1. Introduction
This Cookie Policy explains how cookies and similar technologies are used across filigran.io (the “Website”), academy.filigran.io (“Filigran Academy”), and our online platforms (“Services”) (together, the “Filigran Sites and Services”). It forms part of our broader Privacy Policy and should be read alongside it. Capitalised terms not defined in this Cookie Policy have the meaning set out in our Privacy Policy.
Cookies and similar technologies are used across the Filigran Sites and Services. For deployments of the Services hosted by Filigran (SaaS), Filigran is the cookie provider where specified in Section 4 (Cookies we use). For on-premises deployments of Services, the cookies are set by the customer hosting the platform and the on-premises host is the provider. If this changes, we will update this Cookie Policy accordingly. These platform cookies relate to accessing the SaaS platforms – any personal data processed within the platforms themselves is governed by the applicable Data Processing Agreement.
2. What Are Cookies?
Cookies are small text files that are placed on your device by websites you visit. They are widely used to make websites work more efficiently, as well as provide information to the site owners.
Cookies help us recognise your browser or device and remember certain information about your visits, such as your preferences or login status. They allow us to analyse traffic and usage patterns to improve the user experience.
Cookies can be stored for different lengths of time:
- Session cookies are temporary and are deleted once you close your browser.
- Persistent cookies remain on your device for a set period or until you delete them, allowing us to recognise you on return visits.
We may also use similar tracking technologies (such as pixels or local storage) that operate in the same way as cookies. You can find more details about specific cookies we use in the Cookie Table below.
3. Types of Cookies
We use different types of cookies across the Filigran Sites and Services which provide functionality, enhance user experience, and help us understand how the Filigran Sites and Services are used. Below is a summary of the categories of cookies we use:
- Necessary Cookies – these are essential for the Filigran Sites and Services to function properly. They enable core features such as secure log-in, page navigation, and consent management. These cookies do not collect personally identifiable information for marketing purposes.
- Functional Cookies – allow the Filigran Sites and Services to remember choices you make (such as display preferences) and enable enhanced features like social sharing or feedback collection. These cookies may be set by us or by third-party providers.
- Performance and Analytics Cookies – collect information about how visitors use the Filigran Sites and Services, such as which pages are visited most often or if users encounter errors, measure how the Filigran Sites and Services are performing, often in terms of speed, responsiveness and load balancing. The data helps us improve the Filigran Sites and Services performance and user experience.
- Marketing Cookies – used to deliver relevant advertisements to you based on your browsing behaviour and interests. They also help us measure the effectiveness of advertising campaigns. These may be set by us or by third-party ad partners.
4. Cookies We Use
The cookies we use are set out below by property. Where a cookie appears under more than one property, it is set across those properties.
Website (filigran.io)
| Cookie Name | Provider | Purpose | Duration | Type |
| cookieyes-consent | CookieYes | Stores user’s cookie consent preferences | 1 year | Necessary |
| __cf_bm | Cloudflare | Distinguish between humans and bots | ~30 minutes | Necessary |
| _cfuvid | Cloudflare | Bot protection / rate limiting | Session | Necessary |
| __sec__cid | Filigran | Security session identifier | 1 day | Necessary |
| __sec__fid | Filigran | Security fingerprint ID | ~4 months | Necessary |
| __sec__ghost | Filigran | Anti-bot security token | ~9 months | Necessary |
| __sec__token | Filigran | JWT security token for authentication | 1 day | Necessary |
| __sec_crid | Filigran | Security request ID | ~3 months | Necessary |
| __sec_tid | Filigran | Security tracking ID | ~3 months | Necessary |
| pll_language | WordPress/Polylang | Stores selected language preference | 1 year | Necessary |
| slReferer | Filigran | Tracks referrer URL for internal routing | ~3 months | Necessary |
| __hs_cookie_cat_pref | HubSpot | Stores HubSpot cookie category preferences | ~4 months | Functional |
