Cookie Policy
Last updated: September 21, 2026
This page lists every cookie and browser storage key WebDecoy uses. It covers two different things, and the difference matters:
- Our own sites, webdecoy.com, docs.webdecoy.com and the dashboard at app.webdecoy.com, where WebDecoy LLC decides what is set.
- Sites that install WebDecoy, where our software runs on someone else's site. There the site owner decides, and this page is what they need in order to describe us accurately in their own policy.
1. Our marketing site (webdecoy.com)
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
_ga, _ga_TE1MYSJJPV | Google Analytics. Counts visits and tells us which pages are read | 2 years | Analytics |
wd_hb | Session storage. Stops our own bot detection script from sending more than one install check per browser tab | Until the tab closes | Necessary |
Our own bot detection script runs on this site, the same script customers install. We use our site as bait for crawlers on purpose.
2. Documentation (docs.webdecoy.com)
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
_ga, _ga_TE1MYSJJPV | Google Analytics, the same measurement as the marketing site | 2 years | Analytics |
starlight-theme | Local storage. Remembers the documentation colour theme | Until you clear it | Functional |
3. The dashboard (app.webdecoy.com)
No analytics or advertising runs in the dashboard. Everything below is first-party browser storage.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
@@auth0spajs@@… | Keeps you signed in across tabs | Until you sign out | Necessary |
webdecoy_post_login_redirect, redirectAfterLogin | Returns you to the page you asked for after signing in | Seconds, during sign-in | Necessary |
wd.vercel.pendingInstall | Holds a Vercel install handoff while you create an account | 25 minutes | Necessary |
webdecoy_selected_property_id | Remembers which site you were looking at | Until you clear it | Functional |
detections_burst_grouping, detections_burst_window | Remembers your detection table preferences | Until you clear it | Functional |
webdecoy.firstRunDismissed, webdecoy.firstRunExampleDecoy | Stops the getting-started banner reappearing | Until you clear it, and tab session | Functional |
webdecoy.updateLanding, webdecoy.reloadedFor… | Handles loading a new version of the app without a reload loop | Tab session | Necessary |
| Offline cache | Stores the app's own files so it loads fast and survives a deploy mid-session | Until replaced | Necessary |
The dashboard also loads a few things from other companies, which see your IP address and browser:
- Auth0 handles sign-in and sets its own cookies on its domain during that redirect.
- Google Fonts serves the typeface and icons.
- jsDelivr serves the map outlines used by the geographic chart.
- HubSpot loads the support form, and only when you open it. It may set its own cookies at that point.
- Stripe handles checkout and billing on its own pages, where Stripe sets its own cookies.
4. What WebDecoy sets on sites that install it
If you are a visitor to a site protected by WebDecoy, this is everything our software puts in your browser. All of it is first-party to the site you are visiting. None of it is used for advertising, and none of it follows you to another site.
| Name | Purpose | Lifetime | Where |
|---|---|---|---|
wd_clearance | Records that this browser already passed a check, so it is not challenged again on every page | 30 minutes | Sites using edge or client-side enforcement |
webdecoy_verified | The same idea on WordPress: marks a visitor who passed the challenge | 15 minutes | WordPress sites |
wd_hb | Session storage. One install check per tab | Tab session | Sites using the browser script |
webdecoy_session | Session storage. A random ID linking a shopping session to a detection, so a fraudulent order can be matched to what caused the alert | Tab session | Shopify stores |
Worth stating plainly: the wd_clearance value is tied to a device signature calculated from your browser's rendering behaviour, screen and timezone. It exists to tell an automated client apart from a person, and it is what a block decision attaches to. We consider it strictly necessary for the security of the site you are visiting, and we would rather describe it than bury it.
Our server software, including the Node and PHP libraries, sets no cookies at all.
5. What we never do
- No advertising or retargeting cookies, anywhere.
- No session recording or replay.
- No selling or sharing of personal information, under any state privacy law.
- No tracking of individual people across unrelated sites. Our identifiers are per site.
6. Controlling cookies
We do not currently show a cookie banner on our own sites, so analytics on webdecoy.com and docs.webdecoy.com runs for everyone. You can stop it:
- Install Google's Analytics opt-out add-on.
- Block third-party or all cookies in your browser settings.
- Use a browser or extension that blocks analytics by default.
Blocking cookies on our marketing site and documentation costs you nothing. Blocking them in the dashboard will prevent sign-in, because the sign-in session is kept in browser storage.
If you run a site with WebDecoy installed and need your visitors to be able to refuse wd_clearance, contact us. Enforcement can be run in a mode that reports without setting anything in the browser.
7. Questions
Email [email protected]. See also our Privacy Policy, our subprocessor list and our Data Processing Agreement.