Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

_GRECAPTCHA Cookie (Google reCAPTCHA) – What It Is

_GRECAPTCHA is a cookie set by Google's reCAPTCHA service, used to help distinguish human visitors from bots on forms and login pages. It is typically classified as strictly necessary, since it supports the security function it was deployed for.

Name
_GRECAPTCHA
Provider
Google reCAPTCHA
Category
Necessary
Type
HTTP cookie
Lifetime
6 months
Consent
No, but it must be listed in the cookie policy
Prevalence
found on 6 Romanian sites scanned by CookieFix

What is the _GRECAPTCHA cookie?

_GRECAPTCHA is an HTTP cookie set by Google when a website integrates the reCAPTCHA service (v2 or v3) to protect contact forms, login pages, comment sections or checkout flows against bots and automated spam.

The cookie is set as soon as the reCAPTCHA widget loads on a page, usually on forms rather than on every page visit. It is set on Google's or recaptcha.net's domain, not on the visited site's own domain.

What data it stores

_GRECAPTCHA stores a Google-generated identifier used to analyze visitor behavior (mouse movements, page interactions) and calculate a risk score indicating the likelihood that the visitor is a bot.

The exact value format is not publicly documented by Google and may change over time. The collected data is sent to Google's servers for processing and anti-fraud analysis.

What it is used for

For the site owner, this cookie enables reCAPTCHA to work as a protection layer against spam, brute-force attacks, and fraudulent form submissions.

For Google, the collected signals help improve bot-detection algorithms globally, across all sites using the service.

Does it require consent?

CookieFix classifies _GRECAPTCHA as strictly necessary when it is used solely for the security function it was implemented for (protecting a form). Strictly necessary cookies do not require prior consent under Article 5 of the ePrivacy Directive and Romania's Law 506/2004, but must still be disclosed in the site's cookie policy.

Site owners should verify whether reCAPTCHA is used only for security or also for broader purposes (such as extended traffic analysis by Google); in the latter case, reclassification and possibly consent may be required.

How to block or delete _GRECAPTCHA

Visitors can delete or block this cookie via browser settings (Chrome, Firefox, Edge, Safari – per-site cookie management), though blocking it may prevent submission of forms protected by reCAPTCHA.

  • Manual deletion from browser privacy settings
  • Blocking via anti-tracking browser extensions
  • Opting out through the site's consent settings, if offered

For site owners, a CMP like CookieFix can automatically block the reCAPTCHA script until consent is given, in cases where the site chooses to treat the component as not strictly necessary in its specific context.

Frequently asked questions

Usually not, when it is used solely to protect a form against bots, as it is considered strictly necessary. It still needs to be listed in the site's cookie policy.

Forms relying on reCAPTCHA for verification may stop working correctly, or visitors may get errors when submitting them.

Its typical duration is around 6 months, based on data collected by the CookieFix scanner across Romanian websites.

The cookie is set directly by Google, on the reCAPTCHA service's own domain, not by the domain of the site embedding the widget.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.