Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free
Legal

Cookie and browser storage policy

Last updated: July 14, 2026. A practical overview of how CanaryVaults uses cookies, session state, and related browser storage across public and authenticated flows.

Types of browser-side storage used by the app

This page is written as an operator-facing summary rather than a long legal document so users can understand why storage exists in the first place.

Essential session cookies

Authentication and account continuity

Three first-party cookies keep you signed in: canaryvaults_session, canaryvaults_session_token, and canaryvaults_session_refresh. All are HttpOnly and Secure, live at most 7 days, and are strictly necessary — the app cannot keep a session without them.

Product preference state

Lightweight UI memory

Some localStorage keys preserve interface choices such as tabs, toggles, or the last-used view so the product feels continuous. They never leave your browser except as part of the pages they configure.

First-party measurement

Analytics and journey understanding

A first-party analytics identifier (canaryvaults:analytics-session-id) is held in localStorage and sent with UX events to our own /api/analytics endpoint. No third-party analytics, advertising, or cross-site tracking scripts are loaded, and no analytics cookies are set.

Important notes

What users should expect

  • No third-party advertising, analytics, or cross-site tracking cookies are set anywhere on the product.
  • There is currently no cookie consent banner: the only cookies set are strictly necessary session cookies, which do not require consent. A consent control for the first-party analytics identifier in localStorage is under review.
  • Security-sensitive session handling takes priority over convenience when the two conflict.
  • Clearing browser storage signs you out, resets saved preferences, and removes the analytics identifier.
  • Some storage may be set by infrastructure or authentication providers needed to operate the app.
User actions

How to manage storage-related concerns

  • Clear browser cookies or site data directly in the browser settings — this also removes the first-party analytics identifier.
  • Sign out and restart a session if account state appears stale.
  • Review privacy and support pages if you need context on storage or data-handling expectations.
  • Email hello@canaryvaults.com if browser storage behavior appears incorrect, or security@canaryvaults.com if it looks security-sensitive.

Related trust pages

Browser storage is only one part of the trust picture. Privacy, security, and support pages explain the rest of the product expectations.

PrivacySecuritySupportAccount settings
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS