Cookie Policy
The minimal set of cookies and local storage Nocturne relies on — and the tracking we deliberately don't do.
Overview
This Cookie Policy explains how Nocturne uses cookies and similar local storage technologies. We take the same minimalist approach here as everywhere else: we use only what is required to sign you in and keep your vault working.
Strictly necessary cookies
These cookies are essential and cannot be switched off without breaking core functionality:
- nocturne-vault-warm — a short-lived flag (about one hour, SameSite=Strict) indicating your vault has been unlocked this session, so the app doesn't lock you out mid-task
- Supabase authentication cookies — secure tokens that keep you signed in and authorize requests to your encrypted blobs
None of these cookies contain your passphrase, your keys, or any decrypted content.
What we don't use
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile you across the web. We do not sell or share cookie data with advertisers.
Local storage and IndexedDB
Most of Nocturne's state lives on your device, not in cookies. We use browser local storage and IndexedDB to hold vault metadata, wrapped (encrypted) key material, and cached on-device models. This data stays on your device and is never transmitted in readable form.
Managing cookies
You can clear or block cookies through your browser settings. Note that clearing Nocturne's cookies or local storage will sign you out and lock your vault — you will need your passphrase to unlock it again. Blocking strictly necessary cookies will prevent the app from functioning.
Changes to this policy
We will update this policy if our use of cookies changes. The "Last updated" date above reflects the current version.
Contact
Questions about cookies can be sent to privacy@nocturne.app.
This document is a design artifact for the Nocturne product and is not legal advice.