Skip to main content

Cookie policy

Cookie Policy

Every cookie ShieldMail sets, what each one does, which are strictly necessary, and how to refuse or remove the advertising cookies set by Google.

Last updated

This page lists what is stored in your browser by ShieldMail and by the third parties it loads, and how to control each category.

Strictly necessary

These cannot be declined, because without them the tool does not function. None of them identify you as a person.

NameTypePurposeLifetime
Session tokenHttpOnly cookieHolds the upstream provider's access token so the server can fetch your mail. Not readable by page scripts.Until the mailbox expires
shieldmail.currentSessionLocal storageRemembers the current address and expiry so a page reload returns you to the same inbox.Until expiry or cleared
shieldmail.lastDomainLocal storageRecords the last domain used, so pressing Change prefers a different one.Until cleared
shieldmail.consent.v1Local storageRemembers your choice on the consent banner so you are not asked repeatedly.Until cleared

Local storage is not technically a cookie, but it is data kept in your browser, so it is listed here rather than hidden behind a definition.

Advertising

ShieldMail is funded by Google AdSense. When advertising is active and you have not declined, Google and its partners may set cookies in your browser.

What they do: measure ad performance, limit how often the same ad is shown, and personalise ads based on your prior visits to this and other sites. This includes the DoubleClick advertising cookie, which Google uses across the sites it works with.

Consent Mode. ShieldMail implements Google Consent Mode v2. Before you choose, and if you decline, the following are set to denied:

  • ad_storage
  • ad_user_data
  • ad_personalization
  • analytics_storage

Choosing Accept sets them to granted. The site behaves identically either way — declining does not remove features, reduce functionality, or show you a nag screen.

Analytics

If analytics is enabled on this deployment, it is Google Analytics and it follows the same consent signal as advertising. No analytics identifier is joined to inbox activity at any point.

How to refuse or remove them

Four levels, from most specific to most complete:

  1. The consent banner on this site. Choose "Reject non-essential". Your choice is remembered in local storage.
  2. Google Ads Settings at adssettings.google.com turns off personalised advertising across all of Google's services.
  3. Industry opt-outs at optout.aboutads.info and youronlinechoices.eu cover participating vendors.
  4. Your browser. Blocking third-party cookies stops most advertising cookies being set at all. Clearing site data removes the strictly necessary items too, which means losing the current inbox.

Changing your mind

To revisit a consent choice, clear this site's data in your browser settings. The banner will appear again on your next visit. Note that clearing site data also clears the session, so save anything in your current inbox first.

What is never in a cookie

  • The contents of your messages
  • The addresses of people who wrote to you
  • Any personal information about you, because none is collected

FAQ

Can I use ShieldMail with all cookies blocked?

Partly. The tool needs its session cookie to fetch mail, so blocking cookies for this site entirely will prevent an inbox from working. Blocking *third-party* cookies is fine and affects only advertising.

Does declining ads mean I see no ads?

No. It means the ads you see are not personalised. Contextual advertising may still appear, which is what keeps the service free.

How long do Google's advertising cookies last?

That is set by Google and varies by cookie, typically from days to months. Google's own policies document the specifics, and they can change without a change here.

Why is local storage listed on a cookie policy?

Because it is data stored in your browser and you deserve a complete list rather than one narrowed by a technical definition.

Do you use tracking pixels in emails?

We send no email at all. In the opposite direction, remote images in messages you receive are blocked when rendering, so tracking pixels inside incoming mail do not fire.