Cookie Policy

Validity Date: 15 July 2026

1. Introduction

This Cookie Policy explains how cookies and similar technologies are used across filigran.io (the “Website”), academy.filigran.io (“Filigran Academy”), and our online platforms (“Services”) (together, the “Filigran Sites and Services”). It forms part of our broader Privacy Policy and should be read alongside it. Capitalised terms not defined in this Cookie Policy have the meaning set out in our Privacy Policy.

Cookies and similar technologies are used across the Filigran Sites and Services. For deployments of the Services hosted by Filigran (SaaS), Filigran is the cookie provider where specified in Section 4 (Cookies we use). For on-premises deployments of Services, the cookies are set by the customer hosting the platform and the on-premises host is the provider. If this changes, we will update this Cookie Policy accordingly. These platform cookies relate to accessing the SaaS platforms – any personal data processed within the platforms themselves is governed by the applicable Data Processing Agreement.

2. What Are Cookies?

Cookies are small text files that are placed on your device by websites you visit. They are widely used to make websites work more efficiently, as well as provide information to the site owners.

Cookies help us recognise your browser or device and remember certain information about your visits, such as your preferences or login status. They allow us to analyse traffic and usage patterns to improve the user experience.

Cookies can be stored for different lengths of time:

  • Session cookies are temporary and are deleted once you close your browser.
  • Persistent cookies remain on your device for a set period or until you delete them, allowing us to recognise you on return visits.

We may also use similar tracking technologies (such as pixels or local storage) that operate in the same way as cookies. You can find more details about specific cookies we use in the Cookie Table below.

3. Types of Cookies

We use different types of cookies across the Filigran Sites and Services which provide functionality, enhance user experience, and help us understand how the Filigran Sites and Services are used. Below is a summary of the categories of cookies we use:

  • Necessary Cookies – these are essential for the Filigran Sites and Services to function properly. They enable core features such as secure log-in, page navigation, and consent management. These cookies do not collect personally identifiable information for marketing purposes.
  • Functional Cookies – allow the Filigran Sites and Services to remember choices you make (such as display preferences) and enable enhanced features like social sharing or feedback collection. These cookies may be set by us or by third-party providers.
  • Performance and Analytics Cookies – collect information about how visitors use the Filigran Sites and Services, such as which pages are visited most often or if users encounter errors, measure how the Filigran Sites and Services are performing, often in terms of speed, responsiveness and load balancing. The data helps us improve the Filigran Sites and Services performance and user experience.
  • Marketing Cookies – used to deliver relevant advertisements to you based on your browsing behaviour and interests. They also help us measure the effectiveness of advertising campaigns. These may be set by us or by third-party ad partners.

4. Cookies We Use

The cookies we use are set out below by property. Where a cookie appears under more than one property, it is set across those properties.

Website (filigran.io)

