Cookies
Last updated: 3 October 2026
legalnomos.com stores in the browser only what the language, the request form and cabinet sign-in need. Google Analytics and Google Ads turn on only after Accept all. Advertising cookies are not necessary: the site, the form and the cabinet work without them.
1. How to accept, reject and withdraw
The banner at the bottom has two buttons: Accept all and Necessary only. The code has no separate “analytics only” choice. The choice is stored in localStorage under nomos-cookie-choice. The code sets no expiry: it stays until you change it or clear site data.
Before a choice, the tag uses Consent Mode v2. ad_storage, ad_user_data, ad_personalization and analytics_storage are denied. functionality_storage and security_storage are granted, because language and the sign-in session depend on them.
You can change the choice with the buttons below. Necessary only sets analytics and advertising back to denied. Cookies the browser already stored stay until they expire, unless you delete them in the browser.
2. Necessary
These are not analytics and not advertising. The site scripts do not call document.cookie. This is what the code actually writes.
- nomos-cookie-choice — localStorage, Legal Nomos. Your choice. No expiry in the code.
- legalnomos_lang and legalnomos_cabinet_lang — localStorage, Legal Nomos. Site and cabinet language. No expiry in the code.
- legalnomos_pending_case — sessionStorage, Legal Nomos. Carries the form request into the cabinet. Ends with the tab.
- legalnomos_last_error — sessionStorage, Legal Nomos. The last cabinet technical error. Ends with the tab.
- nomos_inq_ts — localStorage, Legal Nomos. Time of the last request, so the form is not sent twice in a row (the pause in code is 45 seconds).
- Firebase session — Google Firebase Authentication. The code uses local persistence, not a named cookie. It keeps you signed in until you sign out.
3. Analytics — only after Accept all
Provider: Google Analytics 4. The id in the code is G-GNKBJK3ZZN, script googletagmanager.com/gtag/js. The site does not set cookie_expires, so the lifetime is Google’s default for this tag.
- _ga — 2 years. Distinguishes browsers.
- _ga_GNKBJK3ZZN — 2 years. Stores session state.
While analytics_storage is denied, the tag should not set these cookies.
4. Advertising — only after Accept all. Not necessary
Provider: Google Ads. The id in the code is AW-18437995984, the same gtag.js, with allow_enhanced_conversions. There is no separate Google Tag Manager container (GTM-) in the files.
The site code does not name advertising cookies. When ad_storage is granted, the Google Ads tag may set cookies on this site’s domain that Google publishes for Google Ads. The site does not override the lifetime:
- _gcl_au — 90 days. Ad measurement.
- _gcl_aw — 90 days. Ad-click id, if the link had one.
- _gcl_gs — 90 days. Google Ads measurement.
Google may also set cookies on its own domains, including doubleclick.net. Google keeps that list, not this site. While ad_storage, ad_user_data and ad_personalization are denied, the page asks the tag not to do this.
After Accept all, a form request or cabinet sign-in may send an email or phone number to Google Ads to measure a conversion. That is not required to open the cabinet.
5. What the code does not have
- a third button for analytics only;
- url_passthrough and ads_data_redaction — they are not in the code;
- admin or lawyer-cabinet cookies on this page: only staff see those after sign-in.
Other data: privacy and GDPR. Requests: legalnomosceo@gmail.com.
