VaultKey is designed with a minimal storage footprint. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. This policy explains the limited browser storage mechanisms we do use and why.
1. What Are Cookies?
Cookies are small text files stored on your device by a website. They can store information that persists between sessions (persistent cookies) or is cleared when the browser tab/window is closed (session cookies). VaultKey's web application primarily uses browser storage APIs (sessionStorage) rather than traditional HTTP cookies. However, third-party services integrated into VaultKey (specifically Google Firebase) may set cookies of their own.
2. Storage We Use
The following table summarises all browser storage mechanisms used by VaultKey:
| Name / Key | Type | Category | Purpose | Expires |
|---|---|---|---|---|
vk_unlocked |
sessionStorage | Tracks whether your vault is unlocked in the current browser tab. Cleared on tab close or sign out. | Tab session | |
vk_master_password |
sessionStorage | Holds the master password in memory for the active session to derive the encryption key. Cleared on tab close or sign out. | Tab session | |
| Firebase Auth token | IndexedDB / Cookie | Set by Firebase Authentication to maintain your signed-in state with Google. Required for Firestore access. | Up to 1 year (Firebase managed) | |
| Firebase session cookie | HTTP Cookie | Set by Google Firebase to manage your authentication session. Not accessible by VaultKey JavaScript. | Session / Firebase managed |
3. What We Do NOT Use
VaultKey does NOT use: • Advertising or targeting cookies of any kind. • Third-party analytics cookies (e.g., Google Analytics, Hotjar, Mixpanel). • Social media tracking pixels or scripts. • Persistent fingerprinting or cross-site tracking mechanisms. • Any cookies beyond those listed in Section 2. We are committed to a minimal data footprint and will not introduce tracking or advertising storage mechanisms without updating this policy and obtaining appropriate consent where required by law.
4. Third-Party Cookies (Firebase / Google)
VaultKey uses Google Firebase for authentication and data storage. As part of this integration, Google may set cookies or use IndexedDB entries on your device to manage authentication tokens. These are managed by Google and governed by Google's own privacy and cookie policies: • Firebase Privacy: firebase.google.com/support/privacy • Google Privacy Policy: policies.google.com/privacy • Google Cookie Policy: policies.google.com/technologies/cookies VaultKey has no control over the cookies set by Firebase/Google and cannot read or modify them.
5. Managing & Deleting Cookies
You can control and delete cookies and browser storage through your browser settings: • Chrome: Settings → Privacy and security → Cookies and other site data • Firefox: Settings → Privacy & Security → Cookies and Site Data • Safari: Preferences → Privacy → Manage Website Data • Edge: Settings → Cookies and site permissions → Cookies and site data Note that clearing VaultKey's sessionStorage will sign you out of your current vault session. Clearing Firebase authentication data will require you to sign in again with Google. On Android, you can clear app storage via: Settings → Apps → VaultKey → Storage → Clear Data. This will remove all locally stored key material and require biometric re-enrolment on next launch.
6. Consent
The storage mechanisms used by VaultKey fall into two categories:
• Essential / Strictly Necessary: The sessionStorage entries (vk_unlocked, vk_master_password) are strictly necessary for the Service to function. They do not require your consent under ePrivacy regulations as they are essential to a service you have explicitly requested.
• Functional (Firebase): Firebase authentication cookies are necessary for you to use the Google Sign-In feature you have chosen to use. By signing in with Google, you consent to Firebase's use of these functional storage mechanisms.
As we do not use any non-essential, analytical, or advertising cookies, we do not currently present a cookie consent banner. If this changes, we will update this policy and implement appropriate consent mechanisms.
7. Changes to This Policy
We may update this Cookie Policy from time to time. We will notify you of material changes by updating the "Last updated" date above and posting a notice in the app. Continued use of VaultKey after changes are posted constitutes acceptance of the updated policy.
8. Contact Us
For questions about our use of cookies or browser storage, contact us at: Email: support@vaultkey.app
Questions about cookies or storage?
We'll respond within 30 days.