This FAQ explains the Service Cookies used in the Text app and LiveChat Services, including the widget cookies __lc_cid and __lc_cst cookies, which supports widget functionality and Client SSO.
For the purposes of this FAQ, "Services" means the Text app and LiveChat applications and their related widget functionality.
What are __lc_cid and __lc_cst cookies?
The __lc_cid and __lc_cst cookies are Service Cookies used by the Text app and LiveChat Services to support customer identification, secure sessions, widget functionality, and Client SSO (Single Sign-On).
Specifically:
__lc_cid stores a unique customer identifier (customer_id) generated by the Services
__lc_cst stores a secure cryptographic token used to verify the customer’s identity
These cookies help:
keep chat sessions active
recognize returning customers
restore conversation history
support secure customer and teammate interactions across sessions
In certain authorization scenarios, an additional technical cookie, __oauth_redirect_detector, may also be used temporarily to detect redirect loops and support authentication.
What type of cookies are these?
These cookies are generally classified as:
Essential cookies
Authentication cookies
Service infrastructure cookies
They aren't used for advertising, cross-site tracking, or third-party behavioral targeting. Clients should classify these cookies based on their own setup and applicable privacy laws.
Are __lc_cid and __lc_cst cookies necessary for the Services?
Yes. These cookies support core service functionality and security, including:
customer authentication
maintaining chat sessions
restoring conversation history
reconnecting returning customers
preventing unauthorized access to conversations
enabling Client SSO
Without these cookies, certain functionality of the Services may not work properly.
What happens if cookies are blocked or disabled?
Some features of the Services rely on essential Service Cookies or similar technologies to function correctly.
If these cookies are blocked, disabled, or deleted, some functionality may be unavailable or behave unexpectedly.
Depending on the Client’s implementation, this may include:
customers being asked to authenticate more frequently
Agent’s sessions ending unexpectedly
returning visitors not being recognized
conversation history not being restored
widgets behaving as if the visitor is new
certain security protections becoming unavailable
Clients should carefully evaluate the impact of blocking essential Service Cookies when configuring their consent mechanism.
What happens if an Agent blocks cookies?
Some Agent-facing features of the Services rely on essential Service Cookies.
If an Agent blocks or deletes these cookies, they may experience issues such as:
repeated sign-in requests
loss of authenticated sessions
interrupted workflows
reduced functionality of certain features
The exact impact depends on the browser configuration and the functionality being used.
Do these cookies contain personal data?
The cookies themselves don't store direct personal data such as names or email addresses.
However:
__lc_cid contains a unique identifier generated by the Services,
this identifier may be associated with customer activity within the Client’s environment.
Under some privacy laws, these identifiers may be considered Personal Data. Each Client should independently assess this based on its implementation and applicable legal requirements.
Who receives these cookies?
Depending on the Client’s implementation, Service Cookies may be stored in the browser of:
visitors interacting with a Client's website or application through the widget
authenticated customers using Client SSO
Agents accessing the Services, or
other users interacting with the Services made available by the Client
The cookies used may differ depending on the functionality enabled by the Client and the way the Services are implemented.
Who processes data related to these cookies?
Data related to these cookies may be processed by the Client using the Services and Text as the service provider.
Text processes this data to:
provide and secure the Services
maintain authenticated sessions
enable Client SSO
support widget functionality
maintain reliability and security of the Services
Text doesn't use these cookies for advertising, third-party data sales, or cross-Client user targeting.
Does Text use the data for analytics or product improvement?
These cookies are primarily used for technical, authentication, security, and core service functionality.
The identifier stored in __lc_cid may allow recognition of returning customers and continuation of conversation history within a Client's environment.
Text may also use Services Data generated in connection with the Services for:
operational analytics
service reliability and security
product improvement
feature development
optimization of the Services
Where appropriate, such analytics are performed using aggregated and anonymized data and are not used to identify individual End-Users or to perform across-Client targeting.
Are these cookies used for advertising or marketing profiling?
No. These cookies aren't used for:
advertising
third-party marketing
cross-site advertising
cross-Client targeting
independent marketing profiling of end-users
Do these cookies require user consent?
Cookie consent requirements depend on:
applicable laws and regulations
the Client's implementation
how the cookies are used
the Client's chosen consent model
In many jurisdictions, cookies required for authentication, security, or core service functionality may not require opt-in consent.
Each Client should independently assess its obligations applicable under laws, including where relevant GDPR, the ePrivacy Directive, CCPA other applicable local laws.
Clients are responsible for:
classifying cookies used on their websites or apps
implementing appropriate consent mechanisms
maintaining compliant Cookie Policies and Privacy Notices
Should Clients include these cookies in their Cookie Policy?
Yes. Clients using the Services should disclose these cookies in their Cookie Policy or equivalent privacy documentation.
Where applicable, this documentation should include:
cookie names
purposes
expiration periods
cookie categories
information about the service provider
whether the cookies are required for the provision of the Services
Clients should also make sure their disclosures accurately reflect the way they use and configure the Services within their own environment. For implementation details, see here.
How does Client SSO work?
Implementation details are available here.
Where can I learn more about Text's use of cookies and personal data?
For additional information, please refer to:
Cookie Policy: Information about the categories of cookies and similar technologies used by Text, their purposes, retention, and cookie preference management.
Privacy Policy: Information about how Text processes Personal Data, legal bases for processing, recipients, international data transfers, retention periods, and your privacy rights.
Client Authorization documentation: Technical implementation details regarding Client SSO and Service Cookies: