Cookie Policy
See also: Privacy Policy
1. What Are Cookies
Cookies are small text files placed on your device by a website. Local storage is a similar browser mechanism that stores data without expiration dates. litwarden uses both, and this policy covers all of them.
We use a minimal set — only what's needed for the site to function and, with your consent, for anonymous usage statistics.
2. Strictly Necessary (no consent required)
These are required for the site to work. They cannot be disabled.
| Name | Type | Purpose | Duration |
|---|---|---|---|
litwarden_session |
Cookie | Authentication session for the admin panel. HMAC-signed token containing username and role. Only set when you log in. | Browser session |
_wn |
Cookie | One-time WebAuthn nonce used during the passkey login ceremony. Deleted immediately after authentication completes. | 5 minutes |
3. Functional (preferences)
These remember your preferences. They don't track you across sites.
| Name | Type | Purpose | Duration |
|---|---|---|---|
lang |
Cookie | Your language preference (English or Estonian). Sent to the server so content-heavy pages are served in the right language. | 1 year |
theme |
localStorage | Your light/dark theme preference. Never sent to the server. | Until cleared |
cookie-consent |
localStorage | Records whether you accepted or declined analytics cookies, so we don't ask again. | Until cleared |
sup-banner-closed |
localStorage | Remembers that you dismissed the support banner at the bottom of the page. | Until cleared |
4. Analytics (consent required)
These cookies are set only after you click "Accept" on the cookie consent banner. If you decline or ignore the banner, no analytics cookies are set and no data is sent to Google.
| Name | Type | Purpose | Duration |
|---|---|---|---|
_ga |
Cookie | Google Analytics. Generates a random ID to distinguish unique visitors. Does not contain personal information. | 2 years |
_ga_9DVF951LZF |
Cookie | Google Analytics. Maintains session state (which pages you visited in one session). | 2 years |
We use Google Analytics to understand which pages are visited and where visitors come from. IP addresses are anonymized. We do not use Google Analytics for advertising, remarketing, or profiling.
5. Third-Party Services
| Service | Purpose | Cookies | Privacy policy |
|---|---|---|---|
| Google Analytics | Anonymous usage statistics | _ga, _ga_* |
Google Privacy |
| Cloudflare | CDN, DDoS protection, TLS | May set __cf_bm for bot detection |
Cloudflare Privacy |
| Google Fonts | Typography (Inter, Source Serif 4) | None (loaded via CSS, no tracking) | Google Privacy |
6. How to Manage Cookies
Change your analytics consent
To withdraw consent for analytics cookies, clear your browser's local storage for
this site (this removes the cookie-consent item) and reload the page.
The consent banner will reappear and you can choose "Decline."
Browser settings
You can delete or block all cookies through your browser:
Note: blocking strictly necessary cookies will prevent the admin panel from working. The public dashboard does not require any cookies.
7. Changes
This policy may be updated when we add or remove cookies. The "last updated" date at the top will reflect changes.