Skip to content
AbuseScore
  • How it works
  • Pricing
  • Developers
  • Sign in
  • Get an API key
Home Legal Cookie Policy

Cookie Policy

Three cookies, all of them necessary, none of them tracking you. Plus one third-party request we would rather be honest about.

Last updated 2026-09-14

Why there is no cookie banner

Consent is required for cookies that are not strictly necessary, such as advertising, analytics and profiling. We do not set any. Everything below is required to sign you in and to stop your forms being forged, which is the exemption that applies. So there is no banner, because there is nothing to ask you about.

What we set

Cookie Purpose Lifetime
APPSESSID Keeps you signed in across pages and carries the token that protects forms against cross-site forgery. Session, up to 24 hours
JWT “Remember me”. Set only if you tick the box at sign-in. A signed token, not your password. 7 days
Captcha cookies Set by the captcha on the sign-up and password reset forms, to tell a person from a script. Set by the captcha provider, not by us. Short-lived

All of ours are HttpOnly (JavaScript cannot read them), Secure (HTTPS only) and SameSite=Lax.

What we do not set

  • No advertising or retargeting cookies. We do not advertise.
  • No analytics cookies. No Google Analytics, no product analytics, no session recording.
  • No social media pixels or share-button trackers.
  • No cross-site profiling of any kind.

Third-party requests

Cookies are not the only way a browser talks to someone else. On most sites the fonts, the icons and the analytics all come from somewhere else, and every one of them hands your IP address to a company you never chose to deal with. On this site there are two, and neither of them happens while you are just reading.

  • Cloudflare Turnstile, on the sign-in, registration and password-reset forms only. It is what stops those forms being hammered by scripts, and it works out whether you are a person without asking you to identify traffic lights. Cloudflare receives your IP address and some information about your browser in order to do it, and it sets a cookie of its own (cf_clearance) in some cases. Cloudflare states that Turnstile data is not used for advertising or for cross-site tracking. No other page on this site loads it.
  • Payment pages. Paying takes you to Stripe or CryptoPayr, who set their own cookies under their own policies. We never handle your card details.

Everything else loads from abusescore.com, fonts included. Reading the front page, the pricing or any of these documents sends your IP address to us and to nobody else.

Turnstile needs JavaScript. If you block it, the three form pages cannot verify you and you will not be able to sign in or create an account. Write to [email protected] and we will sort it out by hand.

The fingerprinting script, on other people's websites

This part is not about abusescore.com. We sell a script that our customers put on their own websites so they can recognise a returning browser and spot fraud. It is described here because people look for it in a cookie policy, and because what it does falls under the same rules as a cookie even when it does not use one.

On a customer's site it stores one value in that site's own storage, an identifier that means nothing anywhere else, and falls back to a cookie of the same name where storage is unavailable. Nothing is stored on a visitor's machine by abusescore.com, and the script is not on any page of this website.

If you are a customer, this is your obligation, not ours. Storing anything on a visitor's device, or reading characteristics of their browser to recognise them, needs consent in the EU and the UK, and it needs it whether or not a cookie is involved. You are the controller for your own visitors. Get consent where your own advice says you need it, before the script runs, and say what you are doing in your own privacy notice. You are welcome to link to ours.

What we do on our side: the identifier is unique to that one customer, so the same browser on two different customers' sites is two unrelated identifiers with nothing joining them. The measurements are converted into a fingerprint in the browser and the raw values are never sent to us. Records are deleted 180 days after the last visit. The Privacy Policy has the detail.

Turning them off

Every browser lets you block or delete cookies. Blocking ours means you cannot sign in, because the session cookie is how the site knows who you are. The public pages, including all of these legal documents, work fine without any cookies at all.

More

What we do with personal data generally is in the Privacy Policy. Who processes data for us is in Subprocessors.

IP intelligence and abuse scoring.
Evidence, not guesses.

Product

  • How it works
  • Pricing
  • Developers
  • Create an account

Legal

  • Terms of Service
  • Privacy Policy
  • Refunds & Cancellation
  • All legal documents

Contact

  • [email protected]
  • Legal notice
  • Attribution
  • Report abuse

© 2026 AESHA Technology Services Limited. All rights reserved.

AESHA Technology Services Limited · Company No. 210193 · 1032 Office House of Francis Ilu de Port, Mahe, Seychelles

Appearance