Solutions
Products
Resources
Developers
Pricing
Sign inExplorerBook a demo
Industries
DeFi
Simulate governance, validate cross-chain execution, monitor invariants.
Financial Institutions
Operational controls, visibility, and audit trails for institutional-grade Web3.
Networks
Onboard partners, remove infra dependencies, support ecosystem growth.
Use Cases
Financial Modeling
Cascade impact, pre-trade analysis
→
Incident Management
Detect, simulate, mitigate
→
CI/CD & Staging
Test every change before prod
→
Sandbox environments
Demo, audit, showcase
→
Support Operations
Resolve customer issues without escalating
→
Platform
Simulator
Full-fidelity decision testing
Console
Operational command center
Monitor
Detection-to-response pipeline
Node
Low-latency RPC infrastructure
Case Study
How Aave built V4 on Tenderly — zero testnet dependencies.
500+ E2E tests per environment, 2K+ tests across 4M+ instances. How Aave used Virtual Environments as the shared staging surface for every team.
Read the case study →
Learn
Case Studies
How Aave, Uniswap, and Safe ship
→
Blog
Engineering, research, announcements
→
Changelog
What shipped this week
→
Blog
Validating agentic workflows with Tenderly MCP Server
AI agents · simulation-verified actions · MCP
Read the post →
Build
Documentation
Get started in minutes
→
API Reference
Simulation, Node, Alerts
→
MCP Server
Tenderly inside your AI tooling
→
GitHub
Open source & examples
→
Status
Live platform health
→
Changelog
Loading latest…
Industries
  • DeFi
  • Financial Institutions
  • Networks
Use Cases
  • Financial Modeling
  • Incident Management
  • CI/CD & Staging
  • Sandbox environments
  • Support Operations
  • Simulator
  • Console
  • Monitor
  • Node
  • Case Studies
  • Blog
  • Changelog
  • Documentation
  • API Reference
  • MCP Server
  • GitHub
  • Status
Pricing
Sign inExplorerBook a demo
Legal

Cookies Policy

Effective Date: [October 2026]Last Updated: 21.07.2026Tenderly D.O.O. & Tenderly Technologies Inc.
Privacy PolicyTerms of ServiceCookies PolicyThird-Party Processors
Contents
  • 01 Application
  • 02 Policy
  • 03 Appendix A: Website Cookie Tables (tenderly.co)
  • 04 Appendix B: Dashboard Cookie Tables (dashboard.tenderly.co)
  • 05 How to Control and Delete Cookies
  • 06 Changes and contacts
01

Application

We (Tenderly D.O.O. and Tenderly Technologies Inc. — referred to collectively as "Tenderly") use "cookies" and other tracking technologies to collect and disclose information about you and your activity across our website (tenderly.co, the "Website") and our web application (dashboard.tenderly.co, the "Dashboard") to help us improve your online experience in connection with Tenderly.

02

Policy

Tenderly believes in transparency about the collection and use of data. This policy provides information about how and when Tenderly uses cookies for these purposes. Capitalized terms used in this policy but not defined have the meaning set forth in our Privacy Policy, which also includes additional details about the collection and use of information at Tenderly.

What is a cookie?

Cookies are small text files placed on your computer or mobile device that enable Tenderly's features and functionality. They are unique to your account or your browser. Session-based cookies last only while your browser is open and are automatically deleted when you close it. Persistent cookies last until you or your browser delete them or until they expire. Because the Dashboard is a web application, we also store some working state in your browser's local and session storage; we treat that storage the same way as cookies for the purposes of this policy.

Does Tenderly use cookies?

Yes. Tenderly uses cookies and similar technologies, including browser storage, both session-based and persistent, on the domains it operates (collectively, the "Sites"). Tenderly also uses third-party cookies and services: on the Website, Google (Analytics, Ads), Cloudflare (Turnstile), Matomo, FullStory, Ahrefs, LinkedIn, X, Reddit, Apollo.io, G2 and lemlist; on the Dashboard, Google (Analytics, Tag Manager), Cloudflare (Turnstile), Matomo, FullStory, Ahrefs, ActiveCampaign, Stripe and WorkOS. The Website and the Dashboard share the parent domain .tenderly.co, so a cookie set by one may be visible on the other; each cookie is governed by the property that set it and by the choice you made there.

How is Tenderly using cookies?

Some cookies are associated with your account to remember that you are logged in and which organization you are working in. Other cookies are not tied to your account but are unique and allow us to carry out analytics and to remember your preferences, among other things. We group our use into the categories below.