Cookie NameProviderPurposeDurationType
cookieyes-consentCookieYesStores user’s cookie consent preferences1 yearNecessary
__cf_bmCloudflareDistinguish between humans and bots~30 minutesNecessary
_cfuvidCloudflareBot protection / rate limitingSessionNecessary
__sec__cidFiligranSecurity session identifier1 dayNecessary
__sec__fidFiligranSecurity fingerprint ID~4 monthsNecessary
__sec__ghostFiligranAnti-bot security token~9 monthsNecessary
__sec__tokenFiligranJWT security token for authentication1 dayNecessary
__sec_cridFiligranSecurity request ID~3 monthsNecessary
__sec_tidFiligranSecurity tracking ID~3 monthsNecessary
pll_languageWordPress/PolylangStores selected language preference1 yearNecessary
slRefererFiligranTracks referrer URL for internal routing~3 monthsNecessary
__hs_cookie_cat_prefHubSpotStores HubSpot cookie category preferences~4 monthsFunctional
__sec_idReo.devUser identity for B2B visitor identification~4 monthsFunctional
__sec_peidReo.devEncrypted profile ID for visitor identification~10 monthsFunctional
_BEAMER_BOOSTED_ANNOUNCEMENT_DATE*BeamerTracks last seen announcement~4 monthsFunctional
_BEAMER_FIRST_VISIT*BeamerRecords first visit date for notification widget~8 monthsFunctional
_BEAMER_USER_ID*BeamerUnique user ID for notification widget~8 monthsFunctional
_gaGoogle AnalyticsDistinguishes unique users and sessions1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_34TR31ZHMRGoogle AnalyticsGA4 session persistence (primary property)1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_9FC0TL0TH3Google AnalyticsGA4 session persistence (secondary property)1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_9WXYK3PMB6Google AnalyticsGA4 session persistence (tertiary property)1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_LVN95WRF25Google AnalyticsGA4 session persistence (fourth property)1 year 1 month 4 days (~400 days)Performance / Analytics
ajs_anonymous_idRudderStackAnonymous user ID for analytics1 yearPerformance / Analytics
rl_anonymous_idRudderStackRudderStack anonymous user identifier~7 monthsPerformance / Analytics
rl_sessionRudderStackRudderStack session tracking~7 monthsPerformance / Analytics
rl_page_init_referrerRudderStackStores initial referrer page~5 monthsPerformance / Analytics
rl_page_init_referring_domainRudderStackStores initial referring domain~5 monthsPerformance / Analytics
rl_traitRudderStackStores user traits for analytics~7 monthsPerformance / Analytics
rl_user_idRudderStackIdentified user ID~7 monthsPerformance / Analytics
ph_phc_4URI…_posthogPostHogProduct analytics — session and user tracking~7 monthsPerformance / Analytics
mp_c0b386…_mixpanelMixpanelUser identification and event tracking~10 monthsPerformance / Analytics
__hsscHubSpotTracks session activity and increments session number and timestamps in the __hstc cookie30 minutesPerformance / Analytics
__hssrcHubSpotDetects if a user has opened a new browser sessionSessionPerformance / Analytics
__hstcHubSpotTracks visitors across sessions~6 monthsPerformance / Analytics
hubspotutkHubSpotVisitor tracking for lead attribution and CRM~6 monthsPerformance / Analytics
_conv_rHubSpot / ConvertTracks referral source for conversion attribution~5 monthsMarketing
_conv_vHubSpot / ConvertVisitor data for A/B testing and conversion tracking~5 monthsMarketing
_gcl_lsGoogle Tag ManagerStores Google Ads linker parameter for cross-domain conversion trackingPersistentMarketing
_gcl_auGoogle AdsGoogle Ads conversion linker~3 monthsMarketing
test_cookieGoogle (DoubleClick)Checks whether the browser supports cookies for ad delivery~15 minutesMarketing

Filigran Academy (academy.filigran.io)

Cookie NameProviderPurposeDurationType
slim_sessionFiligran AcademyMaintains the authenticated Filigran Academy sessionSessionNecessary
lw_tokensLearnWorldsStores the logged-in user’s Academy access/refresh tokens7 daysNecessary
schoolLearnWorldsAcademy platform session identifierSessionNecessary
__stripe_midStripeFraud prevention for Stripe-processed payments on Filigran Academy1 yearNecessary
__stripe_sidStripeStripe session identifier used for fraud prevention on Filigran Academy30 minutesNecessary
_cfuvidCloudflareBot protection / rate limitingSessionNecessary
__cf_bmCloudflareDistinguish between humans and bots~30 minutesNecessary
_BEAMER_FILTER_BY_URL*BeamerStores whether URL filtering should be applied to the notification feed20 minutesFunctional
_BEAMER_FIRST_VISIT*BeamerRecords first visit date for notification widget~8 monthsFunctional
_BEAMER_USER_ID*BeamerUnique user ID for notification widget~8 monthsFunctional
_gaGoogle AnalyticsDistinguishes unique users and sessions1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_LVN95WRF25Google AnalyticsGA4 session persistence (fourth property)1 year 1 month 4 days (~400 days)Performance / Analytics
__hsscHubSpotTracks session activity and increments session number and timestamps in the __hstc cookie30 minutesPerformance / Analytics
__hssrcHubSpotDetects if a user has opened a new browser sessionSessionPerformance / Analytics
__hstcHubSpotTracks visitors across sessions~6 monthsPerformance / Analytics
hubspotutkHubSpotVisitor tracking for lead attribution and CRM~6 monthsPerformance / Analytics
__mp_aliasedMixpanelRecords that a Mixpanel user identity has been aliased~6 monthsPerformance / Analytics
_gcl_auGoogle AdsGoogle Ads conversion linker~3 monthsMarketing
test_cookieGoogle (DoubleClick)Checks whether the browser supports cookies for ad delivery~15 minutesMarketing

