Skip to main content

Cookie Policy

This Cookie Policy explains how Expat183 ("we", "us", or "our") uses cookies and similar technologies to recognise you when you visit our website. It explains what these technologies are and why we use them, as well as your rights to control our use of them.

This policy applies to visitors worldwide, and one banner is shown to everyone. In the United Kingdom the basis for asking your consent is the Privacy and Electronic Communications Regulations (PECR), read with the UK GDPR. In the European Union, including Ireland and Malta, it is the ePrivacy Directive (2002/58/EC) as implemented in each member state, read with the EU GDPR. In the United States there is no equivalent statutory consent rule for cookies, though state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) give you rights over the data collected; we apply the same banner. Australia, New Zealand, Canada and India likewise have no equivalent statutory consent rule for cookies, and we apply the same banner there too. Whichever applies to you, those rights are described in this policy and in our Privacy Policy (opens in a new tab).

1. What Are Cookies?

Cookies are small data files that are placed on your computer or mobile device when you visit a website. Cookies are widely used by website owners to make their websites work, or to work more efficiently, as well as to provide reporting information.

Cookies set by the website owner (in this case, Expat183) are called "first-party cookies". Cookies set by parties other than the website owner are called "third-party cookies". Third-party cookies enable third-party features or functionality to be provided on or through the website.

2. Why Do We Use Cookies?

We use cookies to ensure our website functions properly and to enhance your experience. Essential cookies are required for basic features like maintaining your login session and ensuring secure form submissions. Without these cookies, core functionality of our service would not work.

Functionality cookies enable features that improve your experience, such as remembering your theme preference (light or dark mode) and maintaining your sidebar state. These cookies help us provide a consistent experience across your visits.

We use analytics cookies to understand how users interact with our platform, which pages are most visited, and where we can make improvements. This data is aggregated and does not identify individual users. Security cookies help us detect and prevent fraudulent activity, protecting both your account and our platform from malicious actors.

