No cookies
Clex sets no HTTP cookies at all. Everything below lives in your browser’s own storage and never travels with a request.
No trackers
No analytics, no advertising pixels, no fingerprinting, no session replay, no third-party tag manager.
Yours to clear
All of it is local. Clearing site data in your browser removes every item listed here, permanently.
The short version
Clex does not set cookies. It does use three browser storage mechanisms — localStorage, sessionStorage and IndexedDB — because the product is a browser application: your vault, your encryption keys and your in-progress transfers have to live somewhere, and we would rather that were your device than our server.
Everything in the table below is strictly necessary for a feature you chose to use. Under the ePrivacy Directive and UK PECR, strictly necessary storage does not require prior consent, which is why you are not asked to click through a consent wall to read this page. We show a one-time notice instead, so the disclosure is still made.
Everything Clex stores
This list is exhaustive for clex.in as of the date above.
Always present
clex-theme-v3— localStorage. Whether you chose light or dark. Kept until you clear site data. Without it the site re-guesses your theme on every page load and flashes.clex-storage-notice-v1— localStorage. Records that you have seen the storage notice, so it is not shown again. Kept until you clear site data.
Only if you open the Vault
vault-data-v1— IndexedDB. Your notes and folders, encrypted before they are written. Kept until you delete them or clear site data.vault-crypto-v1— IndexedDB. The encryption keys for the above, generated on your device. Never transmitted to Clex. Kept until you clear site data — clearing it without a backup makes existing notes unrecoverable, by design.clex_vault_share_resume— localStorage. Lets an interrupted vault share pick up where it left off. Cleared when the share finishes.
Only if you create an API key
clex_dev_apikey_session— sessionStorage. Holds the one-time plaintext of a key you just created so a page reload does not lose the only copy. Deliberately not localStorage: it must not outlive the tab. Gone when the tab closes.
Only on the admin console
clex_admin_session_id— sessionStorage. Identifies an authenticated admin session. Gone when the tab closes.
What Clex does not do
- No HTTP cookies, first-party or third-party
- No analytics or product-telemetry SDK
- No advertising or remarketing pixels, and no data sold or shared for advertising
- No device fingerprinting or cross-site identifiers
- No session replay or heatmap recording
- No tag manager loading further scripts after the page opens
Third parties that can see a request
These are the only external services a Clex page contacts. None of them set a cookie through Clex, but a request necessarily discloses your IP address and user agent to the service handling it.
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) — serves the typefaces. Receives your IP address when fonts are fetched. No cookie is set. - Firebase Authentication (Google) — only if you sign in. Handles the sign-in itself and issues the identity token Clex verifies.
- Cloudflare storage — holds files uploaded through the programmatic API until they expire, and Vault's encrypted backup snapshot (ciphertext only, the key never leaves your device). Not used for direct P2P or local-network transfers.
- Cloudflare — serves the site and runs the API workers.
Clearing what is stored
Everything above is under your control and none of it needs our involvement to remove.
- All of it: clear site data for clex.in in your browser settings — in Chrome and Edge under Settings → Privacy → Third-party cookies → See all site data; in Firefox under Settings → Privacy & Security → Cookies and Site Data; in Safari under Settings → Privacy → Manage Website Data.
- Session items only: close the tab.
- Vault notes: delete them in the Vault, or clear site data to remove the encrypted store and its keys together.
Using Clex in a private or incognito window means nothing persists after you close it. The workspace still works; the Vault will not remember anything between sessions.
Changes and contact
If Clex ever adds storage that is not strictly necessary — analytics being the obvious candidate — this page will say so before it ships, and it will be opt-in rather than assumed. Questions about anything here: abhnv@abhnv.in.
See also the Privacy Policy and the Terms of Service.