Guard.ch
ProductIntegrationsPricing
Home/Legal/Cookie Policy

Cookie Policy

Find out which cookies and browser data Guard.ch stores, why we use them and how you can clear or block them. Skip to how to clear or block data

Effective May 26, 2026 · Last updated September 23, 2026

On this page

  1. 1. Introduction
  2. 2. Scope: your browser
  3. 3. Consent and legal basis
  4. 4. Cookies
  5. 5. localStorage we use
  6. 6. sessionStorage we use
  7. 7. What we do not use
  8. 8. Do Not Track and Global Privacy Control
  9. 9. Clear or block cookies and browser data
  10. 10. Changes to this policy
  11. 11. Contact

1. Introduction

This Cookie Policy explains how Zesiger.net ("we", "us"), the operator of Guard.ch, uses cookies and equivalent browser storage technologies (localStorage and sessionStorage) on the guard.ch website, the dashboard, and the live analysis view. Most of this storage is strictly necessary to run the service; in addition we set security cookies through Cloudflare and payment cookies through Stripe on checkout. All of them are documented below.

It complements our Privacy Policy, which describes the broader processing of personal data. Where this policy and the Privacy Policy overlap, the Privacy Policy governs the processing of personal data and this policy governs what is stored in your browser and why.

2. Scope: your browser

This policy covers only the items Guard.ch stores in the browser you use to visit guard.ch.

Cookies and storage set by an investigated website are outside this policy. During an investigation, an isolated cloud browser loads the target page and records cookies and changes to localStorage and sessionStorage, among other things. Those entries are never set in your own browser. They are covered by the Privacy Policy and, where you control the investigation content, the Data Processing Agreement.

3. Consent and legal basis

This policy covers the storage needed for sign-in, checkout and investigations. The same rules apply to localStorage and sessionStorage as to cookies: all three store information on, or read it from, your device.

  • ePrivacy Directive, Article 5(3): Consent is not required for storage that is strictly necessary to provide a service the user explicitly requested. We explain the purposes of the different storage items below.
  • GDPR, Article 6(1)(f): Where technically necessary storage involves personal data, we rely on our legitimate interests in operating the service, securing accounts and preventing abuse.
  • Swiss Telecommunications Act, Article 45c: under Swiss law, storing data on your device is permitted where you are informed about the processing, its purpose, and how to refuse it, or where the storage is strictly necessary for the service you requested. This page provides that information, and section 9 explains how to refuse or clear the stored items.

Under the rules above, strictly necessary storage and security and payment cookies do not require consent. Section 8 explains how we treat Do Not Track and Global Privacy Control.

4. Cookies

Guard.ch application code does not set its own cookies. After sign-in, an opaque token is kept in localStorage (Section 5) and sent with backend requests in the Authorization header. Cloudflare and Stripe.js on billing pages may set cookies in your browser; their purposes are described below.

Cloudflare delivers and protects Guard.ch. Its security checks may set cookies when you register, sign in, verify an email code, reset a password or start a browser session. These cookies help distinguish people from automated requests and keep the service available. We do not use them for advertising or tracking. See our subprocessors register and Privacy Policy for more detail.

When you open the checkout page or your subscription page, change your plan, or add or manage a payment method, the page loads Stripe.js from js.stripe.com so that payment details are collected by Stripe directly; Guard.ch never receives or stores your card number. Stripe sets cookies in your browser for fraud prevention and payment security (Stripe documents, for example, __stripe_mid with a lifetime of about one year and __stripe_sid with a lifetime of about 30 minutes; current names and durations are listed in Stripe's own cookie documentation). These cookies are set by Stripe, not by us, and are strictly necessary to complete the payment you requested and to detect fraudulent transactions, consistent with section 3. Stripe.js is loaded only on those billing pages, not on the rest of the site. Stripe's role and the transfer safeguards in place are described in the Stripe entries of our subprocessors register.

5. localStorage we use

The following first-party localStorage entries may be created when you use guard.ch. They persist until removed by the application, by you or by your browser.

KeyPurposeLifetime
authOpaque authentication token issued after sign-in (email and password, email code, passkey, Google, Microsoft, or enterprise SSO). Sent with backend requests to identify your session.Until you log out, clear site data, or the token is revoked or expires server-side.
vmIdentifier of the isolated cloud browser workspace running your current investigation, so the live view can reconnect after navigation or a page reload.Removed when the investigation ends; otherwise until you clear site data.
viewer_target_<workspaceId>The URL you submitted for a specific investigation, so the live analysis view can restore its context if the page reloads.Until you clear site data.
<page-url>_scaling_dpiYour preferred display scaling (DPI) for the live investigation viewer, kept so the remote investigation display renders correctly for your screen across reloads. If the entry is absent, the viewer falls back to a default.Until you clear site data.
<page-url>_use_browser_cursorsWhether the live investigation viewer renders native browser cursors, kept so the viewer behaves consistently across reloads. If the entry is absent, the viewer falls back to a default.Until you clear site data.
<page-url>_crash_countA counter used to detect repeated live-view connection failures. After several failures, the viewer switches to a fallback stream and resets the counter. It stays in your browser.Reset by the viewer after recovery; otherwise until you clear site data.