3. Types of Cookies We Use

3.1 Essential Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Cookie NamePurposeDuration
__Secure-WillSessionMaintains your logged-in sessionSession (expires when you close your browser)
__Host-csrftokenSecurity token to prevent cross-site request forgery1 year
__Secure-will_access_tokenShort-lived authentication token for API access; cleared when you sign out30 minutes (up to 24 hours if you choose "Remember it for 30 days" under "This device")
__Secure-will_refresh_tokenRenews your authentication token during an active session; cleared when you sign out4 hours (up to 30 days if you choose "Remember it for 30 days" under "This device")
__Secure-will_token_infoTells the page you are signed in and when your session is due to expire, so the header and the session timer can show the right thing straight away instead of flickering through a signed-out view first. It holds only those timings and no authentication token, and it is the one session cookie the page itself can read; it is not set at all on a device you tell us is shared or publicSame as your access token above
__Host-will_identitySet only on TheWILL.ai, when you sign in there. It lets our other sites that share your account sign you in without asking for your password again. It holds a signed reference to your sign-in and no password, can be read only by our servers and not by the page, and stops working once you sign out or change your password. On a device you tell us is shared or public it is deleted when you close your browserSame as your refresh token above
__Host-sso_stateSet by our other sites while they check with TheWILL.ai whether you are already signed in, so the answer can be matched to the request your own browser started. It holds random values only and nothing about you5 minutes
__Host-sso_checkedSet by our other sites just before they check with TheWILL.ai whether you are already signed in, and again when the answer comes back. If TheWILL.ai cannot be reached, it shows you the site's own sign-in form instead of sending your browser back and forth between the two. It holds no identifier and nothing about you1 minute
__Host-sso_browserSet on TheWILL.ai and on our other sites that share your account. It holds a random identifier for this browser, signed so it cannot be altered, and nothing about you or your account. When you sign out on any of our sites, it lets us find and end the sessions this browser holds on the others, including one you signed in to directly. It can be read only by our servers and not by the page, and is never used for analytics or advertising or shared with a third party180 days, renewed each time one of our sites checks your sign-in with TheWILL.ai
cookie_consentStores your cookie consent preferences1 year
profile_edit_sessionMaintains secure session for profile editing15 minutes
purchase_platformRecords billing platform (web/iOS/Android) for subscription management routing30 days
viewer_countryRemembers the country you select in the header country selector, so pages load in the currency you chose, articles lead with the version written for that country and pages tell you which features are offered there, instead of briefly showing a different one first. Our servers read it when they build the page; while you have not made a selection they use the approximate country of your connection instead, which is never stored in a cookie or against you. It holds nothing but that two-letter country code (no identifier), and is set only when you actively make that selection, never from ordinary browsing, so it falls within the "strictly necessary" exemption for customisation you have explicitly requested1 year
pricing_countryThe previous name of the cookie above, holding the same two-letter country code and set at the same moment, for the same purpose. It holds nothing but that two-letter country code (no identifier), and is set only when you actively make that selection, never from ordinary browsing, so it falls within the "strictly necessary" exemption for customisation you have explicitly requested. Both names are written while our caching rules are updated to recognise the new one; the older name will stop being set once that is done1 year
thewill_refRecords a referral code so your sign-up can be attributed to the person who referred you. It is set only when you actively follow a referral link (a user-initiated action to obtain the referral you requested), and is never set from ordinary browsing, so it falls within the "strictly necessary" exemption30 days
thewill_partnerRecords which legal professional's or firm's partner page you started from, so a will you then start can be attributed to that partner. It holds only the partner's public page reference and nothing about you. It is set only when you press the button to start a will on a partner page (a user-initiated action), and is never set from ordinary browsing, so it falls within the "strictly necessary" exemption30 days
thewill_affRecords a creator/affiliate code so a later paid purchase can be attributed to the creator whose link you followed under our Creator Programme. Like the referral cookie above, it is set only when you actively follow an affiliate link (a user-initiated action), and is never set from ordinary browsing, so it falls within the "strictly necessary" exemption. It uses last-click attribution, so the most recent affiliate link you followed takes precedence60 days
will_anonymous_idIdentifies your browser to our servers before you create an account, so that a will you start as a visitor is still there on the next page. It holds a random reference and nothing about you. Because it is readable only by our servers and not by the page, it cannot be removed from within your browser; clearing your cookies in your browser settings removes it, and starting a fresh one loses any unsaved visitor progress it was holding3 days
willTrial_anonymousId, assetTrial_anonymousId, videoTrial_anonymousIdKeep track of how far you have got in a free trial of the will, asset and video features before you create an account, so your place is not lost when you move between pages. Each holds a random reference for that one feature and nothing about you1 year

3.2 Functionality Cookies

These cookies enable the website to provide enhanced functionality and personalisation. They are not strictly necessary and are blocked until you grant "Functional" consent via the Cookie Consent Manager. None of the cookies listed below are set before you consent. You can withdraw consent at any time using Open Cookie Preferences in Section 5.

One cookie in this category can also be consented to on its own. device_fingerprint_id is set if you choose Remember it for 30 days under "This device" when you sign in or when you confirm your email address at registration, whether or not you have granted the wider "Functional" consent. We ask separately because that choice is a decision about one cookie for one purpose, and it would not be right to read it as consent to the theme cookie alongside it. Choosing it grants nothing else, and it can be withdrawn in the same place as everything else in this category. Granting "Functional" consent on its own also sets it: the choice at sign-in is a second route to the same permission, not the only one.

Signing out does not remove it. This cookie records which browser you are using, not whether you are signed in, so it stays for the 30 days shown below and lets us recognise this browser the next time you arrive. We remove it from this browser when you choose It's a public or shared computer under "This device". Removing the device from your account, or deleting your account, does not reach a cookie already stored in a browser; what it does is withdraw what the cookie buys: the device stops being trusted and we ask you to verify your identity on it again. You can clear the cookie yourself at any time in your browser's own settings. Choosing Remember it for 30 days does one extra thing on top of storing the cookie: it also tells us this browser is yours, so we ask you to verify your identity less often on it. You can still be asked for a verification code.

