Cookie Notice
KRNLA is operated by Britesh Gaire, Nepal. Contact privacy@krnla.com with cookie questions.
Essential sign-in and security storage
On the console domain, KRNLA's authentication cookies are host-only, Secure, HttpOnly and SameSite=Lax. They are not shared across all krnla.com subdomains.
-
__Host-krnla_oidc: protects sign-in state, with a five-minute maximum; cleared after the completed callback. -
__Host-krnla_session: keeps the console session, with a seven-day absolute maximum and 24-hour server-side idle expiry. Trusted activity renews the idle window within the absolute limit. Sensitive actions require fresh authentication; revocation can end access earlier. -
guidance-{agentId}in browser session storage: remembers dismissal of onboarding guidance for the browser page session.
WorkOS and Cloudflare may use separate authentication/security cookies with provider-controlled lifetimes. Their lifetimes and use are controlled by those providers.
Optional tracking and browser controls
The reviewed KRNLA source does not install analytics, advertising or session-replay trackers. There is no marketing cookie banner or consent record to describe. Optional tracking must receive its own legal review and required notice/choice before being introduced.
You can block or clear cookies in your browser. Blocking essential cookies may prevent sign-in. Removing a cookie does not delete your account or workspace data.