  • Authentication: If you are signed in to the Dashboard, cookies help Tenderly show you the right information and keep your session active. Sign-in is handled on our behalf by WorkOS.
  • Security: Tenderly uses cookies and services such as Cloudflare Turnstile and Stripe to enable security features, prevent fraud on payment forms, and detect malicious or automated activity. Turnstile runs only when you submit a protected form and, in our checks, set no cookie or browser storage; an interactive challenge may set a cookie on Cloudflare's own domain. On the Website, a region cookie lets the consent banner apply the right default.
  • Preferences, features, and services: On the Dashboard, browser storage records the choices you make and the work you leave unfinished — your theme, sidebar and table layout, saved filters, recent searches, notices you closed and partially completed forms — so the Dashboard behaves consistently and unfinished work survives navigation. This storage exists only because of an action you took, is never transmitted, and is strictly necessary to provide what you asked for.
  • Performance, Analytics, and Research: With your consent, cookies and tools such as Google Analytics, Matomo, FullStory and Ahrefs help Tenderly learn how the Website and the Dashboard perform and how they are used, so we can improve them. FullStory records how you interact with the interface (session replay). These are set only after you opt in.
  • Marketing: On the Website, with your consent, advertising platforms (Google Ads, LinkedIn, X, Reddit) measure our campaigns and may use your visit to show you relevant ads on their platforms, and Apollo.io, G2 and lemlist identify business visitors. On the Dashboard, one marketing-automation tool (ActiveCampaign) identifies visitors with your consent; the Dashboard does not serve or measure advertising, and its advertising, ad-personalisation and ad-user-data signals are set to "denied" in all cases.

What third-party cookies does Tenderly use?

You can find the third-party cookies Tenderly uses, along with other relevant information, in the cookie tables in Appendix A (Website) and Appendix B (Dashboard). Tenderly does its best to keep these tables updated, but please note that the number and names of cookies, pixels, and similar technologies may change from time to time.

How are cookies used for advertising purposes?

On the Website, if you allow the Marketing category, third parties such as Google, LinkedIn, X and Reddit may use the fact that you visited tenderly.co to show you ads about our services on their platforms and to measure our campaigns. Their use of tracking is governed by their own privacy policies. You can prevent this by leaving the Marketing category off, and you may opt out of interest-based advertising through the Network Advertising Initiative or the Digital Advertising Alliance. The Dashboard does not use cookies, beacons, pixels, or tags to serve interest-based advertising, and Tenderly does not sell personal data.

What can you do if you don't want cookies to be set or want them removed?

Optional cookies are off until you opt in, and you can disable or delete them at any time. On the Website, use the "Cookie preferences" button on tenderly.co/cookies (Necessary, Analytics, Marketing; if you visit from the EU, EEA, United Kingdom or Switzerland, Analytics defaults to off). On the Dashboard, use Account → Security → Cookie Settings or, while signed out, the Tenderly menu at the top left of the page (Strictly Necessary, Functional, Analytics, Marketing; every optional category is off by default in every region). You can also use your browser settings. Blocking categories may impact your experience. Withdrawing consent deletes the cookies of that category and stops the associated tools; on the Dashboard, withdrawing Marketing reloads the page so the tool stops, and a Functional counter stored before this choice existed is kept until you decline the Functional category.

Does Tenderly respond to Do Not Track signals?

Tenderly does not change its behaviour on receipt of a "Do Not Track" signal. Browsers' Global Privacy Control signal needs no special handling on our Sites: analytics and marketing tools stay off in every region until you opt in, and you can withdraw at any time through the consent tools above.

03

Appendix A: Website Cookie Tables (tenderly.co)

Necessary

Required for the Website to work and to remember your consent choices. Always active. Cloudflare Turnstile protects some of our forms against automated abuse and sets no cookie.

CookieProviderDurationType
tnd-regionTenderly24 hoursFirst party — coarse region (EU or rest of world) for the banner default.
tnd-cookie-prefsTenderlyUntil deletedFirst party, local storage — your per-category preferences.
tnd-cookie-consentTenderlyUntil deletedFirst party, local storage — legacy consent choice.

Analytics

Set only if you allow the Analytics category. Ahrefs Web Analytics also runs after the opt-in; it sets no cookie. Matomo's heatmap and session-recording plugin is enabled.

CookieProviderDurationType
_ga, _ga_3MG9H4NR7YGoogle Analytics400 daysThird party — distinguishes visitors and sessions.
_pk_id.*Matomo392 daysThird party — pseudonymous visitor identifier (tenderly.co only).
_pk_ses.*Matomo30 minutesThird party — groups requests into one visit.
fs_uidFullStory1 yearThird party — session-replay visitor identifier (also kept in local storage as _fs_uid).
fs_luaFullStory30 minutesThird party — last activity (also kept in local storage as _fs_lua).