Cookie NamePurposeDuration
thewill_themeStores your light/dark mode preference so the site loads in the theme you chose1 year
device_fingerprint_idRecognises your device across sessions to support account-security checks, such as flagging sign-ins from an unfamiliar device. It relies on device fingerprinting, a technique the ICO treats as requiring consent rather than strictly necessary, so it is listed here as a Functionality cookie, not in the strictly-necessary Security category below. Granted either by "Functional" consent on its own or by choosing "Remember it for 30 days" under "This device". It survives signing out, and we remove it from this browser when you tell us the computer is public or shared; removing the device from your account or deleting your account withdraws the trust it carries rather than reaching the stored cookie, which you can clear in your browser's own settings. Without it we cannot tell a browser you have used before from a new one, so we ask you to verify your identity more often30 days

3.3 Security Cookies

These cookies are strictly necessary to detect and prevent security threats and cannot be disabled. The Category column distinguishes cookies that are strictly necessary for the platform to operate from those used specifically for fraud prevention.

Cookie NamePurposeCategoryDuration
cf_clearanceCloudflare security verificationFraud prevention30 minutes

3.4 Analytics Cookies

These cookies help us understand how visitors interact with our website. They are not strictly necessary and are only set if you grant "Analytics" consent via the Cookie Consent Manager.

Search result clicks. If you grant "Analytics" consent, we record which result you clicked after a search (the search words, the result's title, its address on our site and its position in the list), so we can tell whether our search is returning useful answers. If you are signed out, that record is tied to the session cookie described in 3.1 and to nothing else: we do not set an additional cookie for it, we do not build a profile of you across visits, and we never accept an identifier your browser supplies for it. If you are signed in it is tied to your account, alongside your search history. Declining "Analytics" stops the record being made at all. Search itself is unaffected.

Booking page visits. If you grant "Analytics" consent, a professional's public booking page records three steps of your visit: that the page was viewed, that you picked a time and moved on to your details, and that the booking was completed. This lets the professional see how many visitors go on to book. Your browser keeps a random reference for the visit in browser storage (see 3.7), not a cookie. On our servers we keep only a scrambled form of that reference that differs for every booking page, so visits to two different pages cannot be linked. We do not record your internet address, your browser details or anything you type for this, and these records are deleted after 180 days. Declining "Analytics" means nothing is recorded or stored. Booking itself is unaffected.

Cookie NamePurposeDurationTypeRecipientPrivacy Policy
_gaGoogle Analytics: distinguishes unique users2 yearsThird-partyGoogle LLCpolicies.google.com/privacy (opens in a new tab)
_gidGoogle Analytics: distinguishes users24 hoursThird-partyGoogle LLCpolicies.google.com/privacy (opens in a new tab)
_gatGoogle Analytics: throttles request rate1 minuteThird-partyGoogle LLCpolicies.google.com/privacy (opens in a new tab)
_gat_*Google Analytics: throttles request rate, per analytics property1 minuteThird-partyGoogle LLCpolicies.google.com/privacy (opens in a new tab)
_ga_*Google Analytics 4: stores and counts page views2 yearsThird-partyGoogle LLCpolicies.google.com/privacy (opens in a new tab)

3.5 Marketing Cookies

These are third-party technologies used by Brevo to measure engagement with our marketing emails. They are triggered when you open, or click a link in, a marketing email in your email client, not while you browse this website, which sets no Brevo cookies in your browser. Because they operate within the emails you receive rather than on this site, they are governed by your email-marketing consent (which you give when you opt in to marketing emails and can withdraw at any time using the unsubscribe link in any marketing email or your account communication preferences), and not by the on-site Cookie Consent Manager. Our Cookie Consent Manager has Essential, Functionality and Analytics categories only. There is no separate "Marketing" toggle, because we set no marketing cookies in your browser.

Concretely, opens are measured by a small tracking image embedded in the email and clicks by a redirect on the links in it. Brevo reports each of those events back to us, and we store the send itself, whether it was delivered, opened or clicked, and the running totals we derive from that for the recipient and for the campaign. Where you are part of a multi-email sequence, we use those totals to decide whether the next email in the sequence is still worth sending you. The per-send record is deleted after one year; the derived totals are removed when your account is deleted or anonymised. Because the tracking image and the click redirect store or access information on your device, they engage regulation 6 of the Privacy and Electronic Communications Regulations 2003 in the same way a cookie would, and we rely on your marketing consent for them; unsubscribing stops the emails and the measurement of them together. Our privacy policy sets out the lawful basis and retention in full.

