Cookie Policy

Version of 29 September 2026

1. What this policy covers

The ShieldWave service is run by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG). Below we call ourselves "ENSOMEDIA" or "we".

This policy describes what we store in your browser and read from it on the ShieldWave pages at shieldwave.io: the home page, the app, the blog, the free tools and the legal pages.

We describe three kinds of storage:

The WordPress plugin "Ensomedia Security powered by shieldwave.io" sets no cookies of its own. How we process personal data is described in the Privacy Policy.

Storing information on your device and reading it is governed by Article 399 of the Polish Electronic Communications Law of 12 July 2024. It requires your consent, unless the storage is necessary to transmit a communication or to provide a service you asked for. So necessary storage (section 3.1) and your settings (section 3.2) work without consent, while analytics (section 3.3) and marketing (section 3.4) work only after consent.

Where the storage involves personal data, the GDPR also applies. For necessary storage the legal basis is the contract or our legitimate interest in running and protecting the service (Article 6(1)(b) and (f) GDPR); for analytics and marketing it is your consent (Article 6(1)(a) GDPR).

3. What we store

The tables list everything our pages store in the browser. "Until cleared" means until you clear the site's data in your browser.

3.1 Necessary

NameSet byWhat forHow longKind
sw_sessionShieldWavekeeps you logged in; page scripts cannot read it (HttpOnly)24 hourscookie
_csrfShieldWaveprotects forms against forged requests; set on the first visit24 hourscookie
__cf_bmCloudflareprotects the service by telling people from automated traffic; Cloudflare sets it when it checks the trafficup to 30 minutescookie
cf_clearanceCloudflareremembers that the browser passed a Cloudflare security checkup to 1 year, as Cloudflare sets itcookie
shieldwave_cookie_consentShieldWaveremembers your choice in the consent window, with version and dateuntil you change it (section 6)localStorage
wp_scanner_auth_userShieldWavethe logged-in user name the app needsuntil you log outlocalStorage
sw_purchase_intentShieldWavethe plan and period you chose, so that sign-up leads on to paymentuntil the tab is closedsessionStorage
sw_purchase_seen_XXXXShieldWaveremembers that a purchase confirmation was already shown, so that it is not shown or counted twice (XXXX is the purchase identifier)until the tab is closedsessionStorage
shieldwave-v2ShieldWavecopies of the app's files (scripts, styles, images), so that it loads faster and works during a short loss of connection; no check results or account datauntil the app is updated or the cache is clearedapp cache

3.2 Settings

These entries are created when you change a setting or use a feature (such as report history), and serve only to remember it on your device.

NameSet byWhat forHow longKind
sw_langShieldWavelanguage of the site and appuntil clearedlocalStorage
data-theme, swl-themeShieldWavelight or dark look of the site and appuntil clearedlocalStorage
swl-globe-motionShieldWavewhether the animation on the home page movesuntil clearedlocalStorage
sw_report_theme, swr-themeShieldWavelook of the reportuntil clearedlocalStorage
sidebar_XXXX_openShieldWavewhich menu sections are expanded (XXXX is the section name)until clearedlocalStorage
wp_scanner_perpage, wp_scanner_timeoutShieldWaveresults per page and waiting time set in the appuntil clearedlocalStorage
sw_onboarding_completeShieldWavethat the app's guided tour was completeduntil clearedlocalStorage
sw_report_historyShieldWavelist of recent reports (up to 100: domain, format, time, check identifier)until clearedlocalStorage
shieldwave_trial_banner_dismissedShieldWavethat the trial banner was closeduntil the tab is closedsessionStorage

After you consent to analytics, we load Google Tag Manager and through it Google Analytics 4 (Google Ireland Limited). They help us see which pages and features are used.

NameSet byWhat forHow longKind
_gaGoogletells browsers apart to count visits and eventsup to 2 yearscookie
_ga_XXXXXXXXXXGooglekeeps the session state in Google Analytics (XXXXXXXXXX is our property's identifier)up to 2 yearscookie

Google explains how it uses data from sites that use its services at policies.google.com/technologies/partner-sites.

We use no marketing tags today, and nothing of this group is stored. Consent to marketing has one effect: it lets Google link the data of Google Analytics with its advertising features; without that consent Google does not. When we add a marketing tag, we will name it here and in the consent window and ask for consent again.

4. Stripe's pages and outside content

Payments take place on Stripe's pages, to which we redirect you. Stripe sets its own cookies there under its own rules; we load no Stripe scripts on our pages. We serve fonts from our own server. We embed no maps, videos or social media buttons. Our e-mails contain no tracking pixels.

5. How to accept, refuse and change your choice

On your first visit you see a consent window with three buttons: "Accept all", "Reject all" and "Customize". In "Customize" you choose analytics and marketing separately and save with "Save preferences". Analytics and marketing stay off until you choose them, and we load Google Tag Manager only after you consent to analytics. Refusing does not limit your use of ShieldWave.

You can change your choice at any time with "Cookie settings" in the site footer or in the app menu, which opens the consent window again. After you withdraw consent we stop loading the analytics tools and delete the Google Analytics cookies they set.

You can also block cookies or clear the site's data in your browser. Without the necessary cookies you cannot log in to the app.

6. How long we remember your choice

We store your choice only in your browser (shieldwave_cookie_consent), with the version of the consent window and the date. It applies until you change it. We ask again after 12 months or when the list of tools changes. If you clear the site's data in your browser, we ask on your next visit.

7. Changes to this policy

We change this policy when what we store in the browser changes, and publish each version with its date and an entry in the change history. When we add a tool that needs consent, we ask for consent again. Questions:

8. Change history