Cookies

There are session and CSRF cookies. The site may load the Google AdSense script. Visible ads, if the operator enables them, only appear on tool pages.

ToolZen uses strictly necessary cookies for the site to work. With a Google AdSense Publisher ID, the site may load the adsbygoogle.js script on public pages so Google can review the site. That script does not show an ad by itself.

Session cookie (typical name laravel_session). Identifies the HTTP session for the form and the guest actor. First-party. It expires with the configured session (default 120 minutes of Laravel session inactivity, independent of file TTL).

XSRF-TOKEN cookie. CSRF protection for the upload form. First-party. Not used for ad tracking.

toolzen_ads_consent cookie. First-party, HttpOnly, SameSite=Lax. Only written if you press “Accept ads”. It remembers that consent. It does not identify your file.

Visible ad slots only appear on tool pages if the operator enables them. Until then there are no units on screen. If you accept and units exist, Google may set cookies on its own domain. The file you upload is not sent to the ads network. There are no Auto Ads.

There is no first-party analytics. This page describes the configured behaviour; it is not legal advice.

Questions about cookies or privacy: [email protected].