Policy on the Use of Cookies and Local Storage

Translation notice. This English translation is provided for convenience only. The legally binding text is the Ukrainian original: Політика cookie.

DSTUcrypt service

Website owner: Elektronnyi Obih LLC (ТОВ «ЕЛЕКТРОННИЙ ОБІГ»), EDRPOU (company code) 46191111

Address: Ukraine, 04077, Kyiv, 1a Dniprovodska St., office 1

Contact: privacy@dstucrypt.com.ua

Revision dated: 7 August 2026

Published at: https://dstucrypt.com.ua/en/cookies

1. The Essentials, in Brief

On the public pages of the website we use Google Analytics — to see how many people visit and which pages they read. We have no advertising networks, social media pixels, or cross-site tracking trackers. We do not build visitor profiles and do not pass any data about you to advertisers.

Inside the signing widget there is no analytics at all — where you work with your key, no one is watching you.

We use browser data storage technologies in four cases:

  1. to remember the website theme you have chosen;
  2. to keep you signed in to your account dashboard after logging in;
  3. to count visits to the website’s pages (Google Analytics);
  4. so that — if the site owner has enabled it and you have agreed to it — you are not forced to select the key file and enter the password every time.

The fourth item is the most important one, and a separate Section 5 is devoted to it.

2. What Cookies and Local Storage Are

A cookie is a small text file that a website stores in your browser and receives back on subsequent requests. It is used, among other things, so that the site “remembers” that you have signed in.

Local storage (localStorage) is a browser mechanism for storing data on your device without a time limit. Unlike cookies, this data is not sent automatically to the server with every request — it stays in the browser until it is deleted.

Session storage (sessionStorage) is the same, except the data disappears as soon as you close the tab.

Why the document is named this way. In most services the main workload falls on cookies. In our case it is the opposite: the most important data is stored in localStorage and sessionStorage, while there are almost no actual cookies. That is why calling this document simply a “cookie policy” would be inaccurate.

3. What We Use on the Website dstucrypt.com.ua

3.1. First-Party Technologies

NameTypePurposeAttributesDurationRequired?
dstu-themelocalStoragestores the light or dark website theme you have chosen—until you delete itno — but without it the theme will reset on every visit
Technical session cookie of the account dashboardcookiemaintains the signed-in state of your account after you follow the link sent to your emailSecure, HttpOnly, SameSite=Laxuntil the session ends or you sign out of the accountyes — without it, signing in to the account is impossible

The account session cookie is set only after you sign in; it is not present on the public pages of the website. Our only persistent cookies are analytics ones — _ga and _ga_YZJR7K6E55 (see 3.2). They do not let us know who you are: they contain only a random browser identifier.

3.2. Technologies Loaded from Other Domains

ServiceWhat it doesWhat data it may receiveWhen it appears
Google Analytics (googletagmanager.com)counts visits to the website’s pagesIP address (Google truncates it before storage), device and browser type, the page you came from and the pages you viewed; a random browser identifier in the _ga cookie with a lifetime of 2 yearson the public pages of the website; in the signing widget — never
YouSelfBot (app.youselfbot.com)chat widget for contacting supporttechnical session data; your name, contact details and message content — only if you provide them yourselfon all pages of the website
LiqPay (JSC CB PrivatBank)accepting payment for the Subscriptiondata required to process the payment and to counter fraud, in accordance with the payment system’s rulesonly on the payment page, after you proceed to payment

Important note about YouSelfBot. Although the widget is loaded from another domain, it is a product owned by Elektronnyi Obih LLC, not a third-party service. The data of your enquiry stays within our company and is not passed to anyone. We list it separately only because, technically, it loads from the domain app.youselfbot.com, and you will see this in developer tools or a script blocker.

3.3. What We Do Not Have

We do not use:

  • advertising networks or remarketing systems (Google Ads, Meta Ads, etc.);
  • social media pixels (Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, etc.);
  • behaviour tracking or session recording systems (Hotjar, FullStory, etc.);
  • A/B testing with profiling;
  • any analytics inside the signing widget.

The last item is not a formality but a line we draw deliberately: the pricing page may be counted; the window where a person works with their key may not.

We load fonts from Google Fonts (fonts.googleapis.com), so your IP address becomes known to Google at that moment as well.

4. What Is Used in the Widgets on Our Clients’ Websites

4.1. If you sign a document or sign in with a QES on someone else’s website, the DSTUcrypt widget loads as an isolated iframe from the domain dstucrypt.io.

4.2. Inside this iframe, no analytics or advertising technologies are used. Only what is described in Section 5 is used, and only provided that the site owner has enabled the corresponding feature.

4.3. What the website you are on uses itself is beyond our control. That is determined by its owner’s policy.

5. Storing the Key Container in the Browser — Automatic Mode

This is the most sensitive part, so we describe it in detail.

