Lifevault sets four cookies. All four are strictly necessary, none of them track you, and that is why you have never seen a consent banner on this site.
Consent is required for cookies that are not strictly necessary for a service you asked for. We do not set any, so there is nothing to consent to. A banner would be theatre.
Keeps you signed in. HttpOnly, Secure, SameSite=Lax. Expires when you sign out, or after 30 days of inactivity.
Ensures a form submission came from this site. Secure, SameSite=Strict. Expires with the session.
Remembers whether you chose light or dark. Stored in your browser's local storage rather than sent to us. Persists until you clear site data.
Set by Stripe on the checkout page only, to detect fraudulent payments. Not set unless you open checkout. Expires after 1 year.
No advertising cookies, no cross-site trackers, no third-party analytics, no social media pixels, no session recording, and no fingerprinting. We do not embed Google Analytics or any equivalent on this site.
Aggregate traffic figures come from server logs, which record an IP address for 90 days for security purposes and are never joined to an account for analytics.
You can block or delete cookies in your browser settings. Blocking the session and CSRF cookies will prevent you from signing in — they are the mechanism by which signing in works. Blocking the theme preference simply means the site follows your system setting each visit.
Note that the mobile app does not use cookies at all, so a browser setting has no effect on your check-in.
If we ever add a cookie that is not strictly necessary, we will ask for consent before setting it and announce the change 30 days ahead. Questions: privacy@lifevault.example.