> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.vessl.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cookie list

> Individual cookies and similar technologies used across VESSL websites and VESSL Cloud.

<Info>
  Effective date: August 6, 2026 · Last updated: August 6, 2026
</Info>

This page identifies the individual cookies and similar technologies used on the VESSL websites and the VESSL Cloud service. It is the Cookie List referred to in our [Cookie Policy](/legal/cookie), which defines the categories used below. Providers that process personal data on VESSL's behalf are listed in the [Sub-processor list](/legal/sub-processors).

**Scope.** `vessl.ai` (including `vessl.ai/blog`), `cloud.vessl.ai`, and `docs.cloud.vessl.ai`.

**Consent.** Only the strictly necessary technologies are used without your consent. Everything in the Functional, Performance, and Targeting categories is set only after you accept that category in our cookie banner or cookie settings, and stops being written when you withdraw that consent. See Section 8.

**Sharing across sites.** Most cookies below are set on the parent domain `.vessl.ai`, so the same cookie is readable on all three sites and a single consent choice applies to all of them. Cookies whose host is shown without a leading dot are scoped to that one site.

## 1. Strictly necessary

| Cookie                 | Set by              | Host              | Purpose                                                                                                                                                                      | Duration   |
| ---------------------- | ------------------- | ----------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| `vessl_cookie_consent` | VESSL (first party) | `.vessl.ai`       | Stores your cookie choices — which categories you accepted, when, and the version of the notice you saw — so that we can honour them and not ask again on every page or site | 6 months   |
| `cloud_access_token`   | VESSL (first party) | `.vessl.ai`       | Authenticated access token for VESSL Cloud                                                                                                                                   | 24 hours   |
| `cloud_refresh_token`  | VESSL (first party) | `.vessl.ai`       | Re-issues the access token so your session continues                                                                                                                         | 7 days     |
| `g_state`              | Google              | `cloud.vessl.ai`  | Records that you dismissed the Google sign-in prompt, so it is not shown again for a period. Set by Google Identity Services, which VESSL uses for Google sign-in            | 180 days   |
| `__stripe_mid`         | Stripe              | `.cloud.vessl.ai` | Fraud prevention: identifies the device across payment attempts. Set when a payment form loads in VESSL Cloud                                                                | 1 year     |
| `__stripe_sid`         | Stripe              | `.cloud.vessl.ai` | Fraud prevention: identifies the current payment session while a payment form is open                                                                                        | 30 minutes |

Signing in with Google also causes Google to set its own account and security cookies on `accounts.google.com` and other Google domains. Those cookies are set by Google as an independent controller of your Google account, not by VESSL, and are governed by the [Google Privacy Policy](https://policies.google.com/privacy).

The in-app support chat (Pylon) is also treated as strictly necessary: it is a support channel you have asked us to provide when signed in. It sets no cookie; its browser-storage keys are listed in Section 6.

## 2. Functional

| Cookie               | Set by              | Host             | Purpose                                                                        | Duration |
| -------------------- | ------------------- | ---------------- | ------------------------------------------------------------------------------ | -------- |
| `cloud_last_org_v1`  | VESSL (first party) | `cloud.vessl.ai` | Remembers the organization you last used, so you land in it on your next visit | 1 year   |
| `cloud_last_team_v1` | VESSL (first party) | `cloud.vessl.ai` | Remembers the team you last used within an organization                        | 1 year   |

## 3. Performance

| Cookie           | Set by           | Host        | Purpose                                                                         | Duration       |
| ---------------- | ---------------- | ----------- | ------------------------------------------------------------------------------- | -------------- |
| `_ga`            | Google Analytics | `.vessl.ai` | Distinguishes unique visitors across all three sites                            | Up to 400 days |
| `_ga_8LSM3LEDEX` | Google Analytics | `.vessl.ai` | Holds analytics session state for `vessl.ai` and `cloud.vessl.ai`               | Up to 400 days |
| `_ga_N7NDLW2PZK` | Google Analytics | `.vessl.ai` | Holds analytics session state for `docs.cloud.vessl.ai`                         | Up to 400 days |
| `AMP_be333f40b6` | Amplitude        | `.vessl.ai` | Product-usage analytics device and session identifier for `vessl.ai`            | 1 year         |
| `AMP_19a4a4040f` | Amplitude        | `.vessl.ai` | Product-usage analytics device and session identifier for `cloud.vessl.ai`      | 1 year         |
| `AMP_8ae1e9c618` | Amplitude        | `.vessl.ai` | Product-usage analytics device and session identifier for `docs.cloud.vessl.ai` | 1 year         |

