Legal

Cookie Policy

How Cognardo Workbench uses cookies, local storage, browser storage, Chrome extension storage, and similar technologies.

Last updated: September 1, 2026

This Cookie Policy explains how Cognardo Workbench uses cookies, local storage, browser storage, Chrome extension storage, and similar technologies.

Cognardo Workbench is operated under the public trade name Cognardo. For public-facing contact, Cognardo Workbench is represented by Raven Black.

This Cookie Policy applies to:

  • https://workbench.cognardo.com
  • the Cognardo Workbench Chrome extension
  • Cognardo Workbench account, sync, AI, billing, and support services
  • related website, account, and product features

This Cookie Policy should be read together with:

  • the Privacy Policy at /legal/privacy
  • the Terms of Service at /legal/terms
  • the Acceptable Use Policy at /legal/acceptable-use
  • the Data Processing page at /legal/data-processing

1. What cookies and similar technologies are

Cookies are small files stored by a website in your browser.

Similar technologies include:

  • localStorage
  • sessionStorage
  • browser storage
  • Chrome extension storage
  • authentication tokens
  • device or installation identifiers
  • cached account data
  • security and performance logs
  • payment-provider storage
  • third-party authentication storage

These technologies help websites and extensions remember information, keep you signed in, save preferences, operate security features, support payments, provide product functionality, and improve reliability.

The website currently uses the following cookies and browser storage. A provider-controlled name or duration can change when that provider updates its security or payment service.

Name or storageProvider and typeWhen it is usedPurposeNormal durationOptional sharing choice
__Host-workbench_analytics_choiceCognardo, secure first-party cookieAfter you accept or decline optional usage sharing, or when a supported privacy signal keeps it offRemembers and proves your privacy choice so Workbench does not repeatedly askUp to 180 daysNot required; this cookie only remembers the choice
__Host-workbench_attribution_visitorCognardo, secure first-party cookieOnly after you choose Share usage informationHolds a random visitor identifier for product analytics and acquisition attributionUp to 90 daysRequired
workbench.auth.sessionCognardo, localStorageAfter you sign inKeeps the requested website account session available between pages and visitsUntil logout, token expiry, or browser-data clearingNot required; authentication storage
Firebase authentication storageGoogle Firebase, provider-managed browser storageAfter account authenticationAuthenticates permitted account and Firestore accessUntil logout, expiry, or browser-data clearingNot required; authentication storage
g_stateGoogle Identity Services, cookie on the Workbench domainOn pages offering Google sign-in, where Google sets itRemembers Google sign-in or sign-out state and prevents repeated or looping sign-in experiencesGoogle-controlled; generally up to approximately six months where setNot used for Workbench analytics; authentication functionality
workbench-themeCognardo, localStorageWhen you select light or dark appearanceApplies the appearance you requestedUntil changed or browser-data clearingNot required; user-selected preference
workbench.account.summary.<uid>Cognardo, sessionStorageWhile a signed-in account page is in useBriefly reuses an account summary so account and billing pages appear promptly; the backend still verifies every protected actionUsed for up to 15 minutes and cleared with the tab sessionNot used for analytics
workbench.billing.subscription-attempt:* and workbench.billing.topup-attempt:*Cognardo, sessionStorageAfter you request the related checkoutPrevents an accidental duplicate subscription or credit purchase attemptCurrent tab session or earlier successful completionNot required; requested checkout functionality
workbench.checkout.discountCodeCognardo, sessionStorageAfter you enter or apply a checkout codeCarries the requested code through the current checkoutCurrent tab session or earlier checkout completionNot required; requested checkout functionality
workbench-attribution-session-v1 and workbench-attribution-touch-sent-v1Cognardo, sessionStorageOnly after you choose Share usage informationGroups permitted attribution activity within a tab and avoids duplicate sendsCurrent tab sessionRequired
cf_clearanceCloudflare, secure provider cookieWhen Cloudflare verifies that a browser passed a security checkPreserves the successful security verification so the visitor can reach and continue using the websiteControlled by the active Cloudflare security configurationNot required; essential website security
Paddle checkout cookies and storagePaddle, provider-controlled cookies and browser storageOnly after you start checkout, payment-method, cancellation, or another billing-management flow that requires PaddleOperates checkout, payment security, fraud prevention, tax calculation, transaction continuity, subscription management, and buyer supportVaries by the Paddle flow, payment method, and security checkCore payment storage is used for the payment or billing service you requested
Paddle Retain and ProfitWell storagePaddle and ProfitWell, provider-controlled storageOnly for a signed-in Paddle customer who has chosen Share usage information; not on an ordinary anonymous homepage or pricing visitPermitted subscription analytics and customer-retention messagesProvider-controlled and variableRequired before this optional initialization

The website does not currently use cookies for third-party advertising. It also does not use a client-side advertising or marketing analytics SDK such as Google Analytics, PostHog, Plausible, or Sentry. Workbench's own optional product analytics and acquisition attribution are described below.

3. Chrome extension storage is not the same as website cookies

The Cognardo Workbench Chrome extension uses Chrome extension storage. This is different from normal website cookies.

The extension may use Chrome extension local or session storage to store:

  • authentication state
  • account cache
  • local prompts, conversations, scratchpads, and library data
  • prompt indexes
  • chat title edits
  • sync metadata
  • retry queues
  • analytics queues
  • device or installation IDs
  • settings and toggles
  • permitted origins for optional site access
  • copy formatting settings
  • extension enabled or disabled state
  • Cloud Sync & Intelligence settings
  • other product state needed to operate the extension

This storage allows the extension to provide features such as local saving, sidebar behavior, prompt insertion, conversation tracking, copy settings, sync queues, permitted site access, and account-based functionality.

Removing the Cognardo Workbench Chrome extension from your browser clears local extension data from that browser.

4. Necessary and user-requested storage

Necessary storage is used only to deliver or secure a service you request, remember your privacy choice, authenticate an account, or complete a payment or other action you start. It is not controlled by the optional usage-sharing choice.

Necessary or user-requested storage may be used to:

  • keep you signed in
  • authenticate account sessions
  • operate website account pages
  • operate extension features
  • remember a setting or appearance you select
  • remember extension state
  • manage Cloud Sync & Intelligence status
  • save permitted origins
  • preserve local workspace state
  • provide security and abuse-prevention controls
  • support backend communication
  • prevent repeated authentication or session failures

Without this storage, the related security, account, preference, checkout, or extension function may not work properly. It is not repurposed for Workbench advertising or optional acquisition attribution.

4.1 Why some storage works without the optional sharing choice

The rule that determines whether browser storage needs advance permission is separate from the data-protection rule that requires a lawful reason to process personal information. Workbench applies both tests.

ActivityWhy it can operate without the optional sharing choiceMain data-protection reason
Remembering an accept or decline choiceNeeded to remember and demonstrate the privacy instructionCompliance with privacy obligations and legitimate interests in respecting and documenting the choice
Account authentication, Firebase authentication, and Google sign-inNeeded to provide the sign-in or account service the person requestsPerforming the requested account service and legitimate interests in account security
Cloudflare security checksNeeded to protect the website and avoid repeating a completed challengeLegitimate interests in service security, fraud prevention, and availability; legal obligations where applicable
A theme or functional preference selected by the personNeeded to provide the setting the person expressly requestsPerforming the requested service and legitimate interests in providing a consistent product experience
Checkout, payment, tax, fraud prevention, and subscription actions started by the buyerNeeded to complete or administer the payment or billing service requestedSteps requested before or under a contract, legitimate interests in payment security, and tax, accounting, or other legal obligations
Optional Workbench attribution, product analytics, and Paddle Retain or ProfitWell initializationNot necessary to use WorkbenchConsent; these activities remain off unless Share usage information is chosen

Where consent is the basis, it is optional, can be refused without losing the core service, and can be withdrawn from Privacy Settings. A provider name alone does not make storage necessary: analytics, marketing, or customer-retention storage remains optional even when the provider also supplies payments or security.

5. Authentication storage

Cognardo Workbench may use authentication-related storage to support:

  • email/password login
  • Google sign-in
  • backend sessions
  • Firebase authentication
  • account verification
  • account settings
  • profile management
  • session refresh
  • account security

The website stores its account session in workbench.auth.session localStorage rather than a first-party login cookie. Firebase uses provider-managed authentication storage after login. Google Identity Services may set g_state on signup and sign-in pages to remember Google sign-in or sign-out state. The Google button uses the browser-mediated FedCM flow where supported.

If you disable or clear authentication storage, you may be signed out or unable to access account-based features.

6. Preference storage

We may use browser or extension storage to remember preferences such as:

  • theme preference
  • sidebar position
  • sidebar width
  • sidebar mode
  • floater button settings
  • copy settings
  • shortcut settings
  • active instruction profile setting
  • Cloud Sync & Intelligence setting
  • approved site access
  • product layout preferences

On the website, workbench-theme is written only when you choose an appearance. Preference storage helps Cognardo Workbench behave the way you configured it and is not used for acquisition attribution.

7. Product functionality storage

Cognardo Workbench may use local browser or extension storage to support product functionality, including:

  • local workspace history
  • prompt libraries
  • prompt sequences
  • scratchpads
  • instruction profiles
  • conversation metadata
  • pinned prompts or responses
  • export settings
  • import state
  • copy formatting settings
  • sync metadata
  • retry queues
  • feature state
  • AI action history where stored locally
  • citation-related feature state

The website's account-summary performance cache uses sessionStorage rather than persistent localStorage, is considered fresh for no more than 15 minutes, and is not trusted for protected account or billing actions. Some extension product functionality storage may be local-only. Other product data may sync to cloud infrastructure when Cloud Sync & Intelligence is enabled or when a feature requires cloud processing.

