Cookie Policy
The cookies and browser storage Guard.ch uses, the EU-hosted product analytics we run, and how to refuse or clear them.
1. Introduction
This Cookie Policy explains how Zesiger.net ("we", "us"), the operator of Guard.ch, uses cookies and equivalent browser storage technologies (localStorage and sessionStorage) on the guard.ch website, the dashboard, the live analysis view, and the snapshot viewer. Most of this storage is strictly necessary to run the service; in addition we set security cookies through Cloudflare, payment cookies through Stripe on checkout, and first-party cookies through our EU-hosted product analytics (PostHog). All of them are documented below.
It complements our Privacy Policy, which describes the broader processing of personal data. Where this policy and the Privacy Policy overlap, the Privacy Policy governs the processing of personal data and this policy governs what is stored in your browser and why.
2. Scope: your browser, not investigation captures
This policy covers only the items Guard.ch stores in the browser you use to visit guard.ch.
It does not cover cookies and storage that an investigation records. When you run an investigation, an isolated cloud browser visits the target website on your instruction and captures, among other things, the cookies and localStorage or sessionStorage writes that the target site and its third parties set inside that isolated browser. Those items are never set in your own browser; they are part of the capture content you chose to collect. Their handling is governed by our Privacy Policy and, for customers acting as controllers of their capture content, by the Data Processing Agreement, not by this Cookie Policy.
5. localStorage we use
The following first-party localStorage entries may be created when you use guard.ch. localStorage persists until it is removed by the application, by you, or by your browser. All entries are strictly necessary for the function described.
| Key | Purpose | Lifetime |
|---|---|---|
auth | Opaque authentication token issued after sign-in (email and password, email code, passkey, Google, Microsoft, or enterprise SSO). Also used to hold an anonymous session token that is minted when a visitor without an account launches a guest investigation or opens a shared snapshot link. Sent with backend requests to identify your session. | Until you log out, clear site data, or the token is revoked or expires server-side. |
vm | Identifier of the isolated cloud browser workspace running your current investigation, so the live view can reconnect after navigation or a page reload. | Removed when the investigation ends; otherwise until you clear site data. |
analyze_target_<workspaceId> | The URL you submitted for a specific investigation, so the live analysis view can restore its context if the page reloads. | Until you clear site data. |
<page-url>_scaling_dpi | Your preferred display scaling (DPI) for the live investigation viewer, kept so the remote investigation display renders correctly for your screen across reloads. If the entry is absent, the viewer falls back to a default. | Until you clear site data. |
<page-url>_use_browser_cursors | Whether the live investigation viewer renders native browser cursors, kept so the viewer behaves consistently across reloads. If the entry is absent, the viewer falls back to a default. | Until you clear site data. |
<page-url>_crash_count | A per-page counter the live investigation viewer keeps to notice repeated video-stream failures: after a few in a row it switches the viewer to a safer fallback encoder, then resets the counter. It stays in your browser and is never sent to a server. | Reset by the viewer after recovery; otherwise until you clear site data. |
Keys shown with a <page-url> prefix are namespaced by the viewer code, so the exact key in your browser starts with a sanitized form of the viewer page URL. The viewer also deletes obsolete preference keys left behind by earlier versions of the software; that cleanup only removes data, it does not create any.
In addition, the application reads, but never creates, a small number of legacy or diagnostic keys. In particular, it checks for a developer override key named BACKEND_URL (which, if present, points the application at a different backend; it exists only if you or a tool acting on your behalf created it), and it checks for optional viewer branding keys named viewer_logo_<workspaceId>. The application never sets these keys itself, so on an ordinary visit they do not exist.
6. sessionStorage we use
sessionStorage is scoped to a single browser tab and is cleared automatically when the tab closes. We use it for short-lived, first-party state that has to survive a redirect or reload. Most entries are read once and deleted immediately.
| Key | Purpose | Lifetime |
|---|---|---|
authRedirect | The page you were on before being sent to sign in, so you can be returned there afterwards. | Removed when read after sign-in; at most until the tab closes. |
authNotice | A one-time status message (for example a sign-in error) carried across an authentication redirect. | Removed when displayed; at most until the tab closes. |
azure_oauth_state | Random anti-CSRF state for the Sign in with Microsoft flow, verified when Microsoft redirects back to us. | Removed when the sign-in completes; at most until the tab closes. |
sso_oauth_state_<provider> | Random anti-CSRF state for enterprise single sign-on, verified when the identity provider redirects back to us. | Removed when the sign-in completes; at most until the tab closes. |
guard.pendingCheckout | The plan you selected before being asked to sign in, so the checkout you requested can resume afterwards. | Removed when the checkout resumes; at most until the tab closes. |
guard.fromAnalyze.<workspaceId> | A one-shot interface flag (the value is "1") that prevents a loading animation from playing twice when you move from a live investigation to its snapshots. Contains no personal data. | Removed on first read; at most until the tab closes. |
7. What we do not use
On guard.ch we do not use advertising or marketing cookies, retargeting pixels, social media plugins, or any third-party advertising trackers. We do not fingerprint our own visitors to identify them across other sites, and we do not sell or share identifiers with ad networks or data brokers. We do run first-party product analytics and session recording through PostHog, hosted in the EU and used only to operate and improve the service (Sections 3 and 4). Apart from the Cloudflare Turnstile challenge, Stripe.js on checkout and billing surfaces, and PostHog, no third-party code is loaded into the page.
Fonts and other static assets are bundled and served as part of the site itself; the page does not call third-party font or asset CDNs at runtime.
8. Do Not Track and Global Privacy Control
Guard.ch does not sell personal data and does not share personal data for cross-context behavioral advertising, and we set no advertising cookies, so a Do Not Track (DNT) or Global Privacy Control (GPC) signal has no advertising tracking to switch off. Our first-party product analytics (Section 3) does not currently vary its behavior based on a DNT or GPC signal; to opt out of analytics, block or clear cookies for guard.ch (Section 9) or use a content blocker, and we honor verifiable opt-out, access and deletion requests as described in the Privacy Policy. Our position on US state privacy laws is also set out there.
9. How to refuse, clear, or block
Because everything we store is strictly necessary, refusing or blocking it will break the corresponding feature: without the auth token you cannot stay signed in, and without the workspace entries the investigation viewer cannot reconnect. With that caveat, you stay in control of your browser's storage at all times.
- Log out from the account menu. This removes the
authtoken from your browser and ends the server-side session. - Clear site data for guard.ch in your browser settings (commonly under Privacy, Site Settings, "Cookies and site data", or "Clear browsing data"). This removes all localStorage, sessionStorage, and cookie data for guard.ch, including anything set by Cloudflare or Stripe.
- Close the tab to discard all sessionStorage entries.
- Use private or incognito mode so nothing persists after the private window closes.
- Block storage for guard.ch via your browser's per-site controls. The site will not function in that state.
10. Changes to this policy
We may update this Cookie Policy from time to time, for example when we add, rename, or remove a storage item or change how an existing one works. The "Last updated" date at the top of the page reflects the most recent revision. If a change would introduce storage that requires consent, we will implement a consent mechanism before the change takes effect, as described in section 3. Prior versions are available on request.
11. Contact
Questions about this Cookie Policy or about how we handle cookies and browser storage can be addressed to:
Zesiger.net
[email protected]
See also our Privacy Policy, the Data Processing Agreement, and the Imprint, which carries the postal address and registry details.