Cookies Policy

Last updated: 10 June 2026

Operated by KRYPTHQ LTD, a company registered in England and Wales (company number 17254962), with registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.

This Cookies Policy explains how Krypt ("we", "us", or "our") uses cookies and similar technologies on krypthq.com and within the Krypt application (the "Service"). It should be read alongside our Privacy Policy.


1. What are cookies?

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, to make them work more efficiently, and to provide information to site operators. Similar technologies include local storage, session storage, and pixels — references to "cookies" in this Policy include those technologies where relevant.


2. How we categorize cookies

We group cookies into the following categories, in line with guidance from the UK Information Commissioner's Office (ICO):

  1. Strictly necessary — required for the Service to function (e.g., authentication, security). These do not require your consent under UK PECR / GDPR rules but we still tell you about them.
  2. Functional — remember your preferences and choices (e.g., theme, language).
  3. Analytics — help us understand how the Service is used so we can improve it. These are only set with your consent.

We do not use advertising or tracking cookies for cross-site behavioral advertising.


3. Cookies we use

The exact set of cookies you encounter depends on which pages you visit and which features you use. The table below lists the main cookies and similar technologies in use, grouped by purpose.

3.1 Strictly necessary

Cookie / tokenSet byPurpose
__sessionClerkMaintains your authenticated session.
__client_uatClerkTracks user authentication state.
__clerk_db_jwtClerkShort-lived authentication token.
__stripe_midStripeFraud prevention during checkout.
__stripe_sidStripeFraud prevention during checkout.
CSRF token (in-app)KryptProtects forms and API calls from cross-site request forgery.

[REVIEW] Confirm exact Clerk and Stripe cookie names against current documentation at launch — these vary by version and configuration.

3.2 Functional

Cookie / tokenSet byPurpose
krypt_themeKryptRemembers your dark/light theme preference.
krypt_last_workspaceKryptRemembers the workspace you last viewed.

[REVIEW] Confirm or update functional cookie names to match what the application actually sets at launch.

3.3 Analytics (consent-based)

[REVIEW] We are evaluating analytics providers. The most likely options are:

Cookie / technologySet byPurpose
(Cookieless)PlausiblePrivacy-friendly aggregate usage analytics. Plausible does not use cookies and does not collect personal data, so no consent is required, but we disclose its use here for transparency.
ph_* cookies / local storagePostHogProduct analytics, feature usage, and session-level behavior. Set only with your consent.

If we choose Plausible (cookieless) we will not show a consent banner solely for analytics. If we choose PostHog or another cookie-based analytics provider, we will request consent before any analytics cookies are set.


4. How we obtain your consent

Strictly necessary cookies are set without consent because they are essential to provide the Service you have requested.

For functional and analytics cookies that require consent, we will:

  1. Show a cookie banner on first visit.
  2. Allow you to accept or reject non-essential cookies.
  3. Allow you to change your choice at any time via a "Cookie settings" link in the footer of the website.

[REVIEW] If a cookie banner is not yet implemented at launch, this section must be updated to reflect the actual user experience.


5. How to control cookies

You can also control cookies directly through your browser. Most browsers allow you to:

  • See which cookies are stored and delete them individually or all at once.
  • Block third-party cookies.
  • Block cookies from specific sites.
  • Block all cookies.
  • Delete all cookies when you close the browser.

Useful links:

Please note that disabling strictly necessary cookies (such as the authentication cookies set by Clerk) will break core features of the Service, including the ability to sign in.


6. Third-party cookies

Some cookies on the Service are set by third parties — most notably Clerk (authentication) and Stripe (billing and fraud prevention). These providers act as our sub-processors and are bound by their own privacy policies and the contractual terms we have with them.

[REVIEW] Add links for any analytics provider chosen at launch (e.g., Plausible, PostHog).


7. Changes to this Policy

We may update this Cookies Policy from time to time. The "Effective date" at the top of this document indicates when it was last revised. Material changes will be notified via the Service or by email where appropriate.


8. Contact

Questions about cookies?

Email: hello@krypthq.com Operated by: KRYPTHQ LTD, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF