Last updated: September 1, 2026
This Cookie Policy explains how Cognardo Workbench uses cookies, local storage, browser storage, Chrome extension storage, and similar technologies