Cookie policy

Kairo carries no analytics and no advertising. The only cookies are the ones needed to keep you signed in.

Last updated: 23 September 2026

1. The important part, first

There are no analytics, advertising or third-party cookies. We do not use Google Analytics, or pixels, or tracking tools, or any stats library: none is installed. There are no embedded videos, maps or external fonts either.

The support chat on these pages is ours too: another Craft Lab, SLU app, on its own domain. It is not a service bought from anyone, so what you write there does not leave the house. Even so, its code does not load until you open the chat. Section 6 has the details.

That is why you will not see a consent banner: the only cookies we use are the technical ones needed to run the service you asked for, and those do not require consent under article 22.2 of the Spanish LSSI-CE.

2. What a cookie is

A small file the site stores in your browser and that the browser sends back with every request. Among other things, it lets the server know you are still you, so you do not have to type your password on every screen.

3. The cookies we use

All of them are first-party, technical, and marked HttpOnly — the page's JavaScript cannot read them — with SameSite=Lax and, in production, Secure. They are set by the Auth.js authentication library.

NameWhat forLifetime
authjs.session-token
(__Secure-authjs.session-token over HTTPS)
Your session. A signed token saying who you are; without it you would have to sign in on every page.30 days, or until you sign out
authjs.csrf-token
(__Host-authjs.csrf-token over HTTPS)
Protects the sign-in and sign-out forms against forged requests from another site.Until you close the browser
authjs.callback-urlRemembers which page to return to after signing in or out.Until you close the browser
authjs.pkce.code_verifier, authjs.state, authjs.nonceOnly if you sign in with Google or Apple: they secure that round trip so nobody can hijack it. They last the few seconds the operation takes.15 minutes or less

4. Other things the app keeps on your device

These are not cookies — they never travel to the server — but they take up room in your browser and you should know about them. Kairo works offline, and that means keeping the data there.

Preferences and state (localStorage)

KeyWhat it holds
kairo-themeWhether you prefer the light theme, the dark one or the system's. Read before anything is painted, so there is no flash.
kairo-inicioThe section the app opens on, so it starts there without asking the server.
kairo-duenoWho the data stored here belongs to. If someone else signs in, everything previous is wiped before anything is shown.
kairo-colaChanges made offline that have not been sent yet. They carry their owner: one person's changes are never sent under someone else's session.
kairo-listas-abiertas, kairo-recent-searchesWhich lists you have expanded, and your recent searches.
kairo-precarga, kairo-precarga-datosWhen the offline data was last downloaded, so it is not repeated too often.

In sessionStorage, which empties when you close the tab, there are two one-shot flags: kairo:sesion-iniciada and kairo-recarga-trozo, so a start redirect or a reload is not repeated.

The offline copy (IndexedDB)

A local database called kairo with two stores: consultas, holding the tasks, lists and recordings you have already seen, and grabaciones, holding audio recorded with no coverage that is still waiting to upload. What is stored expires after 30 days. Deliberately nothing sensitive goes there: not the search index, not your tokens, not two-factor material, not the security log.

The service worker cache

Three buckets — kairo-v7, kairo-estaticos and kairo-paginas — holding the offline courtesy page, the application files and the screens you have already opened, so they still show without a network.

5. How to get rid of all this

  • Sign out from within the app. That is the clean way: it clears the session cookie, the local copy of your data and the saved pages. What it does not clear is the queue of pending changes, because they are yours and have not been sent yet; it goes out by itself the next time you sign in with a network.
  • From the browser: any browser's privacy settings let you delete or block site cookies and data. Note that deleting the session cookie signs you out, and blocking site storage leaves the app unable to work offline.
  • Uninstalling the app from your home screen, if you installed it: it takes what it had stored with it.

6. The support chat

The chat button on these pages is another app of ours, run by Craft Lab, SLU on its own domain. There is no chat provider in between: what you write reaches us and stays on our servers, the same ones listed in the privacy policy.

The second thing that matters is when it comes into play: its code does not load until you press the button. Until you do, that part never runs and nothing of it is left on your device.

Once you open it:

  • It sets no cookies. We checked: it keeps a conversation id in local storage on that domain, which is what lets you reload without losing what you had typed. Clearing the site data from your browser removes it.
  • What any request carries ends up there — your IP address, the browser and the page you are writing from — plus the message you send and, if you give it to us, your email so we can reply.
  • If you are signed in while reading these pages, we pass your name and email signed, so whoever answers knows who they are talking to — and so nobody can pose as you by typing another name.
  • Inside the app — once you have signed in — the chat does not exist: support there is by email, and that part of the site does not even allow code from another domain to load.

If you would rather not use it, write to info@mykairo.app: it is the same place chat messages end up.

7. Changes

If we ever add a cookie that is not strictly necessary, we will say so here and ask your permission before installing it. The date at the top shows the last review.

For everything else, see the privacy policy. Any questions: info@mykairo.app.