Skip to main content

Cookie Policy

Last updated: July 2026

HumanKey uses cookies to provide essential functionality and, with your consent, runs first-party analytics to detect AI bots and improve our service. We do not use Google Analytics or any third-party advertising trackers. This policy explains what cookies we use, why, and how you can control them.

What Are Cookies?

Cookies are small text files stored on your device by your web browser. They allow websites to remember your preferences and provide essential functionality like keeping you logged in.

Cookies We Use

Cookie NamePurposeDurationType
accessTokenAuthentication session (short-lived JWT, httpOnly, secure)15 minutesEssential
refreshTokenKeeps you logged in by storing a secure refresh token (httpOnly, secure)7 daysEssential
hk_cookie_consentRemembers your cookie consent choice (localStorage, not a cookie)PermanentEssential
oauth_state, oauth_code_verifierSet only if you sign in with Google: protects the sign-in request against cross-site forgery and completes the secure key exchange (httpOnly, secure)The sign-in redirectEssential
oauth_link_token, oauth_link_payloadSet only when linking a Google account to an existing HumanKey account: carries the pending link across the confirmation step (httpOnly, secure)The linking stepEssential

We do not set any Google Analytics (_ga/_gid) or third-party advertising cookies. Optional analytics are first-party only — see below.

Essential vs Optional Cookies

Essential Cookies (Always Active)

These cookies are strictly necessary for the website to function and cannot be disabled. They include the authentication token that keeps you logged in. Without these cookies, core features like accessing your dashboard would not work.

Optional First-Party Analytics (Require Consent)

When you consent, HumanKey runs its own first-party behavior analysis — the same privacy-first AI-bot-detection technology we provide to customers — to distinguish human visitors from AI bots on this site. It uses an in-session identifier (not a stored advertising cookie) and is processed on our own EU infrastructure. To make that distinction it reads information from your browser and device, including screen and display properties, browser and platform characteristics, your language preferences, a value derived from a canvas drawing that is hashed in your browser, and your interaction patterns on the page. It is never shared with advertisers or other third parties. You can withdraw your consent at any time, as easily as you gave it (Art. 7(3) GDPR), using the tool below — withdrawal does not affect the lawfulness of processing carried out before you withdrew it.

How to Control Cookies

  • Cookie Consent Banner: When you first visit HumanKey, you'll see a banner where you can choose “Essential Only” or “Accept All”. Your choice is saved in localStorage.
  • Change Your Mind: Use the tool below to reset your preference at any time — the consent banner will reappear immediately.
  • Browser Settings: Most browsers allow you to block all cookies via settings. Note that blocking essential cookies will prevent you from logging in.

Your current cookie preference

Not set (banner will show on next visit)

This removes your saved preference. The consent banner will reappear on the next page load.

Third-Party Cookies

HumanKey does not use Google Analytics, advertising networks, or any third-party behavioral-tracking cookies. The optional analytics described above are first-party only. The only third parties that may set cookies are our payment and error-monitoring processors, described below.

Stripe

When you access billing or payment pages, Stripe may set _stripe-sid (session identifier) and _stripe-mid (machine identifier) cookies to prevent payment fraud. These are essential cookies for payment processing security and cannot be disabled without disrupting the checkout process. See Stripe's Cookie Policy.

Error Monitoring

Our error-monitoring provider may set session tracking cookies on pages where JavaScript errors occur. These are functional cookies used exclusively for error diagnosis and performance monitoring. They do not track user behavior for advertising purposes.

AI Assistant (Local Storage)

The HumanKey AI Assistant chatbot stores a conversation identifier (hk_chat_conversation_id) in your browser's localStorage to maintain conversation context within a session. This is not a cookie — it is a locally stored key that is never transmitted to third parties. The conversation ID expires after 30 minutes of inactivity. No personal data is stored. You can clear this at any time by clearing your browser's localStorage.

Other browser storage (functional & preferences)

Beyond the key above, HumanKey stores a small number of first-party values in your browser's localStorage. Like the conversation ID, these are never transmitted to third parties and are never used for advertising or cross-site tracking. They fall into these categories:

  • Preferences — language, theme, selected site, dashboard time range, and demo-data mode, so the app remembers how you left it.
  • Interface state — one-time notices and onboarding steps you have dismissed, so we do not show them again.
  • Consent — your cookie-consent choice (also listed in the table above).
  • Abuse prevention — a short-lived record of your own recent contact/sales form submissions, used only to rate-limit spam from your browser.
  • Transient sign-out signal — a momentary value that signs you out across open tabs; it is not persisted.

All of these are strictly functional or preference storage and hold no advertising or cross-site tracking identifiers. You can clear them at any time by clearing your browser's localStorage.

Contact Us

If you have questions about our use of cookies, contact us via our privacy inquiry form.

For more information about how we process your data, see our Privacy Policy.