5.1. What It Is

The Service has an optional feature called “Automatic Mode” (in the documentation — session). It allows you not to select the key file and not to enter the password every time you sign a document.

5.2. Who Enables It

The feature is enabled by the owner of the integrating website, not by us and not by you. If the owner has not enabled it, no key data is stored in your browser at all.

5.3. What Exactly Is Stored

WhatWhereHow it is protectedFor how long
The encrypted container of your personal keylocalStorage of the domain dstucrypt.ioAES-GCM-256 encryption; the encryption key is derived from your PIN code using PBKDF2-SHA256 with 310,000 iterationsup to 30 days
The unlocked “key + password” pairsessionStorage of the current tabexists only within the open tabfor the period set by the site owner (ttlMinutes)
The fact that you gave consent to storagelocalStorage of the domain dstucrypt.io—together with the container
Your PIN codenowhere——

5.4. Key Guarantees

  • The PIN code is not stored at all — neither in the browser nor on our servers. Without it, decrypting the stored container is impossible.
  • Domain binding. A container saved while working on website A is technically inaccessible from website B, even though both use the same widget domain.
  • Nothing is sent to our servers. All of this data remains on your device.
  • There is a mode without password storage. If the site owner has chosen mode: 'password', only the key file is stored, while the password is requested every time and is never stored.

5.5. How to Delete It

  • in the widget — use the “forget key” function (technically, the session.forget() method);
  • in the browser — clear the site data for dstucrypt.com.ua (see Section 7);
  • do nothing — the container will be deleted automatically after 30 days.

5.6. Our Recommendation

Do not enable key storage on devices that other people have access to — shared, work, or public computers. Encryption protects the container from being read, but it does not protect against someone who knows your PIN.

6. Legal Grounds

6.1. As of the date of this revision, the applicable legislation of Ukraine contains no specific rule on a cookie consent banner analogous to Directive 2002/58/EC. We are guided by the Law of Ukraine “On Personal Data Protection” No. 2297-VI, the Law of Ukraine “On Electronic Communications” No. 1089-IX as regards the protection of End User information, and by the approach established in European practice.

6.2. Allocation of grounds:

WhatGround
Account session identifiernecessity for the provision of a service you have expressly requested (signing in to the account)
dstu-themelegitimate interest — ensuring interface convenience; the data is anonymised and poses no privacy risk
Storage of the key containerconsent — given by you directly in the widget interface when setting up Automatic Mode; the fact of consent is recorded on your device. Consent can be withdrawn at any time by deleting the stored data (Section 5.5)
Google Analyticslegitimate interest — understanding which pages are used; anonymised visit data is collected, and we do not match it with your account. You can opt out at any time (Section 7)
Support widgetlegitimate interest — providing support; personal data is processed only if you provide it yourself
Payment serviceperformance of the agreement and of legal requirements in the field of payment services

6.3. There is currently no consent banner on the website: the legislation of Ukraine contains no rule analogous to Directive 2002/58/EC, and the only analytics we use counts page visits and does not profile you. If we add technologies for which consent is mandatory, or start operating in markets where such a banner is required, we will implement it and update this section.

6.4. Regardless of this, you can opt out of analytics yourself — see Section 7.

7. How to Manage This Data

7.1. In the Browser

You can view, restrict, or delete cookies and site data in your browser settings:

  • Google Chrome: Settings → Privacy and security → Cookies and other site data
  • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Microsoft Edge: Settings → Cookies and site permissions

You can also use private browsing mode — then all data will be deleted after the window is closed.

7.2. Opting Out of Analytics

Google offers an official browser add-on that disables Google Analytics on all websites at once: tools.google.com/dlpage/gaoptout. Any script blocker works the same way. The website will not break because of this — analytics does not affect anything on it.

7.2. What Happens After Deletion

You deletedConsequence
dstu-themethe website will open with the default theme
the session identifieryou will be signed out of the account and will need to sign in again via a link
the stored key containeryou will have to select the key file and enter the password again. The key itself is not lost — your original key file remains with you

7.3. Blocking cookies and local storage at the browser level may render the account dashboard and Automatic Mode inoperable. It does not affect the ability to sign a document in the normal mode.

8. Changes to This Policy

8.1. We update this Policy whenever the set of technologies in use changes. The current revision is always available at https://dstucrypt.com.ua/en/cookies, with the date indicated.

8.2. If we ever start using analytics or advertising technologies, we will announce this separately and introduce a consent mechanism before their launch, not after.

9. Questions

For questions regarding this Policy and the processing of personal data, write to privacy@dstucrypt.com.ua. For general and commercial enquiries — to sale@dstucrypt.com.ua.

Related documents:

Revision dated 7 August 2026.