We keep this short because we keep tracking minimal.
Last updated: July 2026
Walilock is a zero-knowledge password manager, and that principle extends to our website. We use the smallest set of cookies and local storage needed to keep you signed in, complete a purchase, and remember basic preferences — nothing more. This page explains exactly what we store, why, and how you can control it.
The short version: essential and functional cookies only. We do not use third-party advertising cookies, we do not track you across other websites, and we do not sell your data — ever.
A cookie is a small text file a website stores in your browser. On each request, the browser sends the cookie back so the site can recognize your session — for example, to keep you logged in as you move between pages.
Local storage (and sessionStorage) is a related browser mechanism that lets a site save small values on your device without sending them to a server on every request. We use it for lightweight preferences, like remembering your theme.
Both are stored on your device. Neither can read your vault: your encryption keys never leave your device, and nothing we store in a cookie can decrypt your data.
We use two categories only:
When you check out, payment is handled by Stripe on checkout.stripe.com. Stripe sets its own cookies on that page to process the payment securely and prevent fraud. Those cookies are governed by Stripe's own privacy and cookie policies, and Walilock never sees your card details.
| Name / Purpose | Type | Provider | Duration |
|---|---|---|---|
| wl_sessionAuthentication / session token that keeps you securely signed in to the account area after login. | Essential | Walilock (first-party) |
Session — expires when you log out or the token lifetime ends (~1 hour) |
| wl_csrfSecurity token that protects sign-in and form submissions against cross-site request forgery. | Essential | Walilock (first-party) |
Session |
| wl_themeRemembers your interface preference (dark / light) so the site loads the way you left it. | Functional | Walilock (local storage) |
Persistent — until you clear it or change the setting |
| __stripe_mid / __stripe_sidSet by Stripe during checkout to process your payment securely and detect fraud. | Essential | Stripe (checkout.stripe.com) |
Session & up to 1 year (Stripe-controlled) |
Cookie names are stable but may change as we update the site; the purposes and categories above are what matter and will always be honored.
To be explicit:
If that ever changes, we will update this policy first and never quietly switch on tracking. See our Privacy Policy for the full picture of how we handle data.
You are always in control. Every major browser lets you view, block, or delete cookies and clear local storage from its settings — usually under Privacy or Site data:
Note: because we only use essential and functional cookies, blocking or deleting essential cookies will break core features — you may not be able to stay logged in or complete checkout. Functional cookies can be cleared safely; you will just lose remembered preferences like your theme.
If we change the cookies we use, we will update this page and revise the "Last updated" date above. Material changes — for example, introducing any new category of cookie — will be announced clearly before they take effect. We encourage you to check back occasionally.
Questions about this policy or how we handle cookies? We are happy to help. Reach our privacy team at privacy@walilock.com, or use the form on our contact page.