SafeHanded uses only the cookies and browser storage it needs to work securely. There are no analytics, advertising or tracking cookies, so we don't ask for consent.
This marketing website sets no cookies. It stores your light or dark theme choice in your browser's local storage (sh-theme), which never leaves your device.
If anti-abuse checks are switched on, the contact form and link checker load Cloudflare Turnstile, which inspects your browser to tell people from bots. See Cloudflare's Turnstile privacy addendum.
| Name | Purpose | Lasts |
|---|---|---|
safehanded-session | Keeps you signed in | Until 2 hours of inactivity, or sign-out |
XSRF-TOKEN | Protects forms against cross-site request forgery | As the session |
hd | Identifies the enrolled device that holds your encryption key, so you can revoke it | 400 days, or until the device is revoked |
saml_authn_* | Matches a SAML single sign-on response to its request | 10 minutes |
The app also keeps these in your browser:
safehanded-keys: your private encryption keys, held so they cannot be exported from the browser and unlocked with your passkey. Not used where an organisation requires strict mode.Pages opened from a SafeHanded link set no session cookie. They set short-lived cookies limited to that one link:
| Name | Purpose | Lasts |
|---|---|---|
hc, ho, sg | Remember that you entered the correct verification code for this link | 15 minutes |
hdone | Remembers that you already submitted from this browser | 60 minutes |
If the sending organisation turns on anti-abuse checks, these pages also load Cloudflare Turnstile.
All of the above are strictly necessary, so the law does not require consent for them. You can block or delete them in your browser settings, but you will not be able to sign in or complete a handover without them.
More about how we handle personal data is in our Privacy Policy.