Keys shown with a <page-url> prefix are namespaced by the viewer code, so the exact key in your browser starts with a sanitized form of the viewer page URL. The viewer also deletes obsolete preference keys left behind by earlier versions of the software; that cleanup only removes data, it does not create any.

The app may also read two optional settings if they are present: a diagnostic backend setting called BACKEND_URL and a viewer branding setting called viewer_logo_<workspaceId>. Guard.ch does not create either setting during a normal visit.

6. sessionStorage we use

sessionStorage is scoped to a single browser tab and is cleared automatically when the tab closes. We use it for short-lived, first-party state that has to survive a redirect or reload. Most entries are read once and deleted immediately.

KeyPurposeLifetime
authRedirectThe page you were on before being sent to sign in, so you can be returned there afterwards.Removed when read after sign-in; at most until the tab closes.
authNoticeA one-time status message (for example a sign-in error) carried across an authentication redirect.Removed when displayed; at most until the tab closes.
azure_oauth_stateRandom anti-CSRF state for the Sign in with Microsoft flow, verified when Microsoft redirects back to us.Removed when the sign-in completes; at most until the tab closes.
sso_oauth_state_<provider>Random anti-CSRF state for enterprise single sign-on, verified when the identity provider redirects back to us.Removed when the sign-in completes; at most until the tab closes.
guard.pendingCheckoutThe plan you selected before being asked to sign in, so the checkout you requested can resume afterwards.Removed when the checkout resumes; at most until the tab closes.

7. What we do not use

On guard.ch we do not use advertising or marketing cookies, retargeting pixels, social media plugins, or any third-party advertising trackers. We do not fingerprint our own visitors to identify them across other sites, and we do not sell or share identifiers with ad networks or data brokers. Apart from the Cloudflare Turnstile challenge and Stripe.js on checkout and billing surfaces, no third-party code is loaded into the page.

Fonts and other static assets are bundled and served as part of the site itself; the page does not call third-party font or asset CDNs at runtime.

8. Do Not Track and Global Privacy Control

Guard.ch does not sell personal data and does not share personal data for cross-context behavioral advertising, and we set no advertising cookies, so a Do Not Track (DNT) or Global Privacy Control (GPC) signal has no advertising tracking to switch off. We honor verifiable access and deletion requests as described in the Privacy Policy. Our position on US state privacy laws is also set out there.

9. Clear or block cookies and browser data

You can clear or block browser storage for guard.ch at any time. Some features will then stop working: without the auth token you cannot stay signed in, and without certain viewer entries the live view may not reconnect after a reload.

  • Log out from the account menu. This removes the auth token from your browser and ends the server-side session.
  • Clear site data for guard.ch in your browser settings (commonly under Privacy, Site Settings, "Cookies and site data", or "Clear browsing data"). This removes all localStorage, sessionStorage, and cookie data for guard.ch, including anything set by Cloudflare or Stripe.
  • Close the tab to discard all sessionStorage entries.
  • Use private or incognito mode so nothing persists after the private window closes.
  • Block storage for guard.ch via your browser's per-site controls. The site will not function in that state.

10. Changes to this policy

We may update this Cookie Policy from time to time, for example when we add, rename, or remove a storage item or change how an existing one works. The "Last updated" date at the top of the page reflects the most recent revision. If a change would introduce storage that requires consent, we will implement a consent mechanism before the change takes effect, as described in section 3. Prior versions are available on request.

11. Contact

For questions about cookies and browser storage, contact us at:

Zesiger.net
legal@guard.ch

See also our Privacy Policy, the Data Processing Agreement, and the Legal notice, which carries the postal address and registry details.

Guard.ch

Guard.ch is operated by Zesiger.net in Schmiedrued, Switzerland. Account and workspace data is stored in the EU. Live findings are not saved as reports or recordings. Saved browser profiles remain available for later sessions.

Product

  • Overview
  • Pricing
  • Start an investigation

Integrations

  • Extensions
  • MCP
  • API and CDP
  • SSO

Company

  • About
  • Contact
  • Talk to sales

Trust

  • Security
  • DPA
  • Subprocessors
© 2026 Zesiger.net · UID CHE-488.503.816EnglishDeutsch
Legal noticePrivacyCookiesTermsWithdraw from a contract