Legal
Cookie policy
KeyValt uses only what is strictly necessary to keep you signed in and secure.
Last updated: 4 October 2026
| Name | Purpose | Duration |
|---|---|---|
__Host-kv_session / kv_session | Keeps you signed in. HttpOnly, Secure, SameSite=Lax. | Up to 30 days (7 days idle) |
kv_oauth | Protects “Sign in with Google” against cross-site request forgery. Only set if you use Google sign-in. | 10 minutes |
__Host-kv_admin / kv_admin | Staff only: keeps KeyValt employees signed in to the admin console. | Up to 12 hours (2 hours idle) |
Local storage
We store your theme preference, dismissed announcements and whether you dismissed the cookie notice in your browser’s local storage. Your vault is never stored unencrypted in the browser; the unlocked vault exists only in memory and is cleared when it locks.
No tracking
We do not use advertising cookies, cross-site trackers or third-party analytics cookies. Razorpay may set its own cookies inside the secure checkout window when you make a payment.