Clex sets no HTTP cookies at all. Everything below lives in your browser’s own storage and never travels with a request.
No analytics, no advertising pixels, no fingerprinting, no session replay, no third-party tag manager.
All of it is local. Clearing site data in your browser removes every item listed here, permanently.
Clex does not set cookies. It does use three browser storage mechanisms — localStorage, sessionStorage and IndexedDB — because the product is a browser application: your vault, your encryption keys and your in-progress transfers have to live somewhere, and we would rather that were your device than our server.
Everything in the table below is strictly necessary for a feature you chose to use. Under the ePrivacy Directive and UK PECR, strictly necessary storage does not require prior consent, which is why you are not asked to click through a consent wall to read this page. We show a one-time notice instead, so the disclosure is still made.
This list is exhaustive for clex.in as of the date above.
clex-theme-v2 — localStorage. Whether you chose light or dark. Kept until you clear site data. Without it the site re-guesses your theme on every page load and flashes.clex-storage-notice-v1 — localStorage. Records that you have seen the storage notice, so it is not shown again. Kept until you clear site data.vault-data-v1 — IndexedDB. Your notes and folders, encrypted before they are written. Kept until you delete them or clear site data.vault-crypto-v1 — IndexedDB. The encryption keys for the above, generated on your device. Never transmitted to Clex. Kept until you clear site data — clearing it without a backup makes existing notes unrecoverable, by design.clex_vault_share_resume — localStorage. Lets an interrupted vault share pick up where it left off. Cleared when the share finishes.clex_dev_apikey_session — sessionStorage. Holds the one-time plaintext of a key you just created so a page reload does not lose the only copy. Deliberately not localStorage: it must not outlive the tab. Gone when the tab closes.clex_admin_session_id — sessionStorage. Identifies an authenticated admin session. Gone when the tab closes.These are the only external services a Clex page contacts. None of them set a cookie through Clex, but a request necessarily discloses your IP address and user agent to the service handling it.
fonts.googleapis.com, fonts.gstatic.com) — serves the typefaces. Receives your IP address when fonts are fetched. No cookie is set.Everything above is under your control and none of it needs our involvement to remove.
Using Clex in a private or incognito window means nothing persists after you close it. The workspace still works; the Vault will not remember anything between sessions.
If Clex ever adds storage that is not strictly necessary — analytics being the obvious candidate — this page will say so before it ships, and it will be opt-in rather than assumed. Questions about anything here: [email protected].
See also the Privacy Policy and the Terms of Service.