## 4. Targeting

| Cookie                | Set by              | Host             | Purpose                                                                                                             | Duration   |
| --------------------- | ------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------- | ---------- |
| `__hstc`              | HubSpot             | `.vessl.ai`      | Main HubSpot visitor-tracking cookie: domain, first visit, last visit, and session count                            | 6 months   |
| `hubspotutk`          | HubSpot             | `.vessl.ai`      | Visitor identifier that links form submissions to a HubSpot contact                                                 | 6 months   |
| `__hssc`              | HubSpot             | `.vessl.ai`      | Tracks the current session and page views within it                                                                 | 30 minutes |
| `__hssrc`             | HubSpot             | `.vessl.ai`      | Detects whether the browser was restarted, to decide whether to start a new session                                 | Session    |
| `_gcl_au`             | Google Ads          | `.vessl.ai`      | Conversion linker: attributes ad clicks to conversions                                                              | 90 days    |
| `_gcl_aw`             | Google Ads          | `.vessl.ai`      | Stores the Google Ads click identifier when you arrive from a Google ad, so a later sign-up can be attributed to it | 90 days    |
| `_gcl_gs`             | Google Ads          | `.vessl.ai`      | Stores the Google Ads click session identifier that accompanies `_gcl_aw`                                           | 90 days    |
| `AMP_MKTG_19a4a4040f` | Amplitude           | `.vessl.ai`      | Stores the campaign or referrer that brought you to `cloud.vessl.ai`, for attribution                               | 1 year     |
| `AMP_MKTG_8ae1e9c618` | Amplitude           | `.vessl.ai`      | Stores the campaign or referrer that brought you to `docs.cloud.vessl.ai`, for attribution                          | 1 year     |
| `vessl-utm-params`    | VESSL (first party) | `cloud.vessl.ai` | Campaign parameters captured from the URL, held until sign-up so the sign-up can be attributed, then deleted        | 30 days    |
| `vessl-ref`           | VESSL (first party) | `cloud.vessl.ai` | Carries the referral parameter into the browser; moved to session storage for the current tab and then deleted      | Session    |

## 5. Cookies set on providers' own domains

The technologies below run on VESSL sites but write their cookies to the provider's own domain, so they are not visible under `vessl.ai`. They follow the same consent categories as the sections above.

| Cookie                 | Set by               | Host                                                                                                                      | Category           | Purpose                                                                                                                             | Duration   |
| ---------------------- | -------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------ | ----------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| `ajs_anonymous_id`     | Arcade               | `demo.arcade.software`                                                                                                    | Performance        | Anonymous visitor identifier for the interactive product demos embedded in the documentation                                        | 1 year     |
| `bcookie`              | LinkedIn             | `.linkedin.com`                                                                                                           | Targeting          | Browser identifier used by the LinkedIn Insight Tag                                                                                 | 1 year     |
| `bscookie`             | LinkedIn             | `.www.linkedin.com`                                                                                                       | Targeting          | Secure browser identifier used for authenticated LinkedIn actions                                                                   | 1 year     |
| `lidc`                 | LinkedIn             | `.linkedin.com`                                                                                                           | Targeting          | Routes requests to the right LinkedIn data centre                                                                                   | 24 hours   |
| `li_sugr`              | LinkedIn             | `.linkedin.com`                                                                                                           | Targeting          | Probabilistic browser identifier used for audience matching                                                                         | 90 days    |
| `UserMatchHistory`     | LinkedIn             | `.linkedin.com`                                                                                                           | Targeting          | Synchronizes the LinkedIn Ads identifier                                                                                            | 30 days    |
| `AnalyticsSyncHistory` | LinkedIn             | `.linkedin.com`                                                                                                           | Targeting          | Records when the visitor was synchronized with LinkedIn's analytics service                                                         | 30 days    |
| `GCL_AW_P`             | Google Ads           | `.doubleclick.net`, `.google.com`, `.googleadservices.com`                                                                | Targeting          | Stores the ad click identifier on Google's own domains when you arrive from a Google ad, so a later conversion can be matched to it | 90 days    |
| `test_cookie`          | Google (DoubleClick) | `.doubleclick.net`                                                                                                        | Targeting          | Checks whether the browser accepts cookies before ad tags are served                                                                | 15 minutes |
| `__cf_bm`              | HubSpot, LinkedIn    | `.hubspot.com`, `.hs-scripts.com`, `.hs-analytics.net`, `.hs-banner.com`, `.hsforms.com`, `.hsforms.net`, `.linkedin.com` | Strictly necessary | Bot management for those providers' own script and form endpoints. Set by Cloudflare on their behalf, not by VESSL — see Section 7  | 30 minutes |

## 6. Local and session storage

The Cookie Policy also covers browser storage. The keys below are written to `localStorage` or `sessionStorage`; they are not transmitted with HTTP requests and are removed when you clear site data. They follow the same consent categories as the cookies above. The first-party interface-state keys below are implementation details and their names may change between releases.

| Key                                                   | Storage                          | Set by     | Category           | Purpose                                                                                                                         |
| ----------------------------------------------------- | -------------------------------- | ---------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------- |
| `vessl:*`, `signout-time`                             | `localStorage`                   | VESSL      | Strictly necessary | Interface state such as dismissed banners and the last page you were on, and notifying other open tabs that you have signed out |
| `pylon-preferred-locale`, `pylon-theme`               | `localStorage`                   | Pylon      | Strictly necessary | Language and appearance preference for the in-app support chat                                                                  |
| `pusherTransportTLS`                                  | `localStorage`                   | Pylon      | Strictly necessary | Remembers which real-time connection method worked, so the support chat reconnects faster                                       |
| `mintlify_anonymous_id`, `mintlify_session_id`        | `localStorage`, `sessionStorage` | Mintlify   | Performance        | Documentation-site visitor and session identifiers                                                                              |
| `AMP_unsent_*`, `AMP_remote_config_*`, `AMP_URL_INFO` | `localStorage`, `sessionStorage` | Amplitude  | Performance        | Queue of analytics events not yet sent, SDK configuration, and landing-page URL                                                 |
| `_gcl_ls`                                             | `localStorage`                   | Google Ads | Targeting          | Conversion-linker data, used where cookies are unavailable                                                                      |
| `li_adsId`                                            | `localStorage`                   | LinkedIn   | Targeting          | Advertising identifier used by the LinkedIn Insight Tag                                                                         |
| `vessl-ref`                                           | `sessionStorage`                 | VESSL      | Targeting          | Referral parameter for the current tab, moved here from the `vessl-ref` cookie                                                  |

## 7. Notes on providers

**Cloudflare. No Cloudflare cookie is set on any `vessl.ai` domain. The `__cf_bm` cookies in Section 5 are set on HubSpot's and LinkedIn's own domains by those providers' bot protection. Our hosting providers serve some of our sites through Cloudflare’s network, which sets no cookie on our domains.**

**Pylon.** The in-app support chat loads only for signed-in users of VESSL Cloud. It sets no cookie; it writes the browser-storage keys listed in Section 6 and holds the chat conversation inside its own widget on `widget.usepylon.com`.

**Arcade.** Some documentation pages embed an interactive product demo provided by Arcade. The demo runs from `demo.arcade.software` and sets its own anonymous visitor identifier there; it loads only on the pages that contain a demo.

**Stripe.** The two `__stripe_*` cookies in Section 1 are set on `cloud.vessl.ai` by Stripe's payment library when a payment form loads, and are used for fraud prevention. Where a payment is completed on Stripe's own hosted checkout pages, any further cookies are set by Stripe on Stripe's domains and are governed by the [Stripe Privacy Policy](https://stripe.com/privacy).

### 7.1 Provider cookie documentation

Each provider publishes its own description of the cookies it sets, and some offer their own opt-out. Those pages are maintained by the provider, not by VESSL.

| Provider                             | Documentation                                                                                                                                                                                                   |
| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Google (Analytics, Ads, DoubleClick) | [Advertising cookies](https://business.safety.google/adscookies/) · [How Google uses cookies](https://policies.google.com/technologies/cookies) · [Analytics opt-out](https://tools.google.com/dlpage/gaoptout) |
| HubSpot                              | [Cookies HubSpot sets in a visitor's browser](https://knowledge.hubspot.com/privacy-and-consent/what-cookies-does-hubspot-set-in-a-visitor-s-browser)                                                           |
| LinkedIn                             | [LinkedIn cookie table](https://www.linkedin.com/legal/l/cookie-table)                                                                                                                                          |
| Amplitude                            | [Privacy](https://amplitude.com/privacy)                                                                                                                                                                        |
| Arcade                               | [Privacy](https://www.arcade.software/privacy)                                                                                                                                                                  |
| Stripe                               | [Cookie policy](https://stripe.com/cookies-policy/legal)                                                                                                                                                        |
| Pylon                                | [Privacy](https://www.usepylon.com/privacy)                                                                                                                                                                     |
| Mintlify                             | [Privacy](https://www.mintlify.com/legal/privacy)                                                                                                                                                               |
| Cloudflare                           | [Cloudflare cookies](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/)                                                                                         |

## 8. Managing your choices

* **Cookie banner.** On your first visit you can choose **Accept all**, **Essential only**, or **Settings**. Nothing outside Section 1 is set until you choose.
* **Cookie settings.** The **Settings** view lets you accept or reject Functional, Performance, and Targeting individually. Strictly necessary technologies cannot be switched off.
* **Manage cookies.** You can reopen the settings at any time from the **Manage cookies** link on each site, and withdraw a consent you gave earlier. When you withdraw consent we stop setting cookies in that category and delete the ones we can reach from the browser.
* **Re-asking.** Your choices are remembered for 6 months, after which we ask again. We also ask again if we materially change the categories or this notice.
* **Global Privacy Control.** If your browser sends a recognized GPC signal, we treat it as an opt-out and leave the optional categories off unless you turn them on yourself.
* **Browser settings and provider opt-outs.** See [Cookie Policy, Section 4](/legal/cookie#4-managing-your-cookies).

## 9. Change log

| Date       | Change               |
| ---------- | -------------------- |
| 2026-08-06 | Initial publication. |

***

Questions about this list: **[privacy@vessl.ai](mailto:privacy@vessl.ai)**.
