Cookie policy
Cookie Policy
Every cookie ShieldMail sets, what each one does, which are strictly necessary, and how to refuse or remove the advertising cookies set by Google.
Last updated
This page lists what is stored in your browser by ShieldMail and by the third parties it loads, and how to control each category.
Strictly necessary
These cannot be declined, because without them the tool does not function. None of them identify you as a person.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| Session token | HttpOnly cookie | Holds the upstream provider's access token so the server can fetch your mail. Not readable by page scripts. | Until the mailbox expires |
shieldmail.currentSession | Local storage | Remembers the current address and expiry so a page reload returns you to the same inbox. | Until expiry or cleared |
shieldmail.lastDomain | Local storage | Records the last domain used, so pressing Change prefers a different one. | Until cleared |
shieldmail.consent.v1 | Local storage | Remembers your choice on the consent banner so you are not asked repeatedly. | Until cleared |
Local storage is not technically a cookie, but it is data kept in your browser, so it is listed here rather than hidden behind a definition.
Advertising
ShieldMail is funded by Google AdSense. When advertising is active and you have not declined, Google and its partners may set cookies in your browser.
What they do: measure ad performance, limit how often the same ad is shown, and personalise ads based on your prior visits to this and other sites. This includes the DoubleClick advertising cookie, which Google uses across the sites it works with.
Consent Mode. ShieldMail implements Google Consent Mode v2. Before you choose, and if you decline, the following are set to denied:
ad_storagead_user_dataad_personalizationanalytics_storage
Choosing Accept sets them to granted. The site behaves identically either way — declining does not remove features, reduce functionality, or show you a nag screen.
Analytics
If analytics is enabled on this deployment, it is Google Analytics and it follows the same consent signal as advertising. No analytics identifier is joined to inbox activity at any point.
How to refuse or remove them
Four levels, from most specific to most complete:
- The consent banner on this site. Choose "Reject non-essential". Your choice is remembered in local storage.
- Google Ads Settings at
adssettings.google.comturns off personalised advertising across all of Google's services. - Industry opt-outs at
optout.aboutads.infoandyouronlinechoices.eucover participating vendors. - Your browser. Blocking third-party cookies stops most advertising cookies being set at all. Clearing site data removes the strictly necessary items too, which means losing the current inbox.
Changing your mind
To revisit a consent choice, clear this site's data in your browser settings. The banner will appear again on your next visit. Note that clearing site data also clears the session, so save anything in your current inbox first.
What is never in a cookie
- The contents of your messages
- The addresses of people who wrote to you
- Any personal information about you, because none is collected
FAQ
Can I use ShieldMail with all cookies blocked?
Partly. The tool needs its session cookie to fetch mail, so blocking cookies for this site entirely will prevent an inbox from working. Blocking *third-party* cookies is fine and affects only advertising.
Does declining ads mean I see no ads?
No. It means the ads you see are not personalised. Contextual advertising may still appear, which is what keeps the service free.
How long do Google's advertising cookies last?
That is set by Google and varies by cookie, typically from days to months. Google's own policies document the specifics, and they can change without a change here.
Why is local storage listed on a cookie policy?
Because it is data stored in your browser and you deserve a complete list rather than one narrowed by a technical definition.
Do you use tracking pixels in emails?
We send no email at all. In the opposite direction, remote images in messages you receive are blocked when rendering, so tracking pixels inside incoming mail do not fire.