8. Analytics and diagnostics storage

Cognardo Workbench may use local or extension storage to support product analytics, diagnostics, performance monitoring, and reliability.

This may include:

  • analytics queue storage
  • event IDs
  • device or installation IDs
  • session IDs
  • timestamps
  • extension version
  • feature usage events
  • setting toggles
  • plan state
  • diagnostic or runtime telemetry
  • error or performance metadata

This information helps us understand whether features work, troubleshoot issues, improve reliability, prevent abuse, and improve Cognardo Workbench.

Search-related analytics are designed not to include raw search query text. Search analytics may include metadata such as query length instead.

We do not use analytics storage for third-party advertising.

8.1 Optional Workbench analytics and acquisition attribution

Workbench asks before creating its optional first-party analytics visitor identifier or storing acquisition information. If you choose Share usage information, we may use a secure first-party cookie to remember a random visitor identifier for up to 90 days. We remember either acceptance or refusal in the separate __Host-workbench_analytics_choice cookie for up to 180 days so that we do not repeatedly ask you.

With this permission, Workbench may collect limited information such as:

  • the Workbench landing page path, without unrelated query parameters
  • campaign fields you followed, such as approved UTM fields, an affiliate code, or approved advertising click identifiers
  • the referring website's hostname, without the full referring URL
  • a random visitor, session, event, or extension-installation identifier
  • browser family, extension version, distribution store, and Workbench feature events
  • signup, activation, and payment milestones derived from Workbench's own account and billing systems

We do not use this information for third-party advertising and do not sell it. We do not include raw search text, prompts, chats, scratchpad content, email addresses, passwords, authentication tokens, full URLs, or full IP addresses in acquisition attribution records.

Website permission controls website analytics, attribution, visitor-to-account linking, and optional Paddle/ProfitWell tracking. Accepting also enables extension product analytics through a short-lived setup handoff or after sign-in. The extension does not read website cookies. Each surface keeps its own protected receipt or cookie, and the account stores the website choice. Cloud Sync can independently enable extension product analytics, but it cannot enable website cookies or tracking. Workspace uploads depend only on the extension Cloud Sync setting.

If you choose Continue without sharing, we remember the website choice and do not create the optional website visitor identifier. Change this choice at /privacy-settings. Extension product analytics can continue if Cloud Sync is enabled; to stop it, both website sharing and extension Cloud Sync must be off. Turning off Cloud Sync does not change your website choice. Updated website choices reach signed-in extensions when they next start, open, or refresh. Private chats, prompts, and scratchpads are not used for attribution or affiliate commissions.

Browser or infrastructure signals such as Global Privacy Control may be used to keep optional sharing off where applicable. Essential security, authentication, fraud-prevention, and service-delivery processing remains separate from this optional choice.

The Cognardo Workbench website may be served through Cloudflare Workers or related Cloudflare infrastructure.

The live website can set cf_clearance after Cloudflare verifies a browser. It proves that the security check was completed and prevents the same visitor from being challenged on every request. It is necessary security storage and is not part of optional Workbench analytics.

Cloudflare may also process request metadata and, where the corresponding protection is enabled, use security cookies or similar technologies for purposes such as:

  • website delivery
  • routing
  • security
  • performance
  • abuse prevention
  • bot detection
  • traffic management
  • edge logging

Names and durations for additional Cloudflare security cookies depend on the protection active at the time you access the website. They are disclosed here as provider-controlled security storage, not as advertising or attribution cookies.

10. Google and Firebase storage

Cognardo Workbench uses Google and Firebase services for authentication, Google sign-in, database access, custom tokens, profile data, and backend connectivity.

Google or Firebase may use cookies, browser storage, tokens, or similar technologies to:

  • authenticate you
  • verify your Google sign-in
  • maintain Firebase sessions
  • connect the website to backend account services
  • protect account security
  • support cloud database access

On the current signup and sign-in pages, Google Identity Services may set g_state to remember Google sign-in or sign-out state. Cognardo does not read that cookie for analytics. Google or the browser controls the Google account chooser and identity flow, and Google sign-in is subject to Google's own terms and privacy practices.

11. Payment-provider cookies and storage

Payments are processed by Paddle.

Paddle.js is not loaded on an ordinary anonymous homepage or pricing visit. It loads when a visitor starts checkout or when an authenticated customer opens a payment, cancellation, or billing function that requires Paddle. Paddle may then use provider-controlled cookies, an embedded checkout frame, and browser storage to:

  • operate checkout
  • process payments
  • prevent fraud
  • calculate taxes
  • generate invoices
  • manage subscriptions
  • provide buyer support
  • verify transaction status
  • manage billing portals or payment confirmation flows

Paddle cookie names and durations can vary by checkout, payment method, country, fraud check, and provider update. Core checkout, security, fraud-prevention, tax, and transaction-continuity storage is used only for the payment or billing flow the buyer requested.

