Cookie Policy
Effective date: 2 October 2026
Enji Guard has two surfaces of its own and they behave differently, so this page covers both — and then says what happens at the checkout, which is on someone else’s.
You are asked twice, and the two answers are independent. Once on the public website, and once inside the application after you sign in. Accepting on one is not accepting on the other, and refusing one does not refuse the other — they are separate decisions because they are separate kinds of measurement, and you can change either at any time without touching the first.
The public website — optional analytics and attribution, and only after you accept them. Reject and carry on using the site; change your mind with the Cookie settings button in the footer.
The application — product analytics only: which milestones you reach, so we can see where the product works and where people get stuck. No advertising, no attribution storage, and nothing that follows you off the site. Reject it and the product works exactly the same.
The public website
| Name | Provider | Purpose | Type | Lifetime | Data flow |
|---|---|---|---|---|---|
enji_guard_cookie_consent_v1 | Enji Guard | Stores whether the visitor accepted or rejected optional analytics and attribution storage. An expired choice is rejected and cleared the next time it is read. | Essential | Up to 180 days | Stored in the visitor’s browser. It is not sent to Google Analytics by this site. |
guard_attribution_v1 | Enji Guard | Stores sanitized campaign parameters, click-id presence, landing page, referrer origin, capture time, and expiry after consent. | Analytics and attribution | Up to 90 days | Stored in localStorage. Values may be attached to Enji Guard analytics events after optional storage is accepted. |
_ga | Google Analytics | Helps Google Analytics distinguish visits after optional analytics is accepted. | Analytics | Up to 2 years by Google Analytics default settings | Sent to Google Analytics when the analytics tag is active. |
_ga_<container-id> | Google Analytics | Keeps session state for the configured Google Analytics 4 property after consent. | Analytics | Up to 2 years by Google Analytics default settings | Sent to Google Analytics when the analytics tag is active. |
__cf_bm | Cloudflare | Bot management — distinguishes automated traffic from people. | Essential security | 30 minutes | Processed by Cloudflare as the CDN and security edge. |
cf_clearance | Cloudflare | Records that a security challenge was passed, so you are not asked again. Set on .enji.ai, HttpOnly and Secure. | Essential security | Set by Cloudflare’s challenge-passage setting — about 6 months on our current configuration, and only if a challenge was shown | Processed by Cloudflare as the CDN and security edge. |
The lifetimes above are the cookies’. The analytics data itself is retained separately: 14 months for user- and event-level data on our Google Analytics properties — see Data Retention & Deletion.
Cloudflare controls the names and lifetimes of its own security cookies and may set others if we
enable further security features. The two above are what our current configuration uses; any other
__cf or cf_ cookie comes from Cloudflare’s edge and serves security rather than tracking. Ask us
and we will confirm what a particular one is.
Performance measurement without storage
Cloudflare’s web-analytics beacon runs on the public site to measure page performance and traffic. It sets no cookie and writes nothing to your browser, which is why it is not in the table and why it is not gated behind the consent banner — the consent rule for cookies attaches to storing or reading things on your device, and this does neither.
But it still processes your IP address and request metadata, so consent is not the whole question.
- Why we are allowed to: our legitimate interest in knowing whether our own website is fast and working. We have weighed that against your interests; the data is not used to build a profile, is not combined with anything else, and is not used for advertising.
- You can object. Write to contact@enji.ai and tell us. You can also
block the request at
static.cloudflareinsights.comin your browser, which stops it outright.
It is measurement rather than a security control, which is why it is described here and not listed as essential.
The application
Storage in the product falls into three groups.
Cookies
| Name | Provider | Purpose | Type | Lifetime |
|---|---|---|---|---|
cf_clearance | Cloudflare | The same cookie as on the website — it is set on .enji.ai and covers both. See the table above. | Essential security | Set by Cloudflare — about 6 months on our current configuration |
Session storage — cleared when you close the tab.
| Key | Purpose | Type |
|---|---|---|
upfront.auth-user | Your signed-in identity: id, email, name, role. Without it the app does not know who you are. | Strictly necessary |
upfront.user-key | Your account identifier, used to key the rest of the state below. | Strictly necessary |
upfront.route-scroll.v1 | Where you had scrolled on each screen, so going back returns you to the same place. | Functional |
Local storage — persists until you clear it. None of these expire on their own.
| Key | Purpose | Type |
|---|---|---|
upfront.locale | Interface language. | Functional |
upfront.theme | Light, dark or system. | Functional |
upfront:project-activity-orbit:visible | Whether a panel is shown or hidden. | Functional |
upfront:active-repo-runs:<repo-id> | Which audit runs are in progress for a repository, so the interface can show their state without re-querying. | Functional |
upfront:audit-run:<repo-id>:<audit> | The status of a particular run — task id, state, last update. | Functional |
upfront.ga.once.* | Markers recording that a product milestone event — signing up, starting a first audit, completing one — has already been reported to Google Analytics, so it is not reported twice. Keyed to your account. | Analytics |
Product analytics has its own consent, separate from the website’s.
- You are asked inside the application, separately from the banner on the website.
- Refusing the website’s analytics does not refuse the product’s, and refusing the product’s does not refuse the website’s. Two questions, two answers, either changeable at any time.
- If you refuse, the
upfront.ga.once.*keys are not written and no events are sent. Everything else in the tables above still runs, because the product needs it. - You can change your mind inside the application, in the same place the choice was asked for, without touching your answer on the website. If you cannot find it, write to contact@enji.ai and we will change it for you.
- Withdrawing stops the events immediately, and the
upfront.ga.once.*markers are removed where the browser allows it. Clearing site data in your browser removes them in every case. - Product analytics is never tied to advertising and is never shared for it.
Why some entries are not asked about
The consent rule attaches to storing or reading things on your device, with an exemption for what is strictly necessary to provide the service you asked for. Entries marked Strictly necessary sit inside that exemption: without your signed-in identity and the key the rest of your state hangs off, the application cannot tell who you are, and without Cloudflare’s challenge cookie the site cannot tell you apart from a bot it has just blocked.
Entries marked Functional — language, theme, panel state, scroll position, the status of runs in progress — are there to make the interface behave as you left it. They carry no identifier used for measurement, are never read by Google Analytics, and never leave your browser. We treat them as exempt on that basis; if any of them ever started feeding analytics, it would move into the consent gate.
Everything marked Analytics or Analytics and attribution is gated behind a choice.
Buying credits happens on Freemius’s pages, not ours
When you buy credits you leave this site. The checkout is hosted by Freemius, our merchant of record, on its own domain. The cookies you meet there are Freemius’s — payment, security, fraud prevention, and its own record of the choice you make about them — and they are governed by Freemius’s cookie policy and its own consent banner, which is also where you change them.
The tables above are the complete inventory for our own two surfaces. A checkout cookie is not one of ours to list, set or clear, and if you want it gone, Freemius’s banner rather than ours is the place. Who is responsible for which part of a purchase is set out in the Imprint, and what Freemius does with your payment data is in Privacy Policy §1.
How consent works
On the website. Before a choice is saved, Enji Guard does not load Google Analytics and does not write the attribution localStorage key. If you accept all optional storage, analytics and attribution start for that browser. If you reject optional storage, Enji Guard stores only the rejection choice and removes optional analytics storage where the browser allows it. Change your mind with the Cookie settings button in the footer.
In the application. The same before-and-after applies to product analytics, asked separately
after you sign in: before you answer, no events are sent and no upfront.ga.once.* marker is
written.
Essential security cookies set by Cloudflare may still appear on both surfaces because they help deliver and protect the site. They are separate from Google Analytics and attribution.
Enji Guard