Cookie & Consent Policy
This Cookie & Consent Policy explains which cookies and comparable technologies LILY Labs GmbH (“LILY”, “We”) uses, what they are used for, on what legal basis they are set, and how you can withdraw a consent you have given. It supplements our Privacy Policy, which describes the subsequent processing of personal data obtained through these technologies.
1 WHAT COOKIES AND COMPARABLE TECHNOLOGIES ARE
A cookie is a small text file that a website asks your browser to store on your terminal equipment and that is sent back to the setting party on later requests. Beyond cookies, information can also be stored in or read from your terminal equipment through comparable techniques, in particular localStorage and sessionStorage (browser storage that persists across or within a browsing session), and through identifiers embedded in requests.
In this policy, all of these are referred to together as “Cookies”. A first-party Cookie is set under the domain you are visiting; a third-party Cookie is set under the domain of another party.
2 SCOPE
This policy covers the following LILY properties:
- lilylabs.io — the public website
- auth.lilylabs.io — sign-in and account registration
- the web-based LILY Platform (dashboard)
3 COOKIES WE USE
3.1 lilylabs.io — the public website
The public website sets no Cookies at all. It writes nothing to your terminal equipment and reads nothing from it: no cookies, no localStorage, no sessionStorage. It loads no third-party scripts, no third-party fonts, no analytics tags and no advertising or tracking pixels. Web fonts are not fetched from a third party; the site uses fonts already present on your device.
3.2 Content delivery and security (Cloudflare)
Requests to our domains are routed through Cloudflare, which provides DNS, reverse proxy, web application firewall and TLS termination. Cloudflare may set Cookies that are technically required to deliver the site securely, in particular to distinguish automated traffic from human visitors.
As verified against the production domains in August 2026, Cloudflare currently sets no Cookies on lilylabs.io, auth.lilylabs.io or status.lilylabs.io. In particular, no bot-management Cookie is in use.
One exception can occur: if Cloudflare presents a security challenge because a request looks abusive, it sets a short-lived Cookie recording that the challenge was passed (cf_clearance). It is set only in that case, is strictly necessary to deliver the site to you at all, and expires automatically.
3.3 auth.lilylabs.io and the Platform
As verified in August 2026, simply opening the sign-in page at auth.lilylabs.io sets no Cookies. Cookies are set from the point at which you actually sign in, and by the Platform once you are signed in — never by visiting the public website.
The following Cookies occur in that context, by purpose, setting party and category. Individual Cookie names and lifetimes are available on request from privacy@lilylabs.io.
| Purpose | Set by | Category |
|---|---|---|
| Session and authentication state (keeping you signed in, protecting against cross-site request forgery) | LILY | Strictly necessary |
| Sign-in with Google | Google Ireland Limited | Strictly necessary (only when you choose this sign-in method) |
| Sign-in with GitHub; repository integration | GitHub, Inc. | Strictly necessary (only when you choose this sign-in method) |
| Payment processing and fraud prevention during checkout | Stripe Payments Europe, Ltd. / Stripe, Inc. | Strictly necessary |
| Product analytics on the Platform (which features are used, where errors occur), feature-flag assignment | PostHog Inc. | Analytics — consent required |
| Newsletter and waitlist opt-in | MailerLite | Functional — consent required |
3.4 Advertising and marketing Cookies
We currently use no advertising, remarketing or conversion-measurement Cookies. No advertising tag, tracking pixel or conversion pixel of any ad platform is embedded in our properties. Should this change, this policy and the consent options will be updated before any such Cookie is set.
4 CATEGORIES AND LEGAL BASES
Storing information in, and accessing information already stored in, your terminal equipment is governed by § 25 of the German Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG). Any subsequent processing of personal data obtained in that way is governed by the GDPR.
| Category | What it covers | Legal basis for setting | Legal basis for subsequent processing |
|---|---|---|---|
| Strictly necessary | Cookies without which a service you expressly requested cannot be provided: session and authentication state, security and abuse prevention, load distribution, payment execution. | § 25(2) no. 2 TDDDG — no consent required | Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation) |
| Functional | Cookies that enable convenience features going beyond what is strictly necessary, e.g. remembering a newsletter opt-in state. | § 25(1) TDDDG — consent required | Art. 6(1)(a) GDPR — consent |
| Analytics | Cookies used to understand how the Platform is used, which features are used and where errors or friction occur, including feature-flag assignment for A/B tests. | § 25(1) TDDDG — consent required | Art. 6(1)(a) GDPR — consent |
| Marketing | Cookies used for advertising, remarketing and conversion measurement. Currently not used (section 3.4). | § 25(1) TDDDG — consent required | Art. 6(1)(a) GDPR — consent |
Cookies in the strictly necessary category are set without consent. Cookies in every other category are set only after you have given consent, and are not set if you decline.
5 CONSENT AND HOW TO WITHDRAW IT
Where consent is required, it is obtained before the Cookie concerned is set, and can be changed or withdrawn at any time with effect for the future. Withdrawing consent does not affect the lawfulness of processing carried out up to that point.
As verified in August 2026, no consent banner is currently displayed on any of the properties covered by this policy, and none is required for the public website: it sets no Cookies at all, so there is nothing to consent to. Where Cookies requiring consent are introduced — in particular product analytics on the Platform — consent is collected through a consent banner before they are set, and this policy is updated at the same time.
Independently of any banner, you can withdraw a newsletter consent at any time via the unsubscribe link in every newsletter, or by writing to privacy@lilylabs.io.
6 BROWSER SETTINGS
You can also control Cookies through your browser, independently of any consent given to us. Common browsers allow you to view and delete stored Cookies, to refuse Cookies generally or per site, and to have Cookies deleted automatically when the browser is closed. The relevant settings are usually found under “Privacy” or “Cookies and site data”.
Please note that blocking strictly necessary Cookies will prevent you from signing in and from using the Platform, because the sign-in state can then no longer be maintained.
7 CHANGES TO THIS POLICY
We update this policy when the Cookies we use, their purposes or the applicable legal requirements change. The current version is always available at lilylabs.io/legal/cookies.
Questions about this policy: privacy@lilylabs.io.
Last change: August 2026
Step into the world after the cloud.
Start for free, integrate in minutes, and scale when you need to.
What is coming after the cloud
LILY Labs GmbH, Maudacherstraße 45, 67065 Ludwigshafen am Rhein
Amtsgericht Ludwigshafen am Rhein, HRB 70791
© 2026 LILY Labs GmbH. All rights reserved.