Learn how FamilySafe uses cookies and similar technologies, and control your preferences at any time.Manage cookie preferences
Your current consent version is legacy. Last updated: 07/07/2026, 08:34:58.
What are cookies?
Cookies are small text files stored on your device by websites you visit. FamilySafe also uses browser storage such as localStorage and sessionStorage where that is needed to keep the vault secure, preserve session state, or complete billing and account workflows.
How we use cookies
- Necessary (always on):supports consent records, secure login, page navigation, bot protection, billing redirects, and vault encryption workflows.
- Functional:reserved for optional convenience features if FamilySafe adds them to the public website in future.
- Analytics:enables optional measurement through Google Tag Manager and related analytics tags.
- Marketing:reserved for optional advertising or conversion tools if FamilySafe adds them.
Your choices
You can accept all cookies, reject non-essential cookies, or manage categories at any time using the cookie preferences controls on this site. Rejecting non-essential cookies does not stop you from browsing the public website or using the FamilySafe vault.
If you later withdraw consent, FamilySafe stops loading the related optional technologies on future page loads and removes known first-party optional cookies where technically possible.
Retention
FamilySafe stores your cookie choice in the familysafe_consent cookie . That cookie records your chosen categories, a consent version, and consent timestamps so the website can respect your choice on future visits.
The current consent cookie lasts for up to 12 months unless you clear it sooner in your browser settings.
What happens if you reject non-essential cookies
FamilySafe keeps necessary cookies and storage enabled, but it does not load Google Tag Manager or other optional third-party technologies unless you have chosen the relevant category.
If you later withdraw consent, FamilySafe stops loading those technologies on future page loads and removes known first-party optional cookies where technically possible.
Public website cookie and technology inventory
| Name | Type | Provider | Category | Purpose | Duration | Consent required |
|---|---|---|---|---|---|---|
| familysafe_consent | Cookie | FamilySafe | Strictly necessary | Stores your cookie choices, consent version, and consent timestamps. | 12 months | No |
| Google Tag Manager | Script | Analytics | Loads optional website analytics tags after analytics consent is enabled. | Varies by configured Google tags | Yes | |
| Cloudflare Turnstile | Script | Cloudflare | Strictly necessary / security | Protects signup and related forms from abuse and automated attacks. | Provider dependent | No |
Google Tag Manager is currently treated as analytics-only. If the live container later includes advertising or remarketing tags, FamilySafe should reclassify that setup and require the appropriate additional consent.
Vault app essential browser storage
The private vault app currently relies on essential browser storage to keep you signed in, protect encrypted content, handle billing return journeys, and remember UI state. Because those technologies are essential to the authenticated service, the vault does not use a separate optional-cookie banner today.
In practice this includes session, encryption, billing-return, branding, and inactivity state that the vault needs in order to operate securely.
| Name | Type | Provider | Category | Purpose | Duration | Consent required |
|---|---|---|---|---|---|---|
| refreshToken | HttpOnly cookie | FamilySafe API | Strictly necessary | Maintains secure login and session refresh. | 30 minutes in the current implementation | No |
| fullName | Cookie | FamilySafe app | Strictly necessary in current implementation | Stores the signed-in user’s display name for some vault and sharing flows. | 31 minutes in the current implementation | No today; should be reviewed for removal |
| Cookie | FamilySafe app | Strictly necessary in current implementation | Stores the signed-in user’s email address for some vault, sharing, and client logging flows. | 31 minutes in the current implementation | No today; should be reviewed for removal | |
| accessToken / tokenUpdatedOn | sessionStorage | FamilySafe app | Strictly necessary | Stores the bearer token and session refresh timing used for authenticated API calls. | Session | No |
| privateKey / vmk / k0 | sessionStorage | FamilySafe app | Strictly necessary and sensitive | Holds vault key and client-side decryption material needed during a signed-in session. | Session | No |
| salt / evmk | localStorage | FamilySafe app | Strictly necessary and sensitive | Supports vault unlock and encryption/login helper state after sign-in. | Persistent until cleared | No |
| family | localStorage | FamilySafe app | Strictly necessary | Stores family and user context for the current vault experience. | Persistent until cleared | No |
| lastActivity | localStorage | FamilySafe app | Strictly necessary | Tracks inactivity timing for automatic logout protection. | Persistent until replaced or cleared | No |
| familyBranding | sessionStorage | FamilySafe app | Strictly necessary in current implementation | Caches portal branding and theming data used while the vault is open. | Session | No |
| maintenanceBypassUntil | sessionStorage | FamilySafe app | Strictly necessary / admin | Stores the temporary maintenance bypass timestamp for allowed sessions. | Session | No |
| directDebitSetupRequest / billingMandateChangeRequest / billingRequestId / billingRequestPackageId | localStorage | FamilySafe app | Strictly necessary / billing | Preserves billing and direct debit redirect state while GoCardless flows complete. | Persistent until cleared | No |
| dd_customer / dd_bank | sessionStorage | FamilySafe app | Strictly necessary / billing | Stores in-progress direct debit popup flow details during setup. | Session | No |
| cardManagerGridState / firstLogin | sessionStorage | FamilySafe app | Strictly necessary in current implementation | Stores grid layout and onboarding state used by the requested vault experience. | Session | No |
The current vault implementation still uses client-readable fullName and email cookies for some sharing, probate, and client logging flows. They are documented here because they still exist today, but they remain good candidates for a future hardening pass if those flows can be moved onto safer session or authenticated user context.
Blocking cookies or storage in your browser
Rejecting non-essential cookies will not block normal use of FamilySafe. However, if your browser blocks all cookies or browser storage entirely, FamilySafe may not work correctly because login, security, billing redirects, and vault encryption depend on essential storage.
If that happens, FamilySafe should prompt you to allow essential cookies and storage for the service to continue.
Contact
Questions about cookies, privacy, or consent can be sent through the contact page or by email at privacy@familysafe.app.
This page is provided for transparency and should be reviewed alongside the Privacy Policy and any legal guidance that applies to FamilySafe.