Skip to main content
Last updated: August 3, 2026 | Contact: contact@shieldlabs.ai

1. Scope

This Policy covers four distinct contexts, which use different technologies and are governed by different sections below:
  • (A) The ShieldLabs snippet/SDK on Customer websites and applications — see §2.
  • (B) Our marketing website, https://shieldlabs.ai (including our blog) — see §3.1 and §3.2.
  • (C) Our documentation site, https://docs.shieldlabs.ai — see §3.3.
  • (D) The customer portal, our signed-in product at app.shieldlabs.ai — see §4.

2. SDK / Service Identifiers (on Customer properties)

We use strictly necessary and functional identifiers (including cookies and LocalStorage) to assign session or visitor IDs, link events and scoring results, and protect against abuse. We do not use advertising cookies through the Service SDK. Purposes: anti-fraud functionality, security, request attribution, performance, and stability. This section covers the snippet as deployed by our Customers. Where we run the same snippet on our own websites, we are the controller and §3 applies instead. Identifier lifetimes are determined by Customer’s plan and project settings (typically up to 12 months) and may be shortened by Customer. The moment identifiers are set (on entry, after consent, or after sign-in) is determined by Customer policy and consent management configuration. Customer is responsible for obtaining any required end-user consent and providing proper disclosures.

3. Our own websites (shieldlabs.ai and docs.shieldlabs.ai)

3.0 What you can choose

Consent is asked for per purpose, not as a single switch. The banner’s Cookie settings opens a panel with three categories, and the tables below say which tool sits in which: Pressing Accept grants both optional categories. Pressing Decline grants neither. Cookie settings is where you choose between them.

3.0.1 One thing sits outside those switches

We run our own product on our own websites, and it identifies every visit. The ShieldLabs snippet stores a cookieID in a cookie and in local storage for up to 2 years, and derives a device identifier and a risk score from device, browser and network signals. We use it to see how much of our own traffic reaches us through VPNs, proxies and anti-detect browsers. It is not covered by the categories above and runs for every visitor, including in the EU, the EEA and the United Kingdom, without asking first. We would rather say that plainly here than imply a choice that does not exist. If you do not want it, block cdn.shieldlabs.ai in your browser or clear the cookieID cookie and the matching local-storage entry; on our Customers’ own websites the snippet is governed by their consent settings, not ours (see §2).

3.1 What we use on the marketing website

Strictly necessary cookies are also used for security and to remember your cookie choice. We treat the live chat as strictly necessary: it is how you reach us, it loads for every visitor, and it stores nothing until you use it. We do not use session recording. No tool of ours records your screen, your mouse movements, or the text you type. We do not use advertising cookies, and we do not use this data for cross-context behavioral advertising. Google Signals and Google Ads linking are disabled on our Google Analytics property, and ad personalization signals are switched off on the tag.

3.2 When each tool loads

  • Plausible loads for every visitor. It sets no cookies and stores nothing on your device.
  • Google Analytics 4 loads for every visitor, but with storage denied by default (Google Consent Mode). Cookies are only set once analytics storage is enabled as described below.
  • In the EU, EEA and the United Kingdom, Google Analytics storage and PostHog are blocked until you accept Analytics. We show a banner asking first.
  • Elsewhere (including the United States), they are enabled by default; we give notice through this Policy and our Privacy Policy, and you may opt out at any time (see §5).
  • If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out: PostHog does not load and Google Analytics storage stays denied — unless you afterwards explicitly accept.
  • Decline stops both optional categories, in every region.
  • The ShieldLabs snippet is the exception: it runs regardless of the choice, everywhere, as §3.0.1 explains.

