Skip to content
QA environmentSynthetic test data. Sandboxed email / SMS / fax / Stripe. Safe to break.

Cookie Policy

Last updated: July 9, 2026

SLDocs uses a small number of cookies that are strictly necessary to operate the service — for example, to keep you signed in, to protect against cross-site request forgery, and to route requests to the correct tenant on our white-label domains.

We do not use cookies for analytics, advertising, profiling, or any other non-essential purpose. Even during our limited beta, the beta product-analytics tool described below is cookieless and sets no cookie. Apart from that beta tool — which runs only for enrolled beta testers who acknowledged our beta session-tracking notice at signup — we do not embed third-party tracking pixels, session-replay tools, or marketing SDKs. No cookie consent banner is shown and none is required: SLDocs is a U.S.-only service whose users attest they reside in the United States (which places us outside the EU/UK ePrivacy banner regime), and in any event the beta tool stores and accesses nothing on your device.

Cookies we set

CookiePurposeDuration
next-auth.session-token
(or __Secure-next-auth.session-token in production)
Keeps you signed in to your SLDocs account.Session
next-auth.csrf-token
(or __Host-next-auth.csrf-token in production)
Protects against cross-site request forgery during sign-in.Session
next-auth.callback-url
(or __Secure-next-auth.callback-url in production)
Returns you to the page you came from after signing in.Session
trusted_deviceRemembers a device you chose to trust so you can skip the second sign-in (two-factor) step on that device.7 days
pending_2faTemporarily carries your sign-in between the password step and the verification-code step.~11 minutes
branding_tenant_idOn white-label domains, remembers which law firm tenant your request belongs to so the correct branding is shown.5 minutes
av_challengeHolds a one-time access code while you verify as a designated recipient before viewing a vault.10 minutes
av_verifiedConfirms you completed recipient verification so you can view the documents shared with you.60 minutes
med_challengeHolds a one-time code during emergency medical (break-glass) access verification.10 minutes
site_accessDuring our pre-launch period, records that you submitted a valid site access code so you don't have to re-enter it on every page. Only set after you submit the code.7 days

Third-party services

SLDocs relies on a number of third-party service providers to deliver the service. None of these providers set tracking cookies on your browser through SLDocs. If you make a payment, our payment processor may set its own cookies on its own domain during checkout — see that processor's cookie policy for details. The full list of service providers we use and what data each one processes is published on our Subprocessors page.

Beta product analytics (enrolled beta testers only — temporary)

During our limited beta, if you are an enrolled beta tester and acknowledged our beta session-tracking notice at signup, we use a third-party product-analytics tool (PostHog) to understand how testers navigate and use the site so we can improve it. This runs only for signed-in beta testers who gave that acknowledgment — never for other users, and never for visitors who are not signed in.

The tool is configured to be cookieless: it stores nothing on your device — no cookies and no browser/local storage. It records only pageviews and specific in-product events (which pages and features you use). Automatic capture and session recording are turned off, so it does not capture the contents of your documents, your form entries, or your vault. Data is processed in the United States.

PostHog acts solely as our service provider: it processes this data only to provide the analytics to us, may not use it for its own purposes, and may not sell, share, or disclose it to anyone else. It is used only by SLDocs to improve the product before launch — so this is not a “sale” or “share” of personal information under U.S. state privacy laws.

This is a beta-only measure. The tool is removed and this measurement stops when the beta ends (expected within roughly one to one-and-a-half months). PostHog is listed on our Subprocessors page for the beta period.

Controlling cookies

Because all cookies SLDocs sets are strictly necessary, blocking them will prevent you from signing in or using the service. You can delete them at any time via your browser's settings (Chrome: Settings → Privacy and security → Cookies; Safari: Preferences → Privacy; Firefox: Settings → Privacy & Security).

Changes

If we ever add cookies that are not strictly necessary — for example, analytics — we will update this page and ask for your consent before setting them.

Contact

Questions about this policy? Email legal@sldocs.com.

Please don't email sensitive personal or health information or documents — email isn't encrypted and may be stored outside the U.S. Use your in-product vault instead.