Skip to content

Legal

Cookie policy

KeyValt uses only what is strictly necessary to keep you signed in and secure.

Last updated: 4 October 2026

NamePurposeDuration
__Host-kv_session / kv_sessionKeeps you signed in. HttpOnly, Secure, SameSite=Lax.Up to 30 days (7 days idle)
kv_oauthProtects “Sign in with Google” against cross-site request forgery. Only set if you use Google sign-in.10 minutes
__Host-kv_admin / kv_adminStaff only: keeps KeyValt employees signed in to the admin console.Up to 12 hours (2 hours idle)

Local storage

We store your theme preference, dismissed announcements and whether you dismissed the cookie notice in your browser’s local storage. Your vault is never stored unencrypted in the browser; the unlocked vault exists only in memory and is cleared when it locks.

No tracking

We do not use advertising cookies, cross-site trackers or third-party analytics cookies. Razorpay may set its own cookies inside the secure checkout window when you make a payment.