3.3 Documentation site (docs.shieldlabs.ai)

Our documentation is served by a third-party documentation platform (Mintlify, which hosts it on Vercel) and delivered through Cloudflare. It uses a different set of tools from the marketing website: PostHog, live chat, session recording and advertising cookies are not loaded on the documentation site. You may still see cookies from them here: they are set on shieldlabs.ai and are therefore readable across its subdomains, but nothing on this site reads or sends them. When each tool loads. The rule is the one in §3.2, and one answer covers all of our sites: the choice is stored on the shieldlabs.ai domain, so answering on any one of them answers for the rest.
  • In the EU, EEA and the United Kingdom nothing in the table above runs until you accept Analytics, except the ShieldLabs snippet, which runs regardless (see §3.0.1). We show a banner asking first, on this site as well as on the marketing website.
  • Elsewhere (including the United States) they are enabled by default; we give notice through this Policy, and you may opt out at any time (see §5).
  • A Global Privacy Control signal is treated as an opt-out for the categories, and we do not show you the banner — you have already answered.
  • Decline switches the categories off, in every region.
  • If we cannot determine your region, the categories stay off until you answer.
For the platform’s own tools we use its documented consent hook: we tell it whether analytics is permitted for you, and it withholds its telemetry — including the “was this page helpful” widget — when it is not. Two consequences worth stating plainly. That hook is all-or-nothing on this site: when analytics is not permitted, the platform also stops loading Plausible here, even though Plausible sets no cookies and needs no consent. So on the documentation site, declining leaves you with no measurement at all rather than cookie-free measurement — unlike the marketing website, where Plausible keeps running for everyone. And because these tools read the permission as they start, accepting takes effect for them from your next page view; only our own snippet begins immediately.

4. Customer portal (app.shieldlabs.ai)

In the signed-in portal we use: (a) strictly necessary cookies for authentication, security, and session management; (b) product analytics (PostHog, and Google Analytics for aggregate measurement) to understand how the product is used and to improve it; and (c) Crisp live chat, so you can reach us from inside the product. Crisp sets a session identifier so a conversation you start continues as you move between pages, and it stores nothing until you open the chat. We treat it as strictly necessary for the same reason as on the marketing website: it is how you contact us. We do not pass your account details to the chat. Your email and name are not sent to Crisp automatically; the support team sees only what you choose to write. We do not use advertising cookies in the portal, and we do not use session recording there. The ShieldLabs snippet described in §3.0.1 does not run in the portal — the portal is where you read your own data, not a site we measure.

5. Managing your choices

  • Cookie settings. The banner’s “Cookie settings” link, and the same link in the marketing website’s footer, open the per-category panel described in §3.0. You can turn any optional category on or off there and press Save, at any time. Withdrawing is as easy as giving consent. One answer governs all of our sites — the marketing website, the documentation and the portal — so you only answer once, wherever you first arrive. The documentation site has no footer link of its own yet; change your mind there through the marketing website, or by clearing the cookie in your browser.
  • Global Privacy Control. We honour the GPC browser signal as an opt-out, as described in §3.2.
  • Browser controls. You may block or delete cookies through your browser settings. Local storage, including the documentation platform’s own identifier, is cleared through the same site-data controls.
  • Vendor opt-outs. Analytics vendors also provide their own opt-out mechanisms.
  • End-users on Customer properties manage SDK identifiers through browser or device settings; disabling them may reduce fraud protection accuracy or functionality.

6. Who receives this data, and where

  • Plausible Analytics and Crisp (live chat) — processed in the European Union.
  • Google Analytics 4 (Google) and PostHog — these providers process data in the United States.
  • Mintlify (documentation platform, hosted on Vercel) and Cloudflare (content delivery and performance measurement) — these providers process data in the United States.
  • The ShieldLabs snippet on our own sites sends data to ShieldLabs itself, processed on our own infrastructure.
Where personal data is transferred outside the EEA or the United Kingdom, we rely on the safeguards described in our Privacy Policy.

7. Retention

  • Google Analytics event data is retained for 14 months.
  • The ShieldLabs snippet’s cookieID is stored on your device for up to 2 years, and the identification records it produces are retained for up to 12 months.
  • Mintlify’s anonymous identifier, where analytics is permitted, stays in your browser’s local storage until you clear site data.
  • Plausible stores aggregate statistics only, with no identifier on your device.
Other providers retain data according to their own retention settings; the current subprocessor list and retention details are available on request at contact@shieldlabs.ai.

8. Contact

contact@shieldlabs.ai