Privacy & cookies
Last updated 2026-07-27
Controller
Crownpeak Technology, Inc., Attention: Privacy Department, 1700 Lincoln Street, 16th Floor, Suite 16-111, Denver, CO 80203, USA. For any privacy matter, contact DPM@rezolve.com. See also the full FirstSpirit privacy policy.
What we store, and why
When you use the “Ask the docs” chat we set one functional cookie, fsdocs_uid, and compute a short-lived server-side hash of your IP address, browser User-Agent, and Accept-Language header. Both exist solely to rate-limit the chat and prevent abuse of the upstream service. We do not use them to track you.
If you rate an answer helpful or unhelpful, we send that verdict, the id of the answer, and a key derived from your fsdocs_uid to the documentation search service. The key lets us count one verdict per reader instead of one overall; it carries nothing about you, and the question and answer text are not re-sent.
Separately, Cloudflare sets a strictly-necessary security cookie, __cf_bm, on every request to distinguish humans from bots and protect the site. It is set regardless of your choice above, contains no data we can read, and is not used to track you across sites.
Legal basis
Storing the fsdocs_uid cookie requires your consent (§25(1) TDDDG), which we ask for before anything is stored. The associated processing of the data relies on your consent under Art. 6(1)(a) GDPR. The IP/User-Agent hash is personal data under German law. The __cf_bm cookie set by Cloudflare is strictly necessary to deliver the service you request and is therefore exempt from consent under §25(2) no. 2 TDDDG; the underlying security processing rests on our legitimate interest under Art. 6(1)(f) GDPR.
Retention
The fsdocs_uid cookie expires after 30 days. The __cf_bm cookie expires after about 30 minutes (set by Cloudflare, not by us). The server-side fingerprint hash is kept only within a rolling 24-hour window and then discarded. Rate-limit counters live in memory and reset when the server restarts.
Recipients
We do not share your data for tracking or advertising. Cloudflare provides the site’s bot protection as our processor and handles request metadata (including the __cf_bm cookie) on our behalf to deliver and protect the site.
Your rights
You may request access to or erasure of your data, and you can withdraw your consent at any time — as easily as you gave it — via the “Cookie settings” link in the footer of any page; declining there deletes the cookie. To exercise any right, contact DPM@rezolve.com. You also have the right to lodge a complaint with a supervisory authority — for example the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), poststelle@ldi.nrw.de.