Cookie and Storage Notice
Draft — not yet in force. The values highlighted like this are unresolved and must be filled in, and the whole set needs a lawyer's review, before these pages are linked from the product or relied on by an ethics committee. Until then this page describes intended practice, not a binding commitment.
This page lists everything Workframe stores in your browser. It is short, and it is meant to stay short.
Why there is no cookie banner
Consent is required for cookies and storage that are not strictly necessary — analytics, advertising, session replay, cross-site tracking. Workframe uses none of those. What it does use is limited to keeping you signed in, protecting the service from abuse, and remembering interface preferences you set yourself. That category requires disclosure, which is this page, not consent.
If that ever changes — if we add analytics, or any third-party measurement — we will put a consent manager in place first, with rejecting made exactly as easy as accepting, and this page will say so before the change ships.
The participant surface sets nothing
A participant completing a study is the most sensitive case, so it is the strictest. The participant surface sets no cookies, writes nothing to localStorage or sessionStorage, and loads no script, font or image from a third party. The token that identifies a run exists in memory only and is gone when the tab closes. An embedded study carries no one's beacons — including ours.
Researcher sign-in and the builder
These apply only when you sign in as a researcher at app.workframeapp.com.
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
__session | Cookie, first-party | Clerk, on our domain | The signed session that keeps you logged in. Verified server-side on every request. | Short-lived; refreshed continuously while you are active |
__client_uat | Cookie, first-party | Clerk, on our domain | Tells the page whether a session exists, so it can show signed-in state without a round trip. Holds a timestamp, not identity. | Session |
__cf_bm [confirm in production] |
Cookie, first-party | Cloudflare | Bot management — distinguishes humans from automated traffic. Set by our host, not readable by us. | About 30 minutes |
workframe-theme | localStorage | Workframe | Whether you chose light or dark, so the choice survives a reload and carries across to this site. | Until you clear it |
workframe-library-width, workframe-inspector-width |
localStorage | Workframe | The panel widths you dragged, so the editor reopens as you left it. | Until you clear it |
The three workframe-* keys hold interface preferences and no personal data. They
never leave your browser.
This marketing site
workframeapp.com sets no cookies. It reads workframe-theme if the
builder already set it, so that a reader who chose dark mode there is not flashed a white page here.
Fonts are served from this origin rather than from Google Fonts, so loading a page here sends your
IP address to no one but us.
Turning these off
You can clear or block cookies and site data for workframeapp.com in your browser's settings, or
clear the workframe-* keys alone through its developer tools. Blocking
__session will sign you out and prevent signing in — it is the mechanism that
authenticates you, so there is no version of the product that works without it. Nothing else here
affects whether Workframe functions.
Verification status
The rows above are drawn from the application's source. Cookie behaviour that originates with a provider rather than our code — Cloudflare's bot-management cookie in particular, which depends on zone settings — should be confirmed against a real production session before this page is published, and any additional cookie found added here.