Marketing

Set only if you allow the Marketing category. LinkedIn conversion tracking runs only when you submit a demo request. lemlist visitor tracking runs with this category and sets no cookie of its own. Advertising platforms may additionally set cookies on their own domains, governed by their own policies.

CookieProviderDurationType
_gcl_au, __gcl_auGoogle Ads3 monthsThird party — conversion attribution (a copy is kept in local storage as _gcl_ls).
_rdt_uuidReddit3 monthsThird party — Reddit Ads attribution.
_twpid, _twsidX13 monthsThird party — X (Twitter) Ads visitor and session identifiers.
tdly_attr_first, tdly_attr_lastTenderly (via Google Tag Manager)365 days / 90 daysFirst party, on .tenderly.co — first- and last-touch campaign attribution; set only when a campaign source, referrer or click id is detected.
apolloAnonIdApollo.ioUntil deletedThird party, local storage — B2B visitor identification (plus _canTrack and _eventQueue keys).
g2trackingG2Until deletedThird party, local storage — buyer-intent identification.

Other Website providers that receive data

ProviderPurposeRegion
VercelHosting and content delivery; sets the tnd-region cookie from your IP address.United States / global edge
SalesforceReceives contact and demo-request form submissions, including the attribution data above.United States
Cloudflare (Turnstile)Bot and abuse detection on protected forms; runs only when such a form is submitted.Global edge network (EU and US)
lemlistWebsite visitor tracking for sales outreach (Marketing category).European Union (France)
YouTube (Google)Embedded videos on some pages; YouTube sets its own cookies when a video is played.United States
04

Appendix B: Dashboard Cookie Tables (dashboard.tenderly.co)

Strictly Necessary Cookies

These cookies are necessary for the Dashboard to function and cannot be switched off in our systems. They are usually set only in response to actions you take, such as setting your privacy preferences, logging in, or opening a payment form. You can set your browser to block or alert you about these cookies, but parts of the Dashboard will then not work. Cloudflare Turnstile protects some of our forms against automated abuse and sets no cookie.

CookieProviderDurationType
cookie-consentTenderly6 monthsFirst party — stores your cookie choices.
workos-has-sessionWorkOS400 daysFirst party — records that a signed-in session exists.
__stripe_midStripe1 yearThird party — payment fraud prevention (on card forms).
__stripe_sidStripe30 minutesThird party — payment fraud prevention (on card forms).
mStripeUp to 400 daysThird party — payment fraud prevention (m.stripe.com).

Performance / Analytics Cookies

These cookies let us count visits and traffic sources so we can measure and improve the Dashboard, understand how visitors move around it, and replay interface sessions to diagnose problems. They are set only after you opt in, and are deleted if you withdraw consent. Ahrefs Web Analytics also runs after the opt-in; it sets no cookie. To view an overview of Google Analytics privacy, see support.google.com/analytics/answer/6004245. You may install the Google Analytics opt-out add-on at tools.google.com/dlpage/gaoptout.

CookieProviderDurationType
_gaGoogle Analytics400 daysThird party — distinguishes visitors.
_ga_X4KV3LPMTKGoogle Analytics400 daysThird party — maintains session state.
_pk_id.4.*Matomo392 daysThird party — distinguishes visitors.
_pk_ses.4.*Matomo30 minutesThird party — groups requests into one visit.
_pk_ref.4.*Matomo6 monthsThird party — records the referring site.
mtm_cookie_consentMatomo Tag Manager400 daysThird party — record of the analytics opt-in.
fs_uidFullStory1 yearThird party — identifies the session-recording visitor (also mirrored in local storage as _fs_uid; both are cleared when you withdraw).
fs_luaFullStory30 minutesThird party — last activity in a recording session (also mirrored in local storage as _fs_lua; both are cleared when you withdraw).

Marketing Cookies

The Dashboard does not use cookies to serve advertising. We use one marketing-automation tool that sets a cookie to identify visitors. It is set only if you allow the Marketing category, is deleted if you withdraw, and the page reloads on withdrawal so the tool stops. No advertising or ad-personalisation signals are enabled.

CookieProviderDurationType
prism_69245552ActiveCampaign (via Google Tag Manager)30 daysThird party — identifies the visitor for marketing automation.

Browser Storage

The Dashboard stores some working state in your browser rather than in cookies. None of this storage is analytics, none is shared with any third party, and none leaves your device. Strictly necessary storage exists only because of an action you took. Local storage persists until you clear your site data, except that signing out removes the sign-in target, the project you were working in, your saved transaction and transfer filters and your recent searches; session storage is cleared when you close the tab.