| __sec_id | Reo.dev | User identity for B2B visitor identification | ~4 months | Functional |
| __sec_peid | Reo.dev | Encrypted profile ID for visitor identification | ~10 months | Functional |
| _BEAMER_BOOSTED_ANNOUNCEMENT_DATE* | Beamer | Tracks last seen announcement | ~4 months | Functional |
| _BEAMER_FIRST_VISIT* | Beamer | Records first visit date for notification widget | ~8 months | Functional |
| _BEAMER_USER_ID* | Beamer | Unique user ID for notification widget | ~8 months | Functional |
| _ga | Google Analytics | Distinguishes unique users and sessions | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_34TR31ZHMR | Google Analytics | GA4 session persistence (primary property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_9FC0TL0TH3 | Google Analytics | GA4 session persistence (secondary property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_9WXYK3PMB6 | Google Analytics | GA4 session persistence (tertiary property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_LVN95WRF25 | Google Analytics | GA4 session persistence (fourth property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| ajs_anonymous_id | RudderStack | Anonymous user ID for analytics | 1 year | Performance / Analytics |
| rl_anonymous_id | RudderStack | RudderStack anonymous user identifier | ~7 months | Performance / Analytics |
| rl_session | RudderStack | RudderStack session tracking | ~7 months | Performance / Analytics |
| rl_page_init_referrer | RudderStack | Stores initial referrer page | ~5 months | Performance / Analytics |
| rl_page_init_referring_domain | RudderStack | Stores initial referring domain | ~5 months | Performance / Analytics |
| rl_trait | RudderStack | Stores user traits for analytics | ~7 months | Performance / Analytics |
| rl_user_id | RudderStack | Identified user ID | ~7 months | Performance / Analytics |
| ph_phc_4URI…_posthog | PostHog | Product analytics — session and user tracking | ~7 months | Performance / Analytics |
| mp_c0b386…_mixpanel | Mixpanel | User identification and event tracking | ~10 months | Performance / Analytics |
| __hssc | HubSpot | Tracks session activity and increments session number and timestamps in the __hstc cookie | 30 minutes | Performance / Analytics |
| __hssrc | HubSpot | Detects if a user has opened a new browser session | Session | Performance / Analytics |
| __hstc | HubSpot | Tracks visitors across sessions | ~6 months | Performance / Analytics |
| hubspotutk | HubSpot | Visitor tracking for lead attribution and CRM | ~6 months | Performance / Analytics |
| _conv_r | HubSpot / Convert | Tracks referral source for conversion attribution | ~5 months | Marketing |
| _conv_v | HubSpot / Convert | Visitor data for A/B testing and conversion tracking | ~5 months | Marketing |
| _gcl_ls | Google Tag Manager | Stores Google Ads linker parameter for cross-domain conversion tracking | Persistent | Marketing |
| _gcl_au | Google Ads | Google Ads conversion linker | ~3 months | Marketing |
| test_cookie | Google (DoubleClick) | Checks whether the browser supports cookies for ad delivery | ~15 minutes | Marketing |
Filigran Academy (academy.filigran.io)
| Cookie Name | Provider | Purpose | Duration | Type |
| slim_session | Filigran Academy | Maintains the authenticated Filigran Academy session | Session | Necessary |
| lw_tokens | LearnWorlds | Stores the logged-in user’s Academy access/refresh tokens | 7 days | Necessary |
| school | LearnWorlds | Academy platform session identifier | Session | Necessary |
| __stripe_mid | Stripe | Fraud prevention for Stripe-processed payments on Filigran Academy | 1 year | Necessary |
| __stripe_sid | Stripe | Stripe session identifier used for fraud prevention on Filigran Academy | 30 minutes | Necessary |
| _cfuvid | Cloudflare | Bot protection / rate limiting | Session | Necessary |
| __cf_bm | Cloudflare | Distinguish between humans and bots | ~30 minutes | Necessary |
| _BEAMER_FILTER_BY_URL* | Beamer | Stores whether URL filtering should be applied to the notification feed | 20 minutes | Functional |
| _BEAMER_FIRST_VISIT* | Beamer | Records first visit date for notification widget | ~8 months | Functional |
| _BEAMER_USER_ID* | Beamer | Unique user ID for notification widget | ~8 months | Functional |
| _ga | Google Analytics | Distinguishes unique users and sessions | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_LVN95WRF25 | Google Analytics | GA4 session persistence (fourth property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| __hssc | HubSpot | Tracks session activity and increments session number and timestamps in the __hstc cookie | 30 minutes | Performance / Analytics |
