Cookie Policy

Last updated: September 2026

1. What Are Cookies?

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work, as well as to provide information to the website owners.

Cookies may be “session cookies” (deleted when you close your browser) or “persistent cookies” (remain on your device for a set period or until you delete them). Websites can also keep information in your browser's local storage and session storage, which work in a similar way. This policy covers both, and we call them “cookies” and “browser storage” below.

2. How KalHope Uses Cookies

KalHope uses a small number of first‑party cookies: ones that keep you signed in and protect your account, one that records a referral link, and one that stops repeat visits to a portfolio from being counted again and again. We do not use advertising, tracking, or third‑party analytics cookies.

Separately, some tools store settings and drafts in your browser storage. That is described in Section 4.

3. Cookies We Set

3.1 Sign‑in Session Cookie (essential)

Cookie name: authjs.session-token (__Secure-authjs.session-token on HTTPS)

Purpose: Keeps you signed in to your KalHope account so you can move between pages without signing in again. It holds an encrypted token that identifies your session, and it cannot be read by scripts on the page.

Duration: Up to 30 days, and it is renewed while you keep using KalHope. Signing out removes it. The “Remember me” box on the sign‑in page does not currently change this.

3.2 CSRF Protection Cookie (essential)

Cookie name: authjs.csrf-token (__Host-authjs.csrf-token on HTTPS)

Purpose: Helps protect your account from cross‑site request forgery (CSRF) attacks when you sign in or out. It is a security measure required for safe authentication.

Duration: Session.

3.3 Sign‑in Redirect Cookie (essential)

Cookie name: authjs.callback-url (__Secure-authjs.callback-url on HTTPS)

Purpose: Remembers which page you were trying to reach so we can send you there after you sign in.

Duration: Session.

3.4 Social Sign‑in Cookies (essential, only when used)

Cookie names: authjs.pkce.code_verifier, authjs.state, authjs.nonce (with a __Secure- prefix on HTTPS)

Purpose: Set only while you sign in with Google, GitHub, or Facebook. They confirm that the sign‑in response really belongs to the request you started.

Duration: 15 minutes.

3.5 Referral Cookie (functional)

Cookie name: kalhope_ref

Purpose: Set when you open a KalHope referral link (for example kalhope.com/ref/username or a link ending in ?ref=). It stores the referral code so that, if you sign up, the person who referred you can be credited under our affiliate program. It is used for nothing else.

Duration: 365 days. It applies across kalhope.com and its subdomains.

3.6 Portfolio View Cookie (functional)

Cookie name: pf_view_ followed by the portfolio's ID

Purpose: Set when someone other than the owner views a published portfolio. It stops the same browser from being counted again for a short time, so the view count the owner sees is not inflated by refreshes. It contains only the value “1”; it does not identify you, and we do not store your IP address for this.

Duration: 1 hour.

4. Browser Storage (Not Cookies)

The items below are kept in your browser's local or session storage on your own device. They are used only by the feature described, and they are not sent to us by the storage itself.

4.1 Theme Preferences

Local storage keys: kalhope-theme, kalhope:spatial:theme

Purpose: Remember your light, dark, or system display choice, and the light/dark choice for Spatial portfolios, so the interface looks the same on your next visit.

Duration: Until you clear your browser data.

4.2 Developer Tools

Local storage keys starting with kalhope:devtools:

Purpose: Keep your work in the DevTools on your device: the API Tester's request history, saved code snippets (and whether their panel is expanded), your Markdown editor draft, and your QR generator settings. This can include whatever you typed into those tools, such as request addresses and headers, so clear it on a shared computer.

Duration: Until you clear your browser data.

4.3 Math Tool and Floating Windows

Session storage keys starting with kalhope:

Purpose: Keep your Math Tool's current state (history and stored variables), and remember where you placed the Hope AI window and button on the screen.

Duration: Until you close the browser tab.

Hope AI conversations are not kept in your browser storage or in our database. See our GDPR page for how Hope AI handles your messages.

5. Third‑Party Content

KalHope does not add third‑party analytics, advertising, or social media tracking scripts to its pages. Even so, some third parties can receive information from your browser when you use certain features:

  • Sign‑in providers: If you choose to sign in with Google, GitHub, or Facebook, you are taken to that provider, which sets and reads its own cookies under its own policy.
  • Chapa: If you pay for a subscription through Chapa, you are taken to Chapa's payment page, which sets and reads its own cookies under its own policy.
  • Images: Uploaded images are delivered from our own servers. Some pages show images hosted by other image providers; your browser contacts those servers directly, so they can see your IP address and browser details.

We do not control third‑party cookies. Please read the privacy policy of any third party you interact with.

6. What We Do NOT Use

KalHope does not use:

  • Advertising or targeting cookies
  • Third‑party analytics cookies (e.g., Google Analytics)
  • Social media tracking cookies or pixels

7. How to Manage or Disable Cookies

Most web browsers let you control cookies and site data in their settings. You can block or delete them, and clearing “site data” also removes the browser storage described in Section 4. Please note:

  • Blocking the essential cookies (3.1 to 3.4) will stop you from signing in.
  • Blocking the referral cookie (3.5) only means a referrer will not be credited for your sign‑up.
  • Blocking the portfolio view cookie (3.6) means repeat views from you may be counted more than once.
  • Clearing browser storage resets your theme, your DevTools history and drafts, and your calculator and window positions.

Here are links to cookie management instructions for common browsers:

8. Changes to This Cookie Policy

We may update this Cookie Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.

9. Contact Us

If you have any questions about our use of cookies, please contact us at:

KalHope Technology Group
Email: info@kalhope.com
Phone: +251 935961028 / +251 911720932
Loading footer...