Cookie NamePurposeDurationTypeRecipientPrivacy Policy
brevo_*Brevo: email campaign tracking13 monthsThird-partySendinblue SAS (Brevo)brevo.com/legal/privacypolicy (opens in a new tab)
email_idTracks email campaign interactions30 daysThird-partySendinblue SAS (Brevo)brevo.com/legal/privacypolicy (opens in a new tab)

3.6 Document Vaults and Organisation Spaces

Your document vault, and the separate space belonging to an organisation you are a member of, set no cookies of their own and store nothing about your documents on your device. Which space a document belongs to, and whether your account may see it, are worked out on our servers on every request. The essential session cookie listed in 3.1 is all that is needed to use them, so nothing in this policy changes because your organisation has a space.

3.7 Browser Storage

As well as cookies, we store small amounts of information in your browser's own storage (known as local storage and session storage). The rules that govern cookies govern this storage in exactly the same way, so your choices in the Cookie Consent Manager apply to it too: storage in a category you have not granted is simply not written. Session storage is cleared when you close the tab; local storage stays until it is removed, either by you in your browser's settings or by us when you withdraw the consent it depended on.

Withdrawing consent removes it. When you turn a category off in the Cookie Consent Manager, we clear the stored items belonging to that category from this browser along with the cookies, rather than leaving them behind. One consequence worth knowing: notices and prompts you had already dismissed are stored as a Functional preference, so turning Functional off means those dismissals are forgotten and the notices appear again.

What We StorePurposeCategory
Sign-in and session continuityKeeps you signed in across pages, carries you back to where you were after signing in, and coordinates renewing your session between open tabsStrictly necessary
Will, document and payment progressHolds your place in a will or document you are part-way through, including any unsaved draft text and the checkout step of a purchase in progress, so a reload or a move between pages does not lose your workStrictly necessary
themeMode, sidebarCollapsed, sidebarPinnedRemembers your light/dark mode choice and whether the sidebar is collapsed or pinned. Without Functional consent both still work for the visit you are in; they simply are not remembered for the next oneFunctionality
feedbackWidgetEmailThe email address you typed into the feedback form, kept only so the form can fill it in for you next time. It is personal data, which is why we name it here rather than describing it as a preference; it stays in this browser, you can clear it in your browser's settings, and we remove it if you withdraw Functionality consentFunctionality
Dismissed notices, filters and short-lived cachesRemembers which notices you have closed, the filters and page sizes you chose, and copies of lists we have already fetched so pages load faster. Declining costs convenience only: every one of them is re-fetched or reset insteadFunctionality
device_fingerprintsThe device-recognition details that accompany the device_fingerprint_id cookie in 3.2. It follows exactly the same rule as that cookie: it is stored if you grant "Functional" consent, or if you choose "Remember it for 30 days" under "This device" at sign-in, and neither choice on its own grants anything more. Without it we cannot tell a browser you have used before from a new one, so we ask you to verify your identity more oftenFunctionality, or the sign-in device choice
discovery_session_keyAn anonymous reference that ties the answers you give in the discovery questionnaire to the session you gave them in, so we can understand how people use it. Declining Analytics means a part-finished questionnaire is not carried across a reload; you can still complete it in one sittingAnalytics
booking_page_session_idA random reference, kept for the browser tab session only, that ties together the steps of one visit to a professional's booking page (viewed, started, completed) so the professional can see how many visitors go on to book (see 3.4). It identifies nothing about you, and declining Analytics costs you nothing: booking works exactly the sameAnalytics
thewill_nri_signup_source, thewill_community_signup_source, thewill_ai_landing_referral, newsSubscriptionIntent and progress milestonesRecords where a sign-up came from (including the website that linked to us and any campaign tag on the first page you visited, so we can tell visits referred by AI assistants) and how far visitors get through our sign-up steps, so we can measure which routes work. Nothing in the product reads these to decide what you see, so declining Analytics costs us the measurement and costs you nothingAnalytics

4. Third-Party Services

We use the following third-party services that may set cookies:

4.1 Cloudflare

We use Cloudflare for security and performance optimisation. Cloudflare may set cookies to:

  • Identify trusted web traffic
  • Provide security features
  • Route traffic efficiently

4.2 Cloudflare Turnstile

We use Cloudflare Turnstile for bot protection on forms. This service may set cookies to verify that you're a human user. To learn more about how Cloudflare handles personal data and your options to opt out, see Cloudflare's privacy policy (opens in a new tab) and cookie policy (opens in a new tab).

