Cookie Policy
Last updated: August 2026
We set three cookies. All three are strictly necessary or purely functional. There is no analytics, no advertising, no tracking pixel, and no third-party marketing script anywhere on this site — which is why you are not being shown a consent banner.
1. What We Actually Set
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
sessionid |
Keeps you logged in and links your browser to your account session | Strictly necessary | Session / until logout |
csrftoken |
Protects forms against cross-site request forgery. Without it, no form on the site submits. | Strictly necessary | 1 year |
telegram_popup_dismissed |
Remembers that you closed the Telegram chat prompt so it stops reappearing | Functional | 7 days |
Strictly necessary cookies do not require consent under the ePrivacy Directive or the UK PECR. The functional cookie is set only when you actively dismiss the prompt — it stores a single flag, no identifier.
2. What We Do Not Set
- No Google Analytics, Tag Manager, or any analytics platform
- No advertising or retargeting pixels — no Meta pixel, no LinkedIn Insight, no Google Ads tag
- No session recording or heatmap tools
- No cross-site tracking, no data brokers, no fingerprinting
- No social media embeds that phone home on page load
If that changes — if we add analytics later — this page gets updated first and a consent mechanism goes up before the script does.
3. Third Parties That See Your Requests
Cookies are not the only way a third party learns you visited. A few services receive your IP address and browser details because your browser fetches assets or submits data to them:
- Google Fonts and Font Awesome (cdnjs) — serve the Inter typeface and the icon set. They receive your IP and user agent when your browser requests the files. They do not set cookies on our behalf.
- NOWPayments — only when you start a crypto checkout. Their own cookie and privacy terms apply on their pages.
- Telegram — only if you click through to a Telegram link.
- Cloudflare — where a client domain uses Cloudflare DNS or proxying, Cloudflare may set its own cookies on that domain. That is the client's configuration, not ours.
4. Server Logs
Separately from cookies, our web server records requests — IP address, timestamp, requested URL, user agent, response code. This is standard operational logging used for security, abuse investigation, and debugging, not for profiling. Retention and handling are covered in the Privacy Policy.
5. Controlling Cookies
You can block or delete cookies in your browser settings. Blocking sessionid or csrftoken will break login and every form on the site — that is not us being difficult, it is how session authentication works. Blocking telegram_popup_dismissed just means the prompt comes back.
Browser instructions: Chrome, Firefox, Safari, Edge.
6. Changes
If we add a cookie, it appears in the table in Section 1 and the date at the top changes. Anything that is not strictly necessary or functional will ask for your consent before it is set.
7. Contact
Questions about this page: support@lexlabtools.com.