| __hssrc | HubSpot | Detects if a user has opened a new browser session | Session | Performance / Analytics |
| __hstc | HubSpot | Tracks visitors across sessions | ~6 months | Performance / Analytics |
| hubspotutk | HubSpot | Visitor tracking for lead attribution and CRM | ~6 months | Performance / Analytics |
| __mp_aliased | Mixpanel | Records that a Mixpanel user identity has been aliased | ~6 months | Performance / Analytics |
| _gcl_au | Google Ads | Google Ads conversion linker | ~3 months | Marketing |
| test_cookie | Google (DoubleClick) | Checks whether the browser supports cookies for ad delivery | ~15 minutes | Marketing |
XTM Hub
| Cookie Name | Provider | Purpose | Duration | Type |
| scrollPosition | Filigran | Stores scroll position for Hub UX continuity | Session | Necessary |
| cloud-portal | Filigran | Session cookie for Hub portal authentication | Session | Necessary |
| __cf_bm | Cloudflare | Distinguish between humans and bots | ~30 minutes | Necessary |
| _ga | Google Analytics | Distinguishes unique users and sessions | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_34TR31ZHMR | Google Analytics | GA4 session persistence (primary property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_9FC0TL0TH3 | Google Analytics | GA4 session persistence (secondary property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_9WXYK3PMB6 | Google Analytics | GA4 session persistence (tertiary property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| _ga_LVN95WRF25 | Google Analytics | GA4 session persistence (fourth property) | 1 year 1 month 4 days (~400 days) | Performance / Analytics |
| __hstc | HubSpot | Tracks visitors across sessions | ~6 months | Performance / Analytics |
| __hssrc | HubSpot | Detects if a user has opened a new browser session | Session | Performance / Analytics |
| __hssc | HubSpot | Tracks session activity and increments session number and timestamps in the __hstc cookie | 30 minutes | Performance / Analytics |
| hubspotutk | HubSpot | Visitor tracking for lead attribution and CRM | ~6 months | Performance / Analytics |
| _gcl_au | Google Ads | Google Ads conversion linker | ~3 months | Marketing |
| _gcl_ls | Google Tag Manager | Stores Google Ads linker parameter for cross-domain conversion tracking | Persistent | Marketing |
XTM One
| Cookie Name | Provider | Purpose | Duration | Type |
| filigran.io | Filigran | Authentication / session management | Session (expires once the session ends) | Necessary |
OpenCTI
| Cookie Name | Provider | Purpose | Duration | Type |
| opencti_session | Filigran | Maintains the authenticated user session | 20 minutes by default, configurable via the app:session_timeout setting | Necessary |
| opencti_flash | Filigran | Displays transient error messages after authentication failures | 10 seconds | Necessary |
OpenAEV
| Cookie Name | Provider | Purpose | Duration | Type |
| JSESSIONID | Filigran | Identifies the authenticated OpenAEV session | Until the session is destroyed (server-side) or 24 hours | Necessary |
| url_access_token | Filigran | Stores the authentication token when accessing OpenAEV via a link provided by email | Attached to a simulation until the simulation ends; max 30 days by default (configurable per instance) | Necessary |
| XSRF-TOKEN / X-XSRF-TOKEN | Filigran | CSRF protection: read by the OpenAEV front-end and sent back as header X-XSRF-TOKEN | Until the session is destroyed (server-side) | Necessary |
| openaev_token | Filigran | Authentication-by-token cookie; fallback when no Authorization header is present | 1 day | Necessary |
5. Managing Cookies
You can manage your cookie preferences at any time through our cookie consent tool, which allows you to enable or disable non-essential cookies. Necessary cookies are always active and cannot be turned off, as they are essential for the basic functioning of the Filigran Sites and Services. In addition to the consent tool, you may also manage cookies by adjusting your browser settings to refuse or delete cookies. However, doing so may impact the functionality and performance of the Filigran Sites and Services.
6. Changes to This Cookie Policy
We may update this Cookie Policy from time to time in our sole discretion. If we make any material changes, we will notify you in accordance with applicable legal requirements.
7. Contact Information
If you have any questions about this Cookie Policy or our use of cookies, please contact us at privacy@filigran.io.
For more details about how we handle your personal data, please refer to our Privacy Policy.