4.3 Google Analytics

We use Google Analytics 4 to understand how visitors use our website. Google Analytics uses cookies to collect information such as:

  • How often users visit the site
  • What pages they visit
  • What other sites they used prior to coming to our site
  • Conversion events and user journeys

You can opt out of Google Analytics tracking across all websites by installing the Google Analytics Opt-out Browser Add-on (opens in a new tab). You can also withdraw consent for analytics cookies on this site at any time using Open Cookie Preferences in Section 5 below.

4.4 Brevo (Email Services)

We use Brevo (formerly Sendinblue) for both transactional and marketing email services. Brevo may set cookies for different purposes:

  • Transactional emails (password reset, OTP verification, booking confirmations, security alerts): These are essential service communications and do not require marketing consent
  • Marketing emails (newsletters, feature announcements, promotions): Only sent with your explicit consent. Brevo tracks email opens and clicks to measure campaign effectiveness
  • Manage unsubscribe and email preference settings

You can withdraw consent for marketing emails at any time by using the unsubscribe link in any marketing email, by using Open Cookie Preferences in Section 5 below, or by adjusting communication preferences in your account settings. For details on how Brevo processes data, see Brevo's privacy policy (opens in a new tab) and cookie policy (opens in a new tab).

Cookie status: Brevo's email-tracking technologies (brevo_*, email_id) are triggered only when you open, or click a link in, a marketing email in your email client, and only if you have opted in to marketing emails. Our website itself sets no Brevo cookies in your browser, so there is no "Marketing" category in the on-site Cookie Consent Manager; this tracking is instead controlled by your email-marketing consent, which you can withdraw at any time using the unsubscribe link in any marketing email (see Section 3.5). Transactional emails (password resets, OTP verification, security alerts) are an essential service communication and do not set marketing or tracking cookies in your browser.

4.5 Daily.co (Video Consultations)

We use Daily.co to facilitate video consultations between consumers and legal professionals. When you participate in a video consultation, Daily.co may set cookies and use local storage to:

  • Maintain your session during the consultation
  • Manage audio and video device preferences
  • Provide meeting functionality (screen sharing, recording controls)
  • Optimise connection quality and bandwidth

Cookie status: Daily.co sets no cookies while you browse the site. Its cookies and local storage are created mid-flow only when you actively join a video consultation (a user-initiated action), and are strictly necessary to deliver the consultation you have requested (maintaining the session and your audio and video devices). Because they are essential to a service you have asked us to provide, they fall within the "strictly necessary" exemption and are not set before you start a call.

4.6 Consultation and Chat Services

When you use our consultation and in-consultation messaging features, we may use cookies and local storage to:

  • Maintain your WebSocket connection for real-time chat messaging
  • Track recording consent status for the current consultation session
  • Store chat disclaimer dismissal preferences (per consultation)
  • Remember your booking session state during the appointment scheduling flow

4.7 Stripe Payment Processing

We use Stripe for payment processing, subscription billing, and checkout. When you complete a purchase on our checkout page, whether you are signed in or buying a gift card as a guest, or manage your subscription, Stripe may set cookies to:

  • Maintain checkout sessions during the payment process
  • Remember payment preferences for returning customers
  • Prevent fraudulent transactions
  • Facilitate Stripe's Customer Portal for subscription management

Cookie status: Stripe sets no cookies while you browse the site. Its cookies are created mid-flow only when you begin checkout or open the billing portal (a user-initiated action), and are strictly necessary to process the payment you have requested and to prevent fraud. Following the ICO's guidance on cookies that are essential to a transaction the user is mid-way through, these fall within the "strictly necessary" exemption and so do not require prior consent; they are never set merely from browsing.

4.8 Apple and Google

If you subscribe through the Apple App Store or Google Play Store, Apple or Google may set cookies or use device-level storage to:

  • Manage your subscription state
  • Process in-app purchases
  • Verify subscription receipts

4.9 CityFALCON (Market Intelligence)

We use CityFALCON as a market-data source for the financial news, sentiment, regulatory filings, insider transactions and investor-relations documents shown on a security's market-intelligence page. This is a server-side data source only. We fetch the data on our own servers and render it to you, so CityFALCON sets no cookies and runs no scripts in your browser. We send only the public ticker symbol of the security you are viewing; no personal data, account details or holding quantities leave our servers, and none of the returned content is stored in our database.

4.10 YouTube (Embedded Videos)

A small number of our pages embed a YouTube video (for example, the Polar Bear Pitching story on our Oulu promotional page). We embed these videos using YouTube's privacy-enhanced mode (youtube-nocookie.com), which does not set any cookies or store viewing data on your device unless and until you actively press play, a user-initiated action. If you play an embedded video, YouTube (Google Ireland Limited) may then set cookies to remember your playback preferences and measure video engagement; these are governed by Google's privacy policy (opens in a new tab). If you do not play the video, no YouTube cookies are set. You can avoid these cookies entirely by not playing embedded videos.

4.11 Third-Party Cookie Purposes

Third-party cookies generally serve the following purposes:

  • Performance and Analytics: To analyse how our website is accessed, used, or performing
  • Functionality: To remember choices you make to provide enhanced features
  • Security: To help protect against malicious activity

We do not set any advertising or behavioural-targeting cookies that build a profile of your interests across websites.

5. How to Control Cookies

You have the right to decide whether to accept or reject cookies. You can exercise your cookie rights by setting your preferences in the Cookie Consent Manager.

5.1 Withdrawing Consent

Withdrawing consent is as easy as giving it. You can withdraw your consent at any time using Open Cookie Preferences above: simply uncheck the categories you no longer wish to allow and save. The change takes effect immediately: cookies in the withdrawn categories are cleared on your next page load and no new cookies in those categories will be set. No reason or notice period is required, and withdrawal does not affect the lawfulness of any processing carried out before withdrawal.

5.2 Browser Controls

Most web browsers allow you to control cookies through their settings. However, if you limit the ability of websites to set cookies, you may worsen your overall user experience, since it will no longer be personalised to you.

5.3 Disabling Cookies

You can prevent the setting of cookies by adjusting your browser settings. Be aware that disabling cookies will affect the functionality of this and many other websites. Disabling cookies will usually result in also disabling certain functionality and features of this site.

5.4 Your Choice Applies to Each Site Separately

We operate four separate websites, each with its own address:

  • thewill.ai (including the community forum at community.thewill.ai)
  • orchard72.com
  • expat183.com
  • thefamilygroup.ai, the site of the group that operates the other three. It carries no account and nothing is sold on it, but it shows the same banner and records your choice the same way

The cookie that records your choice is stored against the address of the site you are on, so your choice is a separate decision on each of the four sites. Accepting or rejecting cookies on one of them does not carry across to the other three: the banner will appear again the first time you visit each site, and you may set different preferences on each. The one exception is the community forum, which sits on a subdomain of thewill.ai and shares that site's choice, as described in Section 11.

The same applies to withdrawal. Withdrawing your consent on one site withdraws it for that site only. To change your preferences everywhere, use Open Cookie Preferences on each site in turn.

If you are signed in when you make a choice, we keep a record of it on our servers so we can show what you agreed to and when. That record includes which of the three sites the choice was made on. Where we cannot determine the site, we leave that detail blank rather than assume it.

6. Cookie Settings by Browser

Here's how to manage cookies in popular browsers:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions

7. Do Not Track

Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want to have your online activity tracked. Most modern browsers no longer transmit a DNT signal, and there is no industry consensus on how it should be honoured. We therefore rely on the Cookie Consent Manager described in Section 5 to control which cookies are set. Please use that to express your preferences.

