Workframe

Cookie and Storage Notice

Last updated 24 August 2026 · Back to workframeapp.com

Draft — not yet in force. The values highlighted like this are unresolved and must be filled in, and the whole set needs a lawyer's review, before these pages are linked from the product or relied on by an ethics committee. Until then this page describes intended practice, not a binding commitment.

This page lists everything Workframe stores in your browser. It is short, and it is meant to stay short.

Why there is no cookie banner

Consent is required for cookies and storage that are not strictly necessary — analytics, advertising, session replay, cross-site tracking. Workframe uses none of those. What it does use is limited to keeping you signed in, protecting the service from abuse, and remembering interface preferences you set yourself. That category requires disclosure, which is this page, not consent.

If that ever changes — if we add analytics, or any third-party measurement — we will put a consent manager in place first, with rejecting made exactly as easy as accepting, and this page will say so before the change ships.

The participant surface sets nothing

A participant completing a study is the most sensitive case, so it is the strictest. The participant surface sets no cookies, writes nothing to localStorage or sessionStorage, and loads no script, font or image from a third party. The token that identifies a run exists in memory only and is gone when the tab closes. An embedded study carries no one's beacons — including ours.

Researcher sign-in and the builder

These apply only when you sign in as a researcher at app.workframeapp.com.

NameTypeSet byPurposeLifetime
__sessionCookie, first-partyClerk, on our domain The signed session that keeps you logged in. Verified server-side on every request. Short-lived; refreshed continuously while you are active
__client_uatCookie, first-partyClerk, on our domain Tells the page whether a session exists, so it can show signed-in state without a round trip. Holds a timestamp, not identity. Session
__cf_bm [confirm in production] Cookie, first-partyCloudflare Bot management — distinguishes humans from automated traffic. Set by our host, not readable by us.About 30 minutes
workframe-themelocalStorageWorkframe Whether you chose light or dark, so the choice survives a reload and carries across to this site.Until you clear it
workframe-library-width, workframe-inspector-width localStorageWorkframe The panel widths you dragged, so the editor reopens as you left it. Until you clear it

The three workframe-* keys hold interface preferences and no personal data. They never leave your browser.

This marketing site

workframeapp.com sets no cookies. It reads workframe-theme if the builder already set it, so that a reader who chose dark mode there is not flashed a white page here. Fonts are served from this origin rather than from Google Fonts, so loading a page here sends your IP address to no one but us.

Turning these off

You can clear or block cookies and site data for workframeapp.com in your browser's settings, or clear the workframe-* keys alone through its developer tools. Blocking __session will sign you out and prevent signing in — it is the mechanism that authenticates you, so there is no version of the product that works without it. Nothing else here affects whether Workframe functions.

Verification status

The rows above are drawn from the application's source. Cookie behaviour that originates with a provider rather than our code — Cloudflare's bot-management cookie in particular, which depends on zone settings — should be confirmed against a real production session before this page is published, and any additional cookie found added here.