Cookie Policy
Last updated: August 26, 2026
BETA PERIOD NOTICE — THIS SECTION OVERRIDES THE POLICY BELOW.
SLDocs is currently in beta. During the beta period only, and only with the consent you provided at signup, we use PostHog — a product analytics and session-replay tool — to understand how the product is used, to diagnose errors, and to improve the service before general release. PostHog is not strictly necessary to operate SLDocs, which is why we ask for your consent rather than relying on the strictly-necessary exemption described below.
While the beta is running, the statements below that SLDocs uses no analytics cookies and embeds no session-replay tools do not apply.
With your consent, PostHog records navigation and interaction during the beta on screens we specifically permit, including clicks, scrolling, page transitions, and ordinary interface selections. A new or unrecognized screen is not recorded unless we expressly add it. Medical and emergency-medical screens are never recorded. On recorded screens, everything you type and text derived from you or stored data are masked, except that a value identical to fixed interface text may appear as that interface text. Fixed interface text may remain readable. Sensitive controls and statuses are blocked.
PostHog acts solely as our service provider and may not use this data for its own purposes. We do not sell it and we do not share it for advertising.
PostHog stores its identifier in the cookie listed in the table below. It also writes one entry to your browser’s local storage that holds only your opt-in/opt-out preference for this analytics — no identifier, no browsing history, and no analytics content. Both are written only after you have opted in, and the local-storage entry exists solely to record and honor your choice (for example, so that we keep honoring an opt-out).
This is temporary. At the end of the beta period we will remove the analytics and session-replay tooling from the product, delete the analytics and session-replay data collected during the beta, and return to the strictly-necessary-cookies-only posture described in the rest of this page. We are giving you notice of that change now; we will not send a separate notice when it takes effect.
You may withdraw your consent at any time by emailing legal@sldocs.com. Withdrawal does not affect your account, your beta participation, or any promotional pricing you received as a beta participant — we will simply disable analytics and session-replay collection for your account and delete the data already collected from it.
SLDocs uses a small number of cookies that are strictly necessary to operate the service — for example, to keep you signed in, to protect against cross-site request forgery, and to route requests to the correct tenant on our white-label domains.
Outside our limited beta, we do not use cookies for analytics, advertising, profiling, or any other non-essential purpose. Apart from the beta product analytics and session-replay tool described in the beta notice above — which runs only for testers who consented at signup — we do not embed third-party tracking pixels, session-replay tools, or marketing SDKs. No cookie consent banner is shown and none is required: the one non-strictly-necessary cookie we set — the beta product analytics cookie described above — is written only after you give specific opt-in consent at signup; the beta analytics also writes a single local-storage entry, but its only content is the record of your opt-in/out choice (kept so we can honor it), and it too is written only after you consent; every other cookie we set is strictly necessary to operate the service.
Cookies we set
Every cookie listed below is strictly necessary to operate the service, except as noted in the beta notice above.
| Cookie | Purpose | Duration |
|---|---|---|
| next-auth.session-token (or __Secure-next-auth.session-token in production) | Keeps you signed in to your SLDocs account. | 30 minutes |
| next-auth.csrf-token (or __Host-next-auth.csrf-token in production) | Protects against cross-site request forgery during sign-in. | Session |
| next-auth.callback-url (or __Secure-next-auth.callback-url in production) | Returns you to the page you came from after signing in. | Session |
| trusted_device | Remembers a device you chose to trust so you can skip the second sign-in (two-factor) step on that device. | 7 days |
| pending_2fa | Temporarily carries your sign-in between the password step and the verification-code step. | ~11 minutes |
| branding_tenant_id | On white-label domains, remembers which law firm tenant your request belongs to so the correct branding is shown. | 5 minutes |
| av_challenge | Holds a one-time access code while you verify as a designated recipient before viewing a vault. | 10 minutes |
| av_verified | Confirms you completed recipient verification so you can view the documents shared with you. | 60 minutes |
| med_challenge | Holds verification state for two one-time codes — one sent by email and one by text — during emergency medical (break-glass) access verification. | 10 minutes |
| site_access | During our pre-launch period, records that you submitted a valid site access code so you don't have to re-enter it on every page. Only set after you submit the code. | 7 days |
| ph_phc_scR42DRERdjfxsJugKnKK8GQXLs6vi7L3JuiVMmnEL3H_posthog | Beta only. Identifies your browser to our product analytics and session-replay tool so usage events can be grouped into a session. Set only if you consented at signup. | 1 year |
Third-party services
SLDocs relies on a number of third-party service providers to deliver the service. Apart from the beta product analytics tool described above, none of these providers set tracking cookies on your browser through SLDocs. If you make a payment, our payment processor may set its own cookies on its own domain during checkout — see that processor's cookie policy for details. The full list of service providers we use and what data each one processes is published on our Subprocessors page.
Controlling cookies
During the beta period, one cookie we set is not strictly necessary: the product analytics cookie described in the beta notice above, which is set only if you consented at signup. You can block or delete it in your browser without affecting your account or your access to your documents, though some site functionality may behave unexpectedly if you block cookies generally. You can also withdraw your consent at any time by emailing legal@sldocs.com, which stops the collection and deletes the data already gathered from your account. Every other cookie we set is strictly necessary to operate the service.
You can delete cookies at any time via your browser's settings (Chrome: Settings → Privacy and security → Cookies; Safari: Preferences → Privacy; Firefox: Settings → Privacy & Security).
Changes
If we add cookies that are not strictly necessary, we will update this page and obtain your consent before setting them. We have done this for the beta analytics cookie described above, which is set only after you consent at signup.
Contact
Questions about this policy? Email legal@sldocs.com.
Please don't email sensitive personal or health information or documents — email isn't a secure channel and messages are stored unencrypted at rest. Use your in-product vault instead.