Cookie Policy
Effective Date: October 8, 2025
This Cookie Policy explains how Torvus Security uses cookies and similar technologies.
What Are Cookies?​
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and improve your experience.
Types of Data Stored:​
- Session identifiers
- User preferences (language, theme)
- Authentication tokens
- Analytics data
Cookies We Use​
Essential Cookies (Always Active)​
These cookies are necessary for the Service to function:
| Cookie Name | Purpose | Duration | Can Be Disabled? |
|---|---|---|---|
session_token | Authentication | Session (until logout) | L No |
csrf_token | Security (CSRF protection) | Session | L No |
cookie_consent | Remember cookie preferences | 1 year | L No |
Why Essential: Without these cookies, you cannot log in or use the Service securely.
Functional Cookies (Opt-Out Available)​
These cookies enhance your experience:
| Cookie Name | Purpose | Duration | Default |
|---|---|---|---|
theme_preference | Remember dark/light mode | 1 year | Enabled |
language | Remember language preference | 1 year | Enabled |
sidebar_collapsed | Remember sidebar state | 1 year | Enabled |
Opt-Out: Settings � Privacy � Functional Cookies
Analytics Cookies (Opt-In Required)​
These cookies help us understand how you use the Service:
| Cookie Name | Purpose | Duration | Default |
|---|---|---|---|
_ga | Google Analytics (visitor tracking) | 2 years | L Disabled |
_gid | Google Analytics (session tracking) | 24 hours | L Disabled |
analytics_session | Internal analytics | Session | L Disabled |
Data Collected:
- Pages visited
- Time spent on pages
- Browser and device information
- Geographic location (country/city level)
Opt-In: Settings � Privacy � Analytics Cookies
Note: We do NOT use analytics cookies by default. You must explicitly enable them.
Marketing Cookies (Disabled)​
We do NOT use marketing or advertising cookies. We do not track you across websites or sell your data to advertisers.
Third-Party Cookies​
Services We Use:​
Cloudflare (CDN & Security):
- Purpose: DDoS protection, performance
- Cookies:
__cf_bm,__cfduid - Privacy: Cloudflare Privacy Policy
Stripe (Payments):
- Purpose: Payment processing
- Cookies:
__stripe_mid,__stripe_sid - Privacy: Stripe Privacy Policy
- Only loaded on payment pages
Google Analytics (Analytics - Opt-In Only):
- Purpose: Website analytics
- Cookies:
_ga,_gid - Privacy: Google Privacy Policy
- Only if you enable analytics cookies
How We Use Cookies​
Authentication​
- Keep you logged in across sessions
- Remember your authenticated state
- Secure session management
Security​
- Prevent cross-site request forgery (CSRF) attacks
- Detect and prevent abuse
- Monitor for suspicious activity
Preferences​
- Remember your theme (dark/light mode)
- Store language preference
- Save UI state (sidebar, filters)
Analytics (Opt-In)​
- Understand how users navigate the Service
- Identify popular features
- Improve user experience
- Detect and fix issues
Managing Cookies​
In-App Controls​
Settings � Privacy � Cookie Preferences:
- View active cookies
- Enable/disable functional cookies
- Enable/disable analytics cookies
- Clear all non-essential cookies
Browser Controls​
Chrome:
- Settings � Privacy and security � Cookies
- Choose: Block all cookies, Block third-party, Allow all
Firefox:
- Preferences � Privacy & Security � Cookies
- Choose: Block all, Block third-party, Accept all
Safari:
- Preferences � Privacy � Cookies
- Choose: Block all, Block cross-site, Allow all
Do Not Track (DNT)​
We honor "Do Not Track" browser signals:
- Analytics cookies automatically disabled
- Third-party tracking blocked
- Minimal data collection
Enable DNT:
- Chrome: Settings � Privacy � Send "Do Not Track" request
- Firefox: Preferences � Privacy � Send Do Not Track signal
- Safari: Privacy � Website Tracking � Prevent cross-site tracking
Cookie Lifespan​
| Type | Lifespan | When Deleted |
|---|---|---|
| Session Cookies | Until logout or browser close | Immediately |
| Persistent Cookies | 1-2 years | After expiration or manual deletion |
| Authentication | 30 days (if "Remember Me") | Logout or expiration |
Data Collected via Cookies​
Essential Cookies Collect:​
- User ID (hashed)
- Session ID
- Authentication status
- CSRF token
Functional Cookies Collect:​
- Theme preference (dark/light)
- Language (en, es, fr, etc.)
- UI state (collapsed sidebars, filters)
Analytics Cookies Collect (Opt-In):​
- Pages visited
- Time spent on site
- Referrer URL
- Browser/device type
- Geographic location (city/country)
We Do NOT Collect:
- Personally identifiable information (PII)
- Sensitive vault contents
- Passwords or credentials
- Payment information (handled by Stripe)
Legal Basis for Cookies​
GDPR (EU Users)​
Essential Cookies: Legitimate interest (necessary for service) Functional Cookies: Consent (opt-out available) Analytics Cookies: Consent (opt-in required)
CCPA (California Users)​
Cookies are not "sold" or "shared" for advertising. You can opt-out of analytics cookies.
Your Rights:
- Know what cookies are used
- Opt-out of non-essential cookies
- Delete cookies at any time
Cookie Consent​
First Visit​
On your first visit, you'll see a cookie consent banner:
Options:
- Accept All: Enable functional and analytics cookies
- Essential Only: Only essential cookies (default)
- Customize: Choose which cookie types to enable
Default: If you don't choose, only essential cookies are used.
Changing Consent​
You can change your cookie preferences anytime:
- Settings � Privacy � Cookie Preferences
- Choose cookie types to enable/disable
- Save changes
Children's Privacy​
The Service is not directed to children under 18. We do not knowingly collect data from children via cookies.
If you believe a child has used our Service, contact privacy@torvussecurity.com.
Updates to This Policy​
We may update this Cookie Policy from time to time. Changes will be effective upon posting.
Material Changes: We will notify you via email or in-app notification.
Continued Use: Using the Service after changes constitutes acceptance.
Contact​
Privacy Questions: privacy@torvussecurity.com Cookie Opt-Out: Settings � Privacy � Cookie Preferences Data Protection Officer: dpo@torvussecurity.com
Related Policies​
- Privacy Policy: How we collect and use data
- Terms of Service: Legal agreement
- Security Practices: How we protect data
Last Updated: October 8, 2025