8. Your California and US State Privacy Rights

If you are a resident of California or another US state with a comprehensive consumer privacy law (such as Colorado, Virginia, Connecticut, Texas, Oregon, Montana and others), you have specific rights over the personal information collected through cookies and similar technologies. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together "CCPA/CPRA"), gives California residents the right to opt out of the "sale" or "sharing" of personal information, including any sharing for cross-context behavioural advertising.

We do not sell or share your personal information. We do not disclose the data collected through cookies in return for money or other valuable consideration, and, as set out in Section 4.11 above, we set no advertising or behavioural-targeting cookies that build a profile of your interests across other websites for cross-context behavioural advertising. Because we do not engage in these activities, no "Do Not Sell or Share My Personal Information" opt-out is required for our cookies.

You can control every non-essential cookie we set on this website, including analytics cookies, at any time using Open Cookie Preferences in Section 5 above. This is the opt-out mechanism for all cookie-based tracking on our website, and it applies wherever you live. Engagement tracking in our marketing emails (see Section 3.5) is controlled separately, through the unsubscribe link in any marketing email or your account communication preferences.

For the full set of rights available to California and other US state residents, including the rights to know, delete, correct, and to non-discrimination, and for how to exercise them, please see our Privacy Policy (opens in a new tab), which sets out our US state-law disclosures in detail.

9. Preparedness Assessment Storage

Our Preparedness Assessment uses your browser's sessionStorage to store a temporary session key while you complete the questionnaire. This key is used to associate your answers with a single assessment session. sessionStorage is not a cookie: it is automatically cleared when you close the browser tab and is not sent to our servers with every request.

The assessment does not set any additional cookies beyond those already described in this policy (authentication, CSRF protection, and cookie consent). No third-party tracking cookies are placed as part of the assessment.

10. Will Location Registry

The Will Location Registry (the registry dashboard, the registration setup wizard, and the claimant portal used by someone making a claim after a death) introduces no new cookies or browser storage. The registry pages you reach while signed in rely only on the essential authentication, CSRF-protection and cookie-consent cookies already described in Section 3.1. The claimant portal is opened from a signed link we email to a designated party or custodian: the link carries a single-purpose, expiring token in its address, so no cookie or local storage is needed to identify the claimant, and none is set.

The same is true of the invitation we send when a legal professional records, on your behalf, where the will they hold for you is kept. That link also carries a single-purpose, expiring token in its address and sets nothing in your browser when you open it. Accepting the record signs you in as normal, and from that point the essential authentication and CSRF-protection cookies in Section 3.1 apply, exactly as they do anywhere else you are signed in. Declining sets nothing at all.

We set no analytics, marketing or third-party tracking cookies on any registry or claim surface.

11. Community Forum Cookies

Our community forum at community.thewill.ai runs Discourse, an open-source forum platform that we self-host on our own infrastructure. The forum cookies listed below are first-party cookies set by software we operate. No forum cookie data is sent to Discourse Inc. or any other third-party forum host. Because the forum operates on a subdomain of thewill.ai, your consent preferences set via our apex-domain consent banner apply to these cookies as well.

Cookie NamePurposeDurationType
_tForum session authentication tokenSessionStrictly necessary
_forum_sessionForum session state and CSRF protectionSessionStrictly necessary
theme_idsStores your selected forum theme preference1 yearFunctionality
color_scheme_idStores your selected forum colour scheme (light/dark)1 yearFunctionality
cnTracks which forum notifications have been dismissed1 yearFunctionality
__cf_bmCloudflare bot-management challenge token set at the network edge30 minutesStrictly necessary
cf_clearanceCloudflare DDoS / challenge-passed tokenUp to 1 yearStrictly necessary

Forum session cookies (_t and _forum_session) and Cloudflare security cookies (__cf_bm, cf_clearance) are strictly necessary for forum operation and security, and cannot be disabled. The Cloudflare cookies are set at the network edge by our CDN provider, which is disclosed on our Sub-Processor List (opens in a new tab). Theme and notification cookies are functionality cookies and are only set if you have granted "Functional" consent via the apex-domain banner. If consent is withdrawn, these cookies are cleared on your next Forum page-load.

We do not enable Google Analytics, Segment, Cloudflare Web Analytics, or any other third-party analytics on the Forum subdomain. Discourse's built-in administrative analytics are server-side only and do not place tracking cookies on your device.

