Most cookie policies are long because most sites carry advertising and analytics. This one is short for the opposite reason.
1. The short version
Blockra sets no cookies. Not on blockra.io, not in the dashboard, not in the checkout. Our API sets no cookies either.
We load no analytics scripts, no advertising tags, no social pixels and no third-party trackers. Nobody is paid to watch you use this site, because nobody is watching.
What we do use is a small amount of local storage in your own browser. It never leaves your device on its own, and it is listed in full below.
2. What is stored, and why
| Key | Where | Purpose | Cleared when |
|---|---|---|---|
blockra.session | Dashboard | Keeps you signed in between page loads | You sign out, or clear site data |
blockra.device_id | Dashboard | A random identifier so we can recognise this device and email you a code when a new one signs in | You clear site data |
blockra.theme | Dashboard | Light or dark preference | You clear site data |
blockra.checkout.theme | Checkout | Light or dark preference for the checkout | You clear site data |
blockra.cookie_consent | blockra.io | Records your choice on the banner, so we do not ask again | You clear site data, or change it below |
blockra-wallet | Dashboard (IndexedDB) | Your encrypted wallet recovery phrase, if you created a Blockra Wallet | You remove the wallet, or clear site data |
Every one of these is strictly necessary or a preference you set. Under UK and EU rules, strictly-necessary storage does not require consent — but you should still know it is there, which is why it is listed.
About blockra-wallet
If you use the optional Blockra Wallet, your recovery phrase is encrypted in your browser (scrypt key derivation, then AES-256-GCM) and stored in IndexedDB on that device. It is never sent to us. Clearing site data on that device removes it, and without your written-down recovery phrase it cannot be recovered by anyone, including us.
About blockra.device_id
This is a random value your browser generates. It is not derived from your hardware, your headers or anything that identifies you across sites, and it is stored on our side only as a hash. Its whole job is to let us tell "this is the laptop you used last week" from "this is a sign-in from somewhere new".
3. Third-party cookies
We set none, and we embed no third-party content that sets them on our marketing site.
Two caveats, stated because they are true rather than because we chose them:
- Cloudflare serves our sites and may set its own security cookies (for example a bot-management cookie) at the network edge. These are set by Cloudflare for security, not by us for tracking.
- Stripe hosts the card fields inside the checkout, and Stripe sets storage of its own for fraud prevention on the checkout page. This is part of processing a card payment and is governed by Stripe's privacy policy.
4. Your choices
The banner on blockra.io offers analytics and marketing categories. Today both are unused — there is nothing behind them to switch on — and they are off unless you turn them on. They exist so that if we ever add a measurement tool, it is gated behind a choice you already made rather than switched on quietly.
You can change or withdraw your choice at any time from Cookie settings in the footer of any page. You can also clear all of the storage above through your browser's site-data controls.
Blocking storage in your browser will stop the dashboard keeping you signed in, and will remove a wallet stored on that device.
5. Do Not Track and Global Privacy Control
We have no tracking to disable, so these signals change nothing about how we behave. If we ever add analytics, we will honour them.
6. Changes
If we add anything that stores data in your browser, it will be added to the table above and the "last updated" date will change. Anything that is not strictly necessary will be asked for first.
Questions: support@blockra.io.