R
Research.
Legal

Cookies Policy

Last updated: September 6, 2026

Cookies are small text files placed on your device to make our sites work, remember your preferences, and measure performance. Here is exactly what we use and why.

Cookie Categories

Strictly Necessary

Always on

Essential for the site to function. Cannot be disabled.

  • __rsch_session — user session management (session, HttpOnly, Secure)
  • __rsch_csrf — CSRF protection token (session, HttpOnly)
  • __rsch_consent — stores your cookie preferences (1 year)

Analytics

Requires consent

Helps us understand how visitors use our site anonymously.

  • _ga, _ga_* — Google Analytics, page views & sessions (2 years)
  • ph_* — PostHog product analytics, anonymized (1 year)
  • _rsch_perf — internal performance & error tracking (90 days)

Functional

Requires consent

Remembers your preferences and settings.

  • __rsch_theme — UI theme preference (1 year)
  • __rsch_lang — language / locale setting (1 year)
  • intercom-* — support chat session state (6 months)

Marketing

Requires consent

Tracks conversions for B2B campaigns. Disabled by default.

  • _li_* — LinkedIn Insight Tag, B2B attribution (30 days)
  • _fbp — Facebook Pixel, conversion tracking (3 months)

Third-Party Providers

CloudflareSecurity & CDNcloudflare.com/privacypolicy
Google AnalyticsTraffic analysispolicies.google.com/privacy
PostHogProduct analyticsposthog.com/privacy
IntercomSupport chatintercom.com/legal/privacy
LinkedInB2B ad attributionlinkedin.com/legal/privacy-policy

Managing Your Cookies

  • ▸Use the cookie consent banner on first visit to accept or customize preferences.
  • ▸Update preferences anytime via "Cookie Settings" in the footer.
  • ▸Block cookies in your browser settings — note: blocking necessary cookies may break login.
  • ▸Opt out of Google Analytics via the Google Analytics Opt-out Browser Add-on.
  • ▸We respect Do Not Track signals where technically feasible.

In Our Security Platform

Authenticated areas (dashboard, API console, AI pentest tools) use additional session cookies to maintain state and cache scan results. These are strictly necessary and not used for advertising. API access via API keys does not use browser cookies at all.

Questions?

Email: privacy@rsch.io