Cookies and browser storage

Last updated 9 October 2026

Draft pending legal review. It describes how the product works today; the final version may change before paid launch.

Dashboard

  • pl_session — keeps you signed in (httpOnly).
  • pl_csrf — protects forms from cross-site requests.
  • pl_ws — remembers the workspace you selected.

Website widget (on our customers' sites)

  • pl_sid_* (local storage) — a random visit ID, landing UTM source and referrer domain; replaced after 30 minutes of inactivity.
  • pl_shown_*, pl_dismissed_* (session storage) — how often a notification was shown and whether you closed it.

No advertising or cross-site tracking cookies. Businesses can make the widget wait for consent, and ProofLoom.consent(false) clears these values.

We don't claim this satisfies every cookie law; each business remains responsible for its own consent banner.