What is the _hash cookie?
We don't have a vendor description for this cookie yet, but our scan shows it's set by a third-party domain we haven't identified, and it typically lasts 13 months. It's listed as unclassified.
Our October 2026 scan found it on 12 sites (0% of the 2,450 we scanned), set before any consent.
- Purpose
- Unclassified
- Set as
- First-party on 83% of sites, third-party on 17%
- Typical lifetime
- 13 months
Sites that set _hash before consent
The highest-ranked 12 of 12 sites.
- psu.edu4 tracking companies
- msu.edu10 tracking companies
- ucdavis.edu7 tracking companies
- arizona.edu9 tracking companies
- colorado.edu8 tracking companies
- vt.edu10 tracking companies
- uwaterloo.ca7 tracking companies
- oregonstate.edu7 tracking companies
- umass.edu13 tracking companies
- iu.edu15 tracking companies
Show 2 more sites
- udel.edu9 tracking companies
- vanderbilt.edu5 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop _hash being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.