Cookies and local storage
Last updated 4 October 2026. Part of our privacy notice.
Why there is no cookie banner
There is nothing to ask you about. We set no analytics, advertising, tracking or profiling storage of any kind, and this site loads no script, stylesheet, font or image from any third party. Everything in the table below is either required to sign you in and keep you signed in, or is a preference you set yourself on a device you control.
Under the Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 6 — as rewritten by the Data (Use and Access) Act 2025 with effect from 5 February 2026, which moved the exceptions into the new Schedule A1 — consent is not required for storage that is strictly necessary to provide a service the user has requested, or solely to carry out a transmission. The sign-in cookies are strictly necessary: without them you cannot be signed in at all. The two local-storage preferences fall in the same place: they exist only because you asked for that appearance or that workspace, they are never read by us, and they never leave your browser.
If we ever add anything that is not strictly necessary, we will ask you first, with a real choice and a way to change your mind. We have no plans to.
Everything we set
| Name | Type | What it is for | How long | Set when |
|---|---|---|---|---|
| __convexAuthJWT | Cookie | Keeps you signed in. It is the token that proves to the server which account is making a request. | Until it expires or you sign out | When you sign in |
| __convexAuthRefreshToken | Cookie | Lets your session be renewed without making you type your password again. | Until it expires or you sign out | When you sign in |
| __convexAuthCookieForRouterCacheInvalidation | Cookie | Tells the app to stop showing you pages cached for a signed-out visitor once you have signed in. | Session | When you sign in |
| __convexAuthOAuthVerifier | Cookie | Short-lived security value that stops a sign-in being hijacked part-way through. We only use email and password sign-in, so in practice this is rarely set at all. | Minutes | During a sign-in attempt |
| admin_token | Cookie | Only ever set for the site operator, and only on /admin, when they open a signed administration link. It is never set for a customer. | One hour | When an operator opens a signed admin link |
| cognivault.theme | Local storage | Remembers whether you chose the light or dark appearance, so the page does not flash the wrong one before it loads. | Until you clear your browser storage | When you change the appearance setting |
| cognivault.workspaceId | Local storage | Remembers which of your workspaces you were last working in, so the app opens where you left off. | Until you clear your browser storage | When you switch workspace |
Nothing at all is set before you sign in. If you visit this site and never sign in, your browser stores nothing from us beyond whatever it caches for any website.
Turning them off
You can clear or block all of them in your browser settings. If you block the sign-in cookies you will not be able to sign in, because they are the mechanism by which you are signed in — there is no way around that. Clearing the two local-storage preferences simply resets the appearance to follow your system and the app to open on your first workspace.
Asking us about this
Use the form on our contact page or email info@nikah-ai.com. Nikah AI Ltd is the data controller, registered with the Information Commissioner’s Office under ZC176381.