Legal · Cookie Policy

Cookie Policy

This page explains every cookie and similar storage mechanism AnoLawg uses, what each one does, how long it lasts, and your choices. Last updated 2026-05-10.

A cookie is a small text file a website stores on your browser. Some cookies are essential to operate a site; others remember preferences or help the operator measure usage. AnoLawg uses only cookies that are either strictly necessary or directly useful to the logged-in experience. We do not sell cookie data and we do not run third-party advertising trackers.

Where required by law (GDPR, UK PECR, California CCPA/CPRA), we surface a consent banner for optional functional and analytics categories. Analytics cookies, analytics local storage, Vercel Analytics / Speed Insights, and PostHog browser calls are not intentionally loaded unless analytics consent is present. You can also clear cookies and browser storage at any time from your browser settings.

Strictly necessary

Cannot be disabled without breaking the product.

Required for the site to function: authentication, account security, consent memory, MFA routing, route/access gating, billing/onboarding status routing, and support-session safety. You cannot turn these off without breaking login or core security behavior.

NameTypePurposeExpiresSource
anolawg_sessionCookieAuthenticated session identifier. Without this cookie you cannot log in or use the product.7 days (configurable per firm); cleared on logoutFirst-party
anolawg_cookie_consentCookieStores your consent choices so the site can remember which optional categories you accepted or rejected.365 days or until the consent version changesFirst-party
anolawg:cookie-consentLocal storageLocal browser copy of the same consent choice, used for same-origin JavaScript reads and cross-tab durability.Until browser storage is cleared or the consent version changesFirst-party
anolawg_mfa_pendingCookieMarks a login that must complete MFA before accessing protected app areas.Session or cleared after MFA completesFirst-party
anolawg_mfa_verifiedCookieOptimistic hint that a Webmaster session has passed MFA step-up. Authoritative state is stored server-side; this cookie only avoids a database round-trip for route gating.SessionFirst-party
anolawg_ws_shadowCookieTemporary webmaster impersonation support token used to return the webmaster to the original session and clear impersonation state safely.During an active impersonation session; cleared when impersonation ends or on logoutFirst-party
anolawg_utypeCookieStores the logged-in user type (CRM user, attorney, expert, client, webmaster) so the proxy can route you to the correct section of the app without a database lookup on every request.7 days; cleared on logoutFirst-party
anolawg_aroleCookieStores the authenticated role needed for firm and invite routing, especially immediately after sign-up or invite acceptance.7 days or cleared on logoutFirst-party
anolawg_fstatusCookieStores firm account status so onboarding, billing, and access gates can route users without a database lookup on every request.7 days or cleared when no longer applicableFirst-party
anolawg_trialendCookieStores the firm trial end timestamp for trial banners and access routing during onboarding.7 days or cleared when no longer applicableFirst-party

Functional

Opt-out available — see 'Your choices' below.

Remember preferences, recent work context, calendar selections, and local encrypted-device state that improve the product. Turning these off may degrade usability or require re-enrollment of a local device, but does not let us use third-party advertising trackers.

NameTypePurposeExpiresSource
analawg-theme / analawg-bold-mode / analawg-sidebar-densityLocal storageStores your visual appearance preferences, including theme, bold mode, and sidebar density.Until browser storage is cleared or the preference is changedFirst-party
anolawg-table-*Local storageStores table view preferences such as sorting, filters, visibility, and pagination for repeat workflows.Until browser storage is cleared or the view is resetFirst-party
anolawg_recent_matters_*Local storageStores recently viewed matters for a signed-in user so matter navigation can be faster.Until browser storage is cleared or the list is overwrittenFirst-party
anolawg:calendar:*Local storageStores checked calendar selections for the signed-in user on the calendar page.Until browser storage is cleared or selections are changedFirst-party
anolawg_e2ee / anolawg_e2ee_device_idIndexedDB / local storageStores local end-to-end encryption device state and the local device identifier used by encrypted client-portal messaging.Until browser storage is cleared or the device is resetFirst-party

Analytics

Opt-out available — see 'Your choices' below.

Help us understand product usage, page performance, attribution, and feature-test results so we can improve AnoLawg. We do not use advertising cookies or cross-site ad tracking.

NameTypePurposeExpiresSource
anolawg_utmCookieStores first-party marketing attribution parameters from the URL so we can understand which campaigns led to account creation.30 daysFirst-party
anolawg:ab:distinct_id (localStorage)Local storagePseudonymous browser identifier used to keep feature-test and A/B-test variants stable. PostHog feature-flag calls are gated by analytics consent; local bucketing may use this ID without contacting PostHog.Until browser storage is clearedFirst-party
Vercel Analytics / Speed InsightsProvider scriptMeasures page views and web performance when enabled, so we can identify slow pages and reliability regressions.Provider-controlled event storage; browser identifiers depend on Vercel's current implementationThird-party
PostHogProvider scriptSupports product analytics, feature flags, and experimentation when analytics consent is present and PostHog is configured.Provider-controlled; depends on the configured PostHog host and project settingsThird-party

Your choices

  • Browser controls. Any modern browser lets you view, block, or delete cookies on a per-site basis. Disabling anolawg_session will log you out. Clearing local browser storage may also remove saved preferences, recent matter shortcuts, calendar selections, and local E2EE device state.
  • Consent banner. In jurisdictions that require it, a banner will appear on your first visit so you can accept, reject, or customize non-essential cookies and similar technologies. Rejecting optional categories disables the optional features where the app checks consent.
  • Do Not Track. We honor the Sec-GPC (Global Privacy Control) signal as an opt-out of analytics where applicable.

Questions about cookies or privacy? Email privacy@anolawg.com. For security reports, see our security page.