Last updated: September 6, 2026
Cookie policy
Hide currently uses only strictly necessary first-party cookies. We do not use advertising cookies, optional analytics cookies, session replay or cross-site tracking.
1. What this policy covers
Cookies are small pieces of information stored by a website in your browser. Hide uses secure first-party cookies to remember the authority to manage a private exposure case or legacy report and to keep an authenticated personal or company session.
2. Legal basis
Under § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), information may be stored or accessed without consent where this is strictly necessary to provide a digital service requested by the user. Hide relies on this exception only for the essential functions described below.
Because Hide does not currently set optional cookies, no cookie-consent banner is shown. If optional analytics, advertising or similar technologies are introduced, this policy and the interface will be updated before they are activated, and consent will be requested where required.
3. Essential cookies
- hide_manage_[report identifier]
- Allows the browser that created a private Hide Check case, Hide Verify result or legacy public report to manage its protected controls. The token is Secure, HttpOnly and SameSite=Strict. Hide Check and Job Posting Check management cookies last up to 30 days, legacy Clear report-management cookies last up to 90 days, and a Hide Verify outcome token lasts up to 12 months so the creator can return with later ground truth.
- hide_company_session
- Keeps a verified personal or company user signed in. Where two-step sign-in is enabled, this cookie is issued only after both factors succeed. It is Secure, HttpOnly and SameSite=Lax and expires after up to 30 days or earlier when the user signs out.
- hide_mfa_challenge
- Temporarily connects a successful email-code check to the authenticator step without exposing the challenge credential to page scripts. It is Secure, HttpOnly, SameSite=Strict, restricted to the authenticator endpoint and expires after ten minutes.
Cookie values are high-entropy credentials. Hide stores only cryptographic hashes of report-management and company-session tokens in its database.
4. Services outside hidedata.app
If paid features are enabled and you choose to open Stripe Checkout, Stripe may use cookies on its own service under its own policy. Operators of websites and public sources requested during a Clear scan receive ordinary network requests but cannot set cookies on hidedata.app through that process.
5. Your controls
You can inspect, block or delete cookies in your browser settings. Blocking essential Hide cookies may prevent case-management controls or company sign-in from working. Deleting a management cookie does not delete the related case or report; use its delete control first.
6. Changes and contact
We may update this policy when the service or legal requirements change. A new optional cookie category will not be enabled without the consent required by law.
Questions about cookies or privacy can be sent to info@hidedata.app. See the privacy notice, terms and Impressum for related information.