12. Will Import Invitations

When a legal professional invites you to import an existing will, the invitation flow (the email invitation, the client landing page, the engagement-letter consent step, and the import wizard itself) introduces no new cookies or browser storage. Like the claimant portal in Section 10, it opens from an expiring link we email to you, so nothing is stored to recognise you from the email; once you sign in, only the Section 3.1 essentials apply.

We set no analytics, marketing or third-party tracking cookies on any import or invitation surface.

13. Sharing Your Records with a Professional

Sharing your asset register, your guardianship nominations or your business succession plans with a professional, and withdrawing that share again, introduces no new cookies or browser storage. Every part of the choice is recorded on our servers against your account: which category you shared, whether it covers one piece of work or the whole relationship, when it ends, and when you withdrew it. Nothing about it is kept on your device, so clearing your cookies never changes who can see your records, and signing in from another device shows you the same shares.

The same is true of agreeing that a copy of one matter may go to your professional's own drafting software, and of withdrawing that agreement: it introduces no new cookies or browser storage. The request, your answer, the date it expires and any withdrawal are all recorded on our servers against your account, so clearing your cookies neither grants nor cancels one.

The professional access pages themselves rely only on the essential authentication and CSRF-protection cookies already described in Section 3.1. We set no analytics, marketing or third-party tracking cookies on them.

13A. Power of Attorney and Advance Decision Purchases

Buying a power of attorney or an advance decision, and inviting your partner to a couple purchase, introduces no new cookies or browser storage. Choosing between an individual and a couple purchase is recorded on our servers against your account, not on your device, so clearing your cookies never changes what you have bought or who has been invited.

Your partner opens the invitation from a signed link we email them: the link carries a single-purpose, expiring token in its address, so no cookie or local storage is needed to identify them from the email. The purchase itself is completed on the checkout page described in Section 4.7, where Stripe's strictly necessary payment cookies are created mid-flow once you begin, and the invitation and document pages rely only on the essential authentication and CSRF-protection cookies already described in Section 3.1.

13B. The Gift Register and Transfer Documents

Recording a gift you have already made, attaching evidence to it, and preparing or storing a deed or transfer document introduce no new cookies or browser storage. Every entry in your register, and every document stored against one, is held on our servers against your account rather than on your device, so clearing your cookies never changes what you have recorded or what has been uploaded.

The public pages describing this feature, at /products/gifts-and-transfers and /help/gifts-and-transfers, are ordinary marketing and help pages and set nothing beyond the cookies described in Sections 3 and 5. Inside your account, these pages rely only on the essential authentication and CSRF-protection cookies already described in Section 3.1, and any document you upload is transmitted to our servers rather than cached in browser storage.

13C. Practice Integrations

A legal professional connecting their practice's own Xero, Outlook mail or Gmail account from /professional/settings/integrations introduces no new cookies. These connections are being introduced and show as unavailable until they are switched on. While the professional is sent to the provider to sign in and brought back, a one-time security value and a PKCE verifier (a code proving the returning request is the one that set out) are held on our servers in the essential session behind the __Secure-WillSession cookie already described in Section 3.1, and are discarded as soon as the professional returns.

The page also keeps which provider was chosen, with the same security value, in that browser tab's session storage; it is cleared on return and never outlives the tab. The provider's sign-in and consent pages are on the provider's own website, so any cookies they set are the provider's, under its own cookie and privacy policies rather than this one. The access a connection produces is stored on our servers, never in your browser.

14. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Cookie Policy on this page and updating the "Last updated" date. Where a change introduces new non-essential cookies (analytics, marketing, or functionality), or materially expands the purposes of an existing non-essential cookie, we will request your consent again via the Cookie Consent Manager before those new cookies are set. Consent you give to non-essential cookies is valid for up to 12 months. After that period, or sooner if we materially change our cookie practices, we may ask you to refresh your consent so that it continues to reflect how we use cookies.

15. Contact Us

If you have questions about our use of cookies or other technologies, please contact us:

Expat183
Please use the contact form available in your account dashboard or on our Contact Us page.

We use cookies to improve your experience. See our Cookie Policy (opens in a new tab) for details.