Operated by KRYPTHQ LTD, a company registered in England and Wales (company number 17254962), with registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.
This Cookies Policy explains how Krypt ("we", "us", or "our") uses cookies and similar technologies on krypthq.com and within the Krypt application (the "Service"). It should be read alongside our Privacy Policy.
1. What are cookies?
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, to make them work more efficiently, and to provide information to site operators. Similar technologies include local storage, session storage, and pixels — references to "cookies" in this Policy include those technologies where relevant.
2. How we categorize cookies
We group cookies into the following categories, in line with guidance from the UK Information Commissioner's Office (ICO):
- Strictly necessary — required for the Service to function (e.g., authentication, security). These do not require your consent under UK PECR / GDPR rules but we still tell you about them.
- Functional — remember your preferences and choices (e.g., theme, language).
- Analytics — help us understand how the Service is used so we can improve it. These are only set with your consent.
We do not use advertising or tracking cookies for cross-site behavioral advertising.
3. Cookies we use
The exact set of cookies you encounter depends on which pages you visit and which features you use. The table below lists the main cookies and similar technologies in use, grouped by purpose.
3.1 Strictly necessary
| Cookie / token | Set by | Purpose |
|---|---|---|
__session | Clerk | Maintains your authenticated session. |
__client_uat | Clerk | Tracks user authentication state. |
__clerk_db_jwt | Clerk | Short-lived authentication token. |
__stripe_mid | Stripe | Fraud prevention during checkout. |
__stripe_sid | Stripe | Fraud prevention during checkout. |
| CSRF token (in-app) | Krypt | Protects forms and API calls from cross-site request forgery. |
[REVIEW] Confirm exact Clerk and Stripe cookie names against current documentation at launch — these vary by version and configuration.
3.2 Functional
| Cookie / token | Set by | Purpose |
|---|---|---|
krypt_theme | Krypt | Remembers your dark/light theme preference. |
krypt_last_workspace | Krypt | Remembers the workspace you last viewed. |
[REVIEW] Confirm or update functional cookie names to match what the application actually sets at launch.
3.3 Analytics (consent-based)
[REVIEW] We are evaluating analytics providers. The most likely options are:
| Cookie / technology | Set by | Purpose |
|---|---|---|
| (Cookieless) | Plausible | Privacy-friendly aggregate usage analytics. Plausible does not use cookies and does not collect personal data, so no consent is required, but we disclose its use here for transparency. |
ph_* cookies / local storage | PostHog | Product analytics, feature usage, and session-level behavior. Set only with your consent. |
If we choose Plausible (cookieless) we will not show a consent banner solely for analytics. If we choose PostHog or another cookie-based analytics provider, we will request consent before any analytics cookies are set.
4. How we obtain your consent
Strictly necessary cookies are set without consent because they are essential to provide the Service you have requested.
For functional and analytics cookies that require consent, we will:
- Show a cookie banner on first visit.
- Allow you to accept or reject non-essential cookies.
- Allow you to change your choice at any time via a "Cookie settings" link in the footer of the website.
[REVIEW] If a cookie banner is not yet implemented at launch, this section must be updated to reflect the actual user experience.
5. How to control cookies
You can also control cookies directly through your browser. Most browsers allow you to:
- See which cookies are stored and delete them individually or all at once.
- Block third-party cookies.
- Block cookies from specific sites.
- Block all cookies.
- Delete all cookies when you close the browser.
Useful links:
Please note that disabling strictly necessary cookies (such as the authentication cookies set by Clerk) will break core features of the Service, including the ability to sign in.
6. Third-party cookies
Some cookies on the Service are set by third parties — most notably Clerk (authentication) and Stripe (billing and fraud prevention). These providers act as our sub-processors and are bound by their own privacy policies and the contractual terms we have with them.
[REVIEW] Add links for any analytics provider chosen at launch (e.g., Plausible, PostHog).
7. Changes to this Policy
We may update this Cookies Policy from time to time. The "Effective date" at the top of this document indicates when it was last revised. Material changes will be notified via the Service or by email where appropriate.
8. Contact
Questions about cookies?
Email: hello@krypthq.com Operated by: KRYPTHQ LTD, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF