Cookie Policy
1. What we use cookies for
We use only strictly necessary cookies: the ones required to keep you signed in and to keep the Service secure. We do not use advertising cookies, and our product analytics runs cookieless — it stores nothing on your device (see section 3). This policy is provided in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR.
2. The cookies we set
Strictly necessary cookies are loaded by default because the Service cannot function without them; under regulation 6(4) of PECR they do not require consent, which is why the Service shows no consent banner.
| Name | Category | Purpose | Expiry |
|---|---|---|---|
_threatdetective_session |
Strictly necessary | Maintains your signed-in session and CSRF protection | Session |
remember_user_token |
Strictly necessary | Keeps you signed in between visits when you tick "Remember me" | Up to 2 weeks |
__cf_* / cf_* |
Strictly necessary | Cloudflare bot management and TLS performance (set by our CDN) | Up to 30 days |
3. Analytics without cookies
We use PostHog (EU-hosted) for first-party product analytics with in-memory persistence only: no analytics cookie, no localStorage, nothing stored on your device. There is no element-level autocapture and no session recording. Because no information is stored on or read from your device, PECR's consent requirement for storage access does not apply. Our lawful basis for this processing is set out in the privacy notice.
4. Third parties
The third parties that process data in connection with the Service are listed at /subprocessors.