Skip to content
idleakcheck
LEGAL, COOKIE POLICY

Cookie Policy

LAST UPDATED, 17 / 05 / 2026

This policy explains how IDLeakCheck uses cookies and similar storage technologies on dev.idleakcheck.com and the IDLeakCheck application. It supplements, and is incorporated into, our Privacy Policy.

01

What cookies are

Cookies are small text files that a website asks your browser to store on your device. We also use closely related technologies such as localStorage and sessionStorage, which let our application save small amounts of data locally without sending it back to our servers on every request. Throughout this policy, "cookies" refers to all of these.

02

How we use cookies

We use cookies only for three purposes:

  • Authentication — keeping you signed in across page loads.
  • Security — verifying that requests come from your device, detecting abuse, and supporting two-factor authentication.
  • Service operation — remembering preferences like your light/dark theme so the page doesn't flash on load.

We do not use cookies for advertising, ad personalization, retargeting, or cross-site behavioural tracking. We do not load third-party advertising tags. We do not sell or share cookie-derived data with data brokers.

03

Cookies we set

NAMEPURPOSETYPELIFETIMEFLAGS
idl_sessionYour authenticated session (JWT)Strictly necessarySliding 12 hoursHttpOnly, Secure, SameSite=Lax
idl_csPer-session transport-encryption key handleStrictly necessary1 hourHttpOnly, Secure, SameSite=Lax
idl_2fa_trustRemembers a device that has passed two-factor authentication so you aren't re-promptedStrictly necessary30 daysHttpOnly, Secure, SameSite=Lax
idl_imp_actorUsed internally during administrative impersonation to allow exit back to the admin accountStrictly necessaryUntil impersonation endsHttpOnly, Secure
idl_themeRemembers your light/dark theme so the page doesn't flash on loadPreference1 yearSecure, SameSite=Lax (not HttpOnly — read by client)

The idl_2fa_trust cookie is only set when you opt in during sign-in. You can clear it from your account settings or by signing out of all devices.

04

Cookies set by third parties

SET BYCOOKIESPURPOSEWHEN
Stripe__stripe_mid, __stripe_sidFraud prevention during card paymentsOn pages displaying our payment forms
Cloudflare__cf_bm, cf_clearanceBot management, DDoS protectionAcross the site
Cloudflare Turnstilecf_chl_* (transient)Human-verification challengeOn sign-in, sign-up, search, and unlock pages

We do not load Google Analytics, Facebook Pixel, advertising networks, or any other third-party analytics or marketing tags.

05

Local and session storage

KEYPURPOSESTORAGELIFETIME
idl_cookie_consentRemembers your cookie banner choicelocalStoragePersistent until cleared
idl_fcra_confirmed_v1Suppresses the first-search permissible-use confirmation modal after you've confirmed once in the current browser sessionsessionStorageCleared when the tab closes
06

Your choices

You can change your cookie preferences at any time using the "Manage cookies" link in the site footer. Our cookie banner offers a one-click "Reject all" option for non-strictly-necessary cookies.

You can also clear cookies and storage through your browser's settings. Doing so will sign you out and may require you to re-verify your device on sign-in.

07

Global Privacy Control

We honor the Global Privacy Control (GPC) signal as a valid request to opt out of any sale or sharing of personal information under the California Consumer Privacy Act, Colorado Privacy Act, Connecticut Data Privacy Act, and other comparable state laws. We do not sell or share personal information regardless, but a GPC signal from your browser will be treated as an opt-out for any future processing that could be construed as a sale or share.

08

Do Not Track

We do not respond to legacy "Do Not Track" browser headers, because there is no consistent industry standard for how to interpret them. We do honor GPC (see § 7) and the controls in our cookie banner.

09

Changes to this policy

We may update this policy from time to time. Material changes will be announced at least 30 days in advance via an in-product banner.

10

Contact

privacy@idleakcheck.com

See also our Privacy Policy and Sub-processors page.