CategoryKeysWhat is stored
Strictly necessary — sign-in5 + session storageSign-in redirect target, sign-in flow and source, the project you were working in, your answer to a one-time feature prompt; in session storage, a pending action to resume after sign-in, an invitation credential held for up to 30 minutes, and WorkOS sign-in helpers removed when sign-in completes.
Strictly necessary — flow flags3Single-use flags that finish an action you started before a redirect.
Strictly necessary — layout & display18Theme, sidebar state, table columns and ordering, sort order, panel width, developer mode.
Strictly necessary — filters & recall12 + one per projectSaved filters, recent searches, favourite and recent projects and requests, selected explorer and network, networks last used per project.
Strictly necessary — dismissed notices10Records that a banner, announcement or disclaimer has been dismissed.
Strictly necessary — work in progress6Partially built alert rules, a display setting for the Virtual TestNet wallet view, and the wallet addresses and test network sessions used in simulations.
Strictly necessary — tool settings3Settings for the built-in RPC client, the last-used contract read/write tab, a cache of token search results.
Functional — usage counter1Counts how often you have used the RPC request builder, to stop showing its hint. Never transmitted.

Pages that offer wallet connection load the WalletConnect and Coinbase Wallet SDKs only after you choose a wallet. Choosing WalletConnect also starts Reown AppKit, which reports the page address to WalletConnect's telemetry, fetches wallet listings and contacts the relay once a wallet pairs. Both SDKs keep connection state in browser storage, including WalletConnect's IndexedDB database; it is removed when you disconnect.

Other providers that receive data (not consent-gated)

The following providers are necessary to run, secure, and support the service and are not analytics. They rely on our performance of the contract with you or our legitimate interest in operating and improving a secure service.

ProviderPurposeRegion
SentryError reports (stack traces, page addresses, pseudonymous ID; no name or email) and one anonymous session record per page load, used to see which release is in use and whether it crashes. Contacts Sentry on every page load.United States
PylonSupport chat — name, email and conversation content; loads only when you open support. Keeps your chat language and a connection setting in browser storage. Conversations are deleted within 30 days of a deletion request; transfers rest on the EU Standard Contractual Clauses in Pylon's data processing agreement.United States
StripePayments, billing and payment fraud prevention.United States
WorkOSAuthentication and account data.United States
Cloudflare (Turnstile)Bot and abuse detection on protected forms; runs only when such a form is submitted.Global edge network (EU and US)
WalletConnect (Reown), Coinbase Wallet SDKWallet connection, only after you choose a wallet; WalletConnect's telemetry and relay then receive the page address.Provider-operated, global
05

How to Control and Delete Cookies

1. Using the consent tools. Optional cookies are off until you opt in, and you can change or withdraw your choice at any time: on the Website from the "Cookie preferences" button on tenderly.co/cookies, on the Dashboard from Account → Security → Cookie Settings or, while signed out, from the Tenderly menu at the top left.

2. Using your browser. Most cookies can be disabled through your browser settings, usually under the "Help", "Tools" or "Privacy" menus. Disabling a cookie does not delete it from your browser unless you do so manually.

3. Cookies set in the past. If you withdraw consent, we stop using the disabled cookies to collect further information. On the Dashboard, the cookies of the withdrawn category are deleted; on the Website, cookies already set may remain until they expire and can be deleted through your browser. Information collected before your change may already have been processed.

06

Changes and contacts

Changes to our Cookies Policy

This Cookie Policy can be changed from time to time. If we change anything important about this Cookie Policy, we will notify you through a pop-up on the Website or the Dashboard in a reasonable time period prior to and following the change.

Contact Information

You can contact us by email at support@tenderly.co.

Close the gap between assumptions and outcomes.

Run blockchain systems with clarity, control, and predictability from a single operational platform.

Book a demoExplorer
Newsletter
Subscribe to our newsletter

Get tips, technical guides, and best practices. Once a month.

Industries
DeFiFinancial InstitutionsNetworks
Use cases
Financial ModelingIncident ManagementCI/CD & StagingSandbox environmentsSupport Operations
Products
SimulatorConsoleMonitorNodePricing
Resources
DocumentationChangelogBlogCase StudiesAPI ReferenceMCP ServerStatus PageGitHub
Company
AboutCareersContact UsBrand Assets
© 2026 Tenderly·All systems operational
PrivacyTermsCookiesSitemap

We use cookies to improve your experience and measure site usage. See our cookies policy for details.

Cookie preferences

Choose which cookies we can use. Necessary cookies are always on. See our cookies policy for the full list.

Necessary Always on

Required for the site to work — security, load balancing and remembering your choices. These can't be switched off.

Google Analytics, Matomo and FullStory — help us understand how the site is used so we can improve it.

Google Ads — lets us measure our campaigns and show relevant ads. Off means no ad personalization.