Back to Workbench

Workbench Cookie Notice

Effective date
2026-08-24
Version
workbench-public-cookies-owner-approved-2026-08-24-r3

Optional analytics update — September 13, 2026

The optional analytics sections below update the earlier essential-only description. Analytics requires its own permission and is not required to use Workbench. Your account terms and content ownership protections continue.

Supplement version: workbench-optional-analytics-2026-09-13-v2

Current storage choices

Essential storage and optional analytics

Workbench uses essential cookies and browser storage to provide and secure the Service. If you choose Allow analytics, it also uses optional browser storage to recognize repeat visits and understand product usage with PostHog. Optional analytics does not start before you agree. Choose No thanks to continue with essential technologies only. No ad-network cookies, cross-site tracking, behavioral-advertising pixels, or session replay are enabled.

The workbench-analytics-consent-v1 local-storage entry saves your choice, notice version and choice time for up to 180 days. Saving this preference does not itself send an analytics event. After you agree, workbench-analytics-visitor-v1 stores a random browser identifier in local storage, and workbench-analytics-session-v1 stores an analytics session identifier and last-activity time in session storage. A new analytics session begins after 30 minutes without a tracked page visit or when the browser session ends. We do not load a PostHog browser script. A secure, host-only __Host-workbench-analytics-v2 cookie preserves your accepted choice across the sign-in callback, which clears Web Storage. It expires with your choice, after at most 180 days; it may also hold the fixed paid-search campaign code for up to 30 days. It contains no account or browser identifier. workbench-analytics-completion-v2 entries prevent repeat milestone submissions and contain a pseudonymous account reference and milestone name. Withdrawal removes these entries and the cookie from accessible storage. Signing out clears the cookie.

Use Analytics preferences, including on this page, to change your choice. Withdrawal stops new collection and removes these analytics identifiers from accessible storage; essential sign-in and workspace records remain separate. Identifiers otherwise remain until storage is cleared or a later visit detects withdrawal, an expired choice, or a privacy signal. Global Privacy Control and Do Not Track keep optional analytics off. If browser storage is unavailable or we cannot save a choice, optional collection remains off. A storage failure can prevent a choice from persisting; clear site storage in your browser to remove a previously saved choice. The Privacy Notice explains the information sent to PostHog, provider handling and privacy requests.

What the essential technologies do

  • Authentication and session security: keep you signed in, protect the session, and support account verification and recovery.
  • Request and abuse protection: help prevent cross-site request forgery, replay, automated abuse, and excessive requests.
  • Continuity and preferences: remember the selected workspace or project, interface preferences, unsent drafts, and opaque request or session identifiers needed to complete an action. Workbench does not intentionally retain complete conversation bodies in browser storage after signout or an account change.
  • CAPTCHA: Cloudflare Turnstile may use necessary browser and device signals when public account creation is enabled.
  • Billing: Stripe may use necessary cookies and browser storage on its hosted checkout and customer-portal pages.
  • Hosting and delivery: Vercel and Supabase receive ordinary request and security data needed to deliver and protect the Service.

How long first-party storage lasts

  • Access continuity: up to 15 minutes.
  • Selected workspace and scope: up to 30 days.
  • Timezone and timezone source: up to one year.
  • Authentication: for the authenticated session lifetime, subject to the authentication provider's security and refresh controls.
  • Session storage: ordinarily until the browser tab or session ends.
  • Local storage: until the preference, unsent draft, or continuity record is replaced, signout or account change removes content-bearing HardwareHub records, or the user clears browser storage. Workbench removes obsolete records when the relevant workflow supports it.

Turnstile, Stripe, Google sign-in, Supabase, and Vercel may use necessary cookies or device signals under their own notices when the corresponding feature is enabled. HardwareHub does not authorize those providers to use Workbench User Content for advertising.

Your controls

Browser controls can remove or block cookies and storage, but essential features may then stop working. Optional analytics follows the choice and browser-signal controls described above.

Questions or requests: privacy@hardwarehub.io.