Cookie & Local Storage Privacy Vault
At Saathi Bot, your data sovereignty is non-negotiable. Custom LLM credentials (OpenAI, Gemini, Claude, Groq, DeepSeek) are never stored in our central PostgreSQL database or backup snapshots. They reside securely in your browser’s local cryptographic sandbox.
0 Bytes
Never saved to disk
0 Seconds
Ephemeral streaming
TLS 1.3 + HS256
Signed JWT validation
...
In this browser session
Device Storage VaultLoading...
Inspect, export, toggle persistence modes, or wipe private LLM credentials stored on this computer.
Storage & Cookie Inventory
Every cookie, identifier, and client-side storage element utilized across the platform.
| Key / Identifier | Storage Layer | Network Scope | Functional Purpose | Retention |
|---|---|---|---|---|
saathi_bot_key_<id> | LocalStorage / SessionStorage | Never written to Database | Stores your BYOK API keys (Gemini, OpenAI, Claude, Groq, DeepSeek) strictly inside your browser sandbox. | User Controlled |
saathi_storage_consent | LocalStorage | Client Only (No Transfer) | Remembers your cookie banner acknowledgment and telemetry consent preferences. | 1 Year |
sb-*-auth-token | HttpOnly Secure Cookie | Encrypted via TLS to Supabase | Maintains authenticated dashboard session state with cryptographically signed JWT tokens. | 7 Days / Rolling |
saathi_vid | LocalStorage | Anonymous Visitor ID | Enables continuous multi-turn chat memory across page navigation in the live embeddable widget. | 30 Days |
How Zero-Knowledge BYOK Protects You
Trace how your proprietary LLM API tokens travel through our runtime without ever touching persistent disks.
Client-Side Isolation
When entered in Bot Settings or Playground, your key is saved exclusively in your browser’s sandboxed storage. Our server-side database mutation deliberately strips the credential key from SQL writes.
Ephemeral In-Flight RAM
During test streaming, the client transmits the key inside an encrypted TLS header (x-client-api-key). The server holds it in volatile RAM only for the duration of the streaming tokens.
Zero Disk Logging Guarantee
Our application loggers, telemetry trackers, and AI invocation tables (ai_logs) are strictly banned from logging API keys. As soon as the SSE stream terminates, the memory is garbage-collected.