XTM Hub

Cookie NameProviderPurposeDurationType
scrollPositionFiligranStores scroll position for Hub UX continuitySessionNecessary
cloud-portalFiligranSession cookie for Hub portal authenticationSessionNecessary
__cf_bmCloudflareDistinguish between humans and bots~30 minutesNecessary
_gaGoogle AnalyticsDistinguishes unique users and sessions1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_34TR31ZHMRGoogle AnalyticsGA4 session persistence (primary property)1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_9FC0TL0TH3Google AnalyticsGA4 session persistence (secondary property)1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_9WXYK3PMB6Google AnalyticsGA4 session persistence (tertiary property)1 year 1 month 4 days (~400 days)Performance / Analytics
_ga_LVN95WRF25Google AnalyticsGA4 session persistence (fourth property)1 year 1 month 4 days (~400 days)Performance / Analytics
__hstcHubSpotTracks visitors across sessions~6 monthsPerformance / Analytics
__hssrcHubSpotDetects if a user has opened a new browser sessionSessionPerformance / Analytics
__hsscHubSpotTracks session activity and increments session number and timestamps in the __hstc cookie30 minutesPerformance / Analytics
hubspotutkHubSpotVisitor tracking for lead attribution and CRM~6 monthsPerformance / Analytics
_gcl_auGoogle AdsGoogle Ads conversion linker~3 monthsMarketing
_gcl_lsGoogle Tag ManagerStores Google Ads linker parameter for cross-domain conversion trackingPersistentMarketing

XTM One

Cookie NameProviderPurposeDurationType
filigran.ioFiligranAuthentication / session managementSession (expires once the session ends)Necessary

OpenCTI

Cookie NameProviderPurposeDurationType
opencti_sessionFiligranMaintains the authenticated user session20 minutes by default, configurable via the app:session_timeout settingNecessary
opencti_flashFiligranDisplays transient error messages after authentication failures10 secondsNecessary

OpenAEV

Cookie NameProviderPurposeDurationType
JSESSIONIDFiligranIdentifies the authenticated OpenAEV sessionUntil the session is destroyed (server-side) or 24 hoursNecessary
url_access_tokenFiligranStores the authentication token when accessing OpenAEV via a link provided by emailAttached to a simulation until the simulation ends; max 30 days by default (configurable per instance)Necessary
XSRF-TOKEN / X-XSRF-TOKENFiligranCSRF protection: read by the OpenAEV front-end and sent back as header X-XSRF-TOKENUntil the session is destroyed (server-side)Necessary
openaev_tokenFiligranAuthentication-by-token cookie; fallback when no Authorization header is present1 dayNecessary

5. Managing Cookies

You can manage your cookie preferences at any time through our cookie consent tool, which allows you to enable or disable non-essential cookies. Necessary cookies are always active and cannot be turned off, as they are essential for the basic functioning of the Filigran Sites and Services. In addition to the consent tool, you may also manage cookies by adjusting your browser settings to refuse or delete cookies. However, doing so may impact the functionality and performance of the Filigran Sites and Services.

6. Changes to This Cookie Policy

We may update this Cookie Policy from time to time in our sole discretion. If we make any material changes, we will notify you in accordance with applicable legal requirements.

7. Contact Information

If you have any questions about this Cookie Policy or our use of cookies, please contact us at privacy@filigran.io.

For more details about how we handle your personal data, please refer to our Privacy Policy.