# Kiwi Studios Cookie Policy

_Last updated: September 7, 2026_

## What this website uses

The public storefront uses essential sign-in storage when you use a Kiwi account. It does not use advertising pixels or third-party audience analytics. Images, fonts, and demonstration clips are hosted by Kiwi Studios; videos are not embedded from YouTube or another advertising platform.

We do not display an accept-all cookie banner because the public storefront currently has no optional tracking to enable. Essential authentication is used to provide the account service you request. If optional tracking is introduced, we will update this notice and provide the choice required by applicable law before enabling it.

## Sign-in cookies

- **kiwi_uid** identifies the signed-in account. It is a first-party cookie with a 30-day browser lifetime that can be renewed when the session is restored. It is removed on sign-out.
- **kiwi_tok** authenticates the session. It has the same lifetime and sign-out behavior. Treat your account credentials as private.

Both cookies are HttpOnly, use SameSite=Lax, and are set with Secure on the production service. They are used for authentication and session recovery, not advertising. The account service checks the server session before granting access; a cookie's browser expiry alone does not define every server-side retention period.

## Other browser storage

- **user_session** in local storage keeps the account session available to the website and Kauri. It has no automatic browser expiry. Sign-out clears it; your browser may also clear it.
- **kiwi_auth_event** in local storage tells other open Kiwi tabs that you signed out. It contains an event type and time, not an advertising identifier. It is overwritten by the next sign-out event and remains until site data is cleared.
- **Kauri preferences and offline work** use local storage when you use that application. This includes your selected theme, view settings, recent project choices, and queued offline changes. These settings are separate from storefront browsing and remain until replaced, synchronized where applicable, or cleared. Clearing site data can remove work that has not yet synchronized.

The public package directory keeps its filters in the page URL instead of a tracking cookie. Server request logs are explained in the [Privacy Policy](/privacy-policy/).

## Your controls

Use **Sign out** to end the current Kiwi session. You can also block or clear this site's cookies and storage through your browser's site-data settings. Blocking essential storage can prevent sign-in or session recovery; product pages and documentation remain available without an account.

There are no public-storefront advertising cookies to reject or opt back into. Optional newsletter email is a separate choice: [unsubscribe here](/newsletter-unsubscribe/).

## External links and connected services

Following a Fab, Unity, Discord, GitHub, or other external link opens that provider's service, where its own storage and privacy choices apply. Kauri integrations are enabled through the application's connection controls. A marketplace link on a product page is not an embedded marketplace tracker.

## Contact and updates

Contact [support@kiwistudios.co](mailto:support@kiwistudios.co) about cookies or storage. We review this inventory when site features change and show the current notice date above. Read the [Privacy Policy](/privacy-policy/) for account information, retention, and privacy rights.