This policy explains how IDLeakCheck uses cookies and similar storage technologies on dev.idleakcheck.com and the IDLeakCheck application. It supplements, and is incorporated into, our Privacy Policy.
What cookies are
Cookies are small text files that a website asks your browser to store on your device. We also use closely related technologies such as localStorage and sessionStorage, which let our application save small amounts of data locally without sending it back to our servers on every request. Throughout this policy, "cookies" refers to all of these.
How we use cookies
We use cookies only for three purposes:
- Authentication — keeping you signed in across page loads.
- Security — verifying that requests come from your device, detecting abuse, and supporting two-factor authentication.
- Service operation — remembering preferences like your light/dark theme so the page doesn't flash on load.
We do not use cookies for advertising, ad personalization, retargeting, or cross-site behavioural tracking. We do not load third-party advertising tags. We do not sell or share cookie-derived data with data brokers.
Cookies we set
| NAME | PURPOSE | TYPE | LIFETIME | FLAGS |
|---|---|---|---|---|
idl_session | Your authenticated session (JWT) | Strictly necessary | Sliding 12 hours | HttpOnly, Secure, SameSite=Lax |
idl_cs | Per-session transport-encryption key handle | Strictly necessary | 1 hour | HttpOnly, Secure, SameSite=Lax |
idl_2fa_trust | Remembers a device that has passed two-factor authentication so you aren't re-prompted | Strictly necessary | 30 days | HttpOnly, Secure, SameSite=Lax |
idl_imp_actor | Used internally during administrative impersonation to allow exit back to the admin account | Strictly necessary | Until impersonation ends | HttpOnly, Secure |
idl_theme | Remembers your light/dark theme so the page doesn't flash on load | Preference | 1 year | Secure, SameSite=Lax (not HttpOnly — read by client) |
The idl_2fa_trust cookie is only set when you opt in during sign-in. You can clear it from your account settings or by signing out of all devices.
Cookies set by third parties
| SET BY | COOKIES | PURPOSE | WHEN |
|---|---|---|---|
| Stripe | __stripe_mid, __stripe_sid | Fraud prevention during card payments | On pages displaying our payment forms |
| Cloudflare | __cf_bm, cf_clearance | Bot management, DDoS protection | Across the site |
| Cloudflare Turnstile | cf_chl_* (transient) | Human-verification challenge | On sign-in, sign-up, search, and unlock pages |
We do not load Google Analytics, Facebook Pixel, advertising networks, or any other third-party analytics or marketing tags.
Local and session storage
| KEY | PURPOSE | STORAGE | LIFETIME |
|---|---|---|---|
idl_cookie_consent | Remembers your cookie banner choice | localStorage | Persistent until cleared |
idl_fcra_confirmed_v1 | Suppresses the first-search permissible-use confirmation modal after you've confirmed once in the current browser session | sessionStorage | Cleared when the tab closes |
Your choices
You can change your cookie preferences at any time using the "Manage cookies" link in the site footer. Our cookie banner offers a one-click "Reject all" option for non-strictly-necessary cookies.
You can also clear cookies and storage through your browser's settings. Doing so will sign you out and may require you to re-verify your device on sign-in.
Global Privacy Control
We honor the Global Privacy Control (GPC) signal as a valid request to opt out of any sale or sharing of personal information under the California Consumer Privacy Act, Colorado Privacy Act, Connecticut Data Privacy Act, and other comparable state laws. We do not sell or share personal information regardless, but a GPC signal from your browser will be treated as an opt-out for any future processing that could be construed as a sale or share.
Do Not Track
We do not respond to legacy "Do Not Track" browser headers, because there is no consistent industry standard for how to interpret them. We do honor GPC (see § 7) and the controls in our cookie banner.
Changes to this policy
We may update this policy from time to time. Material changes will be announced at least 30 days in advance via an in-product banner.
Contact
privacy@idleakcheck.com