-out: PostHog does not load and Google Analytics storage stays denied — unless you afterwards explicitly accept.
* **Decline** stops both optional categories, in every region.
* **The ShieldLabs snippet is the exception**: it runs regardless of the choice, everywhere, as §3.0.1 explains.

### 3.3 Documentation site (docs.shieldlabs.ai)

Our documentation is served by a third-party documentation platform (Mintlify, which hosts it on Vercel) and delivered through Cloudflare. It uses a different set of tools from the marketing website:

| Tool | Purpose | Sets cookies / stores identifiers? | What it collects |
| - | - | - | - |
| **Plausible Analytics** | aggregate page statistics | **No** — cookie-free by design | page views, referrer, country, device type |
| **Google Analytics 4** | website analytics | Yes, when analytics is permitted | pages viewed, approximate location, device/browser |
| **Cloudflare** | site delivery, security, and page performance measurement | **No** for the measurement beacon; strictly necessary cookies may be set for security and traffic management | page load timings, referrer, approximate location, device/browser |
| **Mintlify** | documentation platform statistics and the "was this page helpful" widget | Yes, when analytics is permitted — an anonymous identifier in local storage | pages viewed, feedback submitted |
| **The ShieldLabs snippet** | we run our own product on our own site | Yes — a `cookieID`, stored in a cookie and in local storage for up to 2 years. **Set for every visitor, without prior consent** (see §3.0.1) | device, browser and network signals, used to derive a persistent device identifier and a risk score |

PostHog, live chat, session recording and advertising cookies are **not** loaded on the documentation site. You may still see cookies from them here: they are set on `shieldlabs.ai` and are therefore readable across its subdomains, but nothing on this site reads or sends them.

**When each tool loads.** The rule is the one in §3.2, and one answer covers all of our sites: the choice is stored on the `shieldlabs.ai` domain, so answering on any one of them answers for the rest.

* **In the EU, EEA and the United Kingdom** nothing in the table above runs until you accept Analytics, **except the ShieldLabs snippet**, which runs regardless (see §3.0.1). We show a banner asking first, on this site as well as on the marketing website.
* **Elsewhere (including the United States)** they are enabled by default; we give notice through this Policy, and you may opt out at any time (see §5).
* A **Global Privacy Control** signal is treated as an opt-out for the categories, and we do not show you the banner — you have already answered.
* **Decline** switches the categories off, in every region.
* If we cannot determine your region, the categories stay off until you answer.

For the platform's own tools we use its documented consent hook: we tell it whether analytics is permitted for you, and it withholds its telemetry — including the "was this page helpful" widget — when it is not.

Two consequences worth stating plainly. That hook is **all-or-nothing** on this site: when analytics is not permitted, the platform also stops loading Plausible here, even though Plausible sets no cookies and needs no consent. So on the documentation site, declining leaves you with **no** measurement at all rather than cookie-free measurement — unlike the marketing website, where Plausible keeps running for everyone. And because these tools read the permission as they start, accepting takes effect for them from your next page view; only our own snippet begins immediately.

## 4. Customer portal (app.shieldlabs.ai)

In the signed-in portal we use: (a) strictly necessary cookies for authentication, security, and session management; (b) product analytics (PostHog, and Google Analytics for aggregate measurement) to understand how the product is used and to improve it; and (c) **Crisp** live chat, so you can reach us from inside the product. Crisp sets a session identifier so a conversation you start continues as you move between pages, and it stores nothing until you open the chat. We treat it as strictly necessary for the same reason as on the marketing website: it is how you contact us.

**We do not pass your account details to the chat.** Your email and name are not sent to Crisp automatically; the support team sees only what you choose to write.

We do not use advertising cookies in the portal, and we do not use session recording there. The ShieldLabs snippet described in §3.0.1 does **not** run in the portal — the portal is where you read your own data, not a site we measure.

## 5. Managing your choices

* **Cookie settings.** The banner's **"Cookie settings"** link, and the same link in the marketing website's footer, open the per-category panel described in §3.0. You can turn any optional category on or off there and press Save, at any time. Withdrawing is as easy as giving consent. **One answer governs all of our sites** — the marketing website, the documentation and the portal — so you only answer once, wherever you first arrive. The documentation site has no footer link of its own yet; change your mind there through the marketing website, or by clearing the cookie in your browser.
* **Global Privacy Control.** We honour the GPC browser signal as an opt-out, as described in §3.2.
* **Browser controls.** You may block or delete cookies through your browser settings. Local storage, including the documentation platform's own identifier, is cleared through the same site-data controls.
* **Vendor opt-outs.** Analytics vendors also provide their own opt-out mechanisms.
* **End-users on Customer properties** manage SDK identifiers through browser or device settings; disabling them may reduce fraud protection accuracy or functionality.

## 6. Who receives this data, and where

* **Plausible Analytics** and **Crisp** (live chat) — processed in the European Union.
* **Google Analytics 4** (Google) and **PostHog** — these providers process data in the United States.
* **Mintlify** (documentation platform, hosted on **Vercel**) and **Cloudflare** (content delivery and performance measurement) — these providers process data in the United States.
* **The ShieldLabs snippet** on our own sites sends data to ShieldLabs itself, processed on our own infrastructure.

Where personal data is transferred outside the EEA or the United Kingdom, we rely on the safeguards described in our [Privacy Policy](/legal/privacy-policy).

## 7. Retention

* **Google Analytics** event data is retained for 14 months.
* **The ShieldLabs snippet's** `cookieID` is stored on your device for up to 2 years, and the identification records it produces are retained for up to 12 months.
* **Mintlify's** anonymous identifier, where analytics is permitted, stays in your browser's local storage until you clear site data.
* **Plausible** stores aggregate statistics only, with no identifier on your device.

Other providers retain data according to their own retention settings; the current subprocessor list and retention details are available on request at [contact@shieldlabs.ai](mailto:contact@shieldlabs.ai).

## 8. Contact

[contact@shieldlabs.ai](mailto:contact@shieldlabs.ai)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.