Paddle also operates ProfitWell and may offer analytics and customer-retention features. Workbench treats that separate initialization as optional: it runs only for a signed-in Paddle customer who has chosen Share usage information. It does not run for an anonymous homepage or pricing visitor. Refusing or leaving the Workbench choice unanswered does not prevent checkout, payment-method management, or cancellation; Paddle can still load when the customer deliberately starts that billing action.

Cookies with analytics or marketing names on .paddle.com or .profitwell.com—for example _ga, _gcl_au, _clck, _hjSessionUser_*, __hstc, hubspotutk, or ajs_*—are not classified by Workbench as necessary payment cookies merely because they appear on a Paddle-owned domain. They may already exist in a browser after a person visits or uses a Paddle-owned service. After an ordinary Workbench page stops requesting those domains, existing provider cookies may remain visible in browser settings until they expire or are cleared, but Workbench does not read them.

Paddle's own checkout, buyer, privacy, and cookie notices apply inside Paddle-controlled payment surfaces. Paddle is responsible for any separate choices it presents within those surfaces. Cognardo does not use Paddle-domain cookies for its own acquisition attribution.

12. AI provider and third-party service storage

When you use Cognardo Workbench, some features may interact with third-party services such as AI providers, search providers, authentication providers, hosting providers, payment providers, or browser platform services.

These third parties may use their own cookies, storage, logs, tokens, or similar technologies when you interact with their services directly or indirectly.

This Cookie Policy does not control third-party websites or services. Their own policies apply.

13. Advertising cookies

Cognardo Workbench does not currently use cookies or extension storage for third-party advertising.

We do not use your user content for third-party advertising.

We do not create third-party advertising profiles from your workspace content.

If this changes in the future, we will update this Cookie Policy and related privacy disclosures as required.

14. Managing website cookies and browser storage

You can manage website cookies and browser storage through your browser settings.

Depending on your browser, you may be able to:

  • block cookies
  • delete cookies
  • clear localStorage
  • clear sessionStorage
  • clear site data
  • block third-party cookies
  • manage stored passwords or tokens
  • clear cached data

If you block or delete cookies and browser storage, some Cognardo Workbench website features may not work properly. You may be signed out, lose preferences, or be unable to access account features.

15. Managing Chrome extension storage

Chrome extension storage is managed differently from website cookies.

To manage Cognardo Workbench extension storage, you may be able to:

  • change settings inside Cognardo Workbench
  • disable Cloud Sync & Intelligence
  • revoke optional site permissions
  • sign out
  • delete saved items
  • delete your account
  • remove the Cognardo Workbench Chrome extension from Chrome
  • clear extension data through Chrome controls where available

Removing the Cognardo Workbench Chrome extension from your browser clears local extension data from that browser.

Account deletion clears cloud account data through the account deletion process, but it may not remove local extension data from every browser or device where the extension remains installed.

16. Consequences of disabling cookies or storage

If you disable, block, or clear cookies, local storage, browser storage, or extension storage, Cognardo Workbench may not function correctly.

You may lose access to:

  • account sessions
  • login state
  • theme preference
  • saved settings
  • local workspace data
  • local prompts
  • local conversations
  • scratchpads
  • sync queues
  • permitted site access
  • extension configuration
  • billing or account pages
  • cloud-backed features
  • AI features
  • citation analysis
  • cross-device sync
  • account restore

Some features require storage to work. Others may require Cloud Sync & Intelligence or backend processing.

17. Do Not Track

Some browsers offer “Do Not Track” signals.

There is no universally accepted standard for how websites should respond to Do Not Track signals. Cognardo Workbench does not currently respond to Do Not Track signals in a separate or automated way.

You can still manage cookies, browser storage, extension permissions, and local data through your browser, Chrome extension controls, and Cognardo Workbench settings.

We may update this Cookie Policy from time to time.

When we make material changes, we may notify you by updating the date at the top of this page, posting a notice on the website, sending an email, showing an in-product notice, or using another reasonable method.

Your continued use of Cognardo Workbench after an updated Cookie Policy becomes effective means you accept the updated policy to the extent permitted by law.

19. Contact

For questions about this Cookie Policy, contact:

  • Product support and privacy requests: support@workbench.cognardo.com
  • General contact: contact@workbench.cognardo.com
  • Billing, account, refund, and subscription questions: accounts@workbench.cognardo.com
  • Security and abuse reports: security@workbench.cognardo.com

Public contact name: Raven Black Public trade name: Cognardo Product: Cognardo Workbench