Data and privacy
Where things are stored and what is never stored.
- Consent records are written to a Cloudflare database restricted to EU jurisdiction.
- We store no IP addresses, not even in hashed form, and no raw browser strings. We use the IP address only to work out the visitor’s country and state, then discard it.
- The banner sets one cookie,
cmp_consent, which holds the visitor’s choice and contains no personal data. - The site check stores a screenshot of your homepage for the preview, and the list of cookies and services it found.
- You sign in with an emailed link or your company’s single sign-on. We keep your email address and your role in each workspace. If you turn on two-factor sign-in, we also keep its secret (encrypted) and your recovery codes (hashed).
- Everyone who processes data for us is on the subprocessor list. The security page explains how we protect it.
- The banner script is served from our edge network. The line from your Install tab is cached for five minutes so fixes reach your site quickly, and pinned versions are cached for a year. The script sends one request for your site’s settings and one when a visitor makes a choice. On about one page view in ten it also sends a short report of the outside services the page contacted and the names of the cookies it can read (never their values, and nothing that identifies the visitor). We count these per day, keep them 30 days, and use them only for the Seen on real visits list.