Kistkeep

Legal

Cookie policy

Last updated 9 September 2026. What we use, why, and how to control it.

1. What cookies are

Cookies are small text files a website stores on your device to remember information between visits, such as whether you're logged in. Similar technologies include local storage and session storage, which we refer to collectively as "cookies" in this policy for simplicity.

2. Cookies on this marketing website

This website (the one you're reading now) uses only strictly necessary cookies required for basic functionality, and does not currently set any analytics, advertising, or cross-site tracking cookies. We don't run third-party ad networks or tracking pixels here.

If that ever changes, for example by adding privacy-respecting analytics to understand which pages are useful, we will update this policy first and provide a way to opt out where required by law.

3. Cookies in the Kistkeep application

The Kistkeep web application (app.kistkeep.com, or your Herd development URL) is a separate service from this marketing site, and uses cookies that are strictly necessary for it to function: a secure, encrypted session cookie that keeps you signed in, and a CSRF-protection cookie that guards against cross-site request forgery attacks. Neither is used for advertising or cross-site tracking.

We also store a small number of items in your browser's local storage, not cookies, on your own device: local preferences such as your light/dark theme choice, and a security device fingerprint. The device fingerprint is generated by the open-source FingerprintJS library, runs entirely in your browser, and is used only to detect and prevent fraudulent or automated account creation and abuse. It is strictly necessary for security, is not sent to any third party, and is not used for advertising or analytics.

4. Payment processing cookies

When you subscribe to a paid plan, our payment processor Stripe may set its own cookies during the checkout flow, for fraud prevention and to process your payment securely. These are governed by Stripe's own privacy and cookie practices, not ours; see stripe.com/privacy for details.

5. Bot protection

Sign-up and other forms on the Kistkeep application are protected by Cloudflare Turnstile, a privacy-preserving alternative to a traditional CAPTCHA. Turnstile does not set cookies and does not track you across sites. It is used only to tell humans and automated bots apart.

6. How long cookies last

Session cookies (like the app login cookie) are deleted automatically when you close your browser, or expire after a period of inactivity for security. We don't set long-lived tracking cookies on this marketing site.

7. Managing cookies

Because this marketing site sets no non-essential cookies, there's nothing to opt out of here. For the Kistkeep application, the session cookie is required for the service to work; disabling it in your browser will simply log you out. You can control or delete cookies at any time through your browser's settings, most browsers let you view, block, or delete cookies on a per-site basis.

8. Do Not Track

Since we don't set tracking cookies on this site in the first place, we don't currently process browser "Do Not Track" signals differently, there's nothing being tracked to stop.

9. Changes to this policy

We may update this policy if our use of cookies changes. Material changes will be reflected here with an updated date, and where legally required, we'll notify you separately.

10. Contact us

Questions about this policy can be sent to [email protected].