Cookie Policy
How KavinoraOS uses cookies and similar technologies to authenticate users and improve the platform experience.
Last updated: 30 July 2026
1. What Are Cookies?
Cookies are small files stored on your browser that remember information about your visit. KavinoraOS uses cookies to authenticate users, remember preferences, and optionally track usage analytics.
2. Cookies We Use
Essential Cookies (Always Required)
auth_token
- Purpose: JWT authentication token for session management
- Duration: 8 hours (expires after inactivity)
- HttpOnly: Yes (secure, not accessible via JavaScript)
- Path: / (all pages)
- Scope: Required to stay logged in
refresh_token
- Purpose: Refresh token used to obtain a new auth_token without requiring re-login
- Duration: 7 days
- HttpOnly: Yes (secure, not accessible via JavaScript)
- Path: /api/auth (only sent to authentication endpoints)
- Scope: Required for persistent login sessions
Google OAuth Cookies
Google Sign-In
- Purpose: When you sign in with Google, Google may set its own cookies to manage the OAuth authentication flow
- Duration: Varies (set by Google, not by KavinoraOS)
- Controller: Google LLC — see the Google Privacy Policy
- Scope: Only set during the Google sign-in flow; not required if you use email/password or passkey authentication
Analytics Cookies (Optional)
_ga, _gid (Google Analytics)
- Purpose: Track page views and user engagement (optional)
- Duration: 2 years (_ga), 24 hours (_gid)
- HttpOnly: No (visible to JavaScript)
- Requires: Cookie consent banner acceptance
- Data shared: Google Analytics (see their privacy policy)
Preference Storage (localStorage, Not Cookies)
Theme Preference
- Purpose: Remember light/dark mode preference
- Storage: localStorage (not a cookie)
- Contains: "light" or "dark" (non-personal)
3. Cookie Consent
When you first visit KavinoraOS, you will see a cookie consent banner. You can:
- Accept All: Enable auth cookies + Google Analytics
- Only Essential: Enable only auth cookies (analytics disabled)
- Customise: Choose exactly which cookies to enable
Your choice is stored in cookie_consent_version (localStorage). You can change your preferences at any time.
4. How to Manage Cookies
Browser Settings
Most browsers allow you to control cookies via settings:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Firefox: Preferences → Privacy → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies and website data
- Edge: Settings → Privacy → Cookies and other data
Disable Analytics
To opt out of Google Analytics tracking, click the cookie preferences button or visit the Google Analytics Opt-out Extension.
Disable All Non-Essential
Disabling non-essential cookies will not affect your ability to use KavinoraOS. You may see less personalised behaviour and analytics will not be collected.
5. Third-Party Cookies
We do not control third-party cookies set by external services. The following third parties may set cookies when you use KavinoraOS:
- Google Analytics: For usage analytics (optional, consent-based). See the Google Privacy Policy.
- Google OAuth: For "Sign in with Google" authentication. See the Google Privacy Policy.
6. Data Retention
- auth_token: Expires after 8 hours or on logout
- refresh_token: Expires after 7 days or on logout
- Analytics: Aggregated and anonymised; no PII retained
- Preferences: Stored locally until cleared by user
7. Do Not Track
If your browser has "Do Not Track" enabled, Google Analytics will respect that signal and not track your activity.
8. Policy Changes
We may update this cookie policy as features evolve. Changes will be notified via email or banner notification at least 14 days before they take effect.
9. Contact
Questions about cookies? Contact us at:
Kavinora Technologies Ltd, 60 Tottenham Court Road, Office 1215, Fitzrovia, London, W1T 2EW, United Kingdom