Every cookie and every piece of browser storage lovault.app uses, what it is for and how long it stays.
There is no cookie banner because nothing here tracks you: each item is needed for something you asked for (signing in, a workspace you joined, a view you picked), which the EU and UK cookie rules do not ask consent for.
| Name | What it does | How long |
|---|---|---|
lvu | Keeps you signed in to your lovault.app account. Sent only to the account service, and never readable by the page’s scripts. | 30 days, or until you sign out |
lv | Keeps the site’s owner signed in to the Thought Deployer (/notes). Only the owner gets it. | 180 days, or until signing out |
Both are first-party cookies, set by lovault.app itself. Cloudflare, which delivers the site, may also set a short-lived security cookie of its own (such as __cf_bm, 30 minutes) when it checks traffic for bots. It is used only to tell people from bots.
These stay in your browser and are read by the site’s own scripts; nothing is sent to us unless the row says so. All are first party.
| Name | What it does | How long |
|---|---|---|
| Local storage | ||
lv.w.joined | The online workspaces you opened in this browser, with your pass to each; the pass is sent to that workspace when you open it. | Until you press Remove |
lv.w.mode, lv.w.view | The view you picked for workspaces: grid or list, board or folders. | Until you clear it |
pv-* | The Thought Deployer preview (/deployer): the pages you write there, the page you had open and the theme. | Until you clear it |
lv-user, lv-theme, lv-page | The Thought Deployer (/notes), the owner’s page: the user name, the theme and the page that was open. | Until you clear it |
| Session storage | ||
lv-connect-code | The code of a PC you are connecting, kept while you sign in. | Until the tab closes |
| IndexedDB | ||
lovault-notes | The owner’s Thought Deployer keys; empty for anyone else. | Until the owner signs out |
lovault-rec | A recording made on /notes, until it is uploaded; empty for anyone else. | Until it is uploaded |
The Gateway’s own account page (lovault-gateway.fly.dev) keeps its sign-in token in that page’s local storage as lv_gw until you sign out; the token stops working after 30 days. It is first party, and the Gateway sets no cookies.
Signing out ends the lvu cookie. To remove everything above, clear the cookies and site data for lovault.app in your browser’s settings. Without them you cannot sign in and opened workspaces are not remembered; the rest of the site still works.
Last updated 7 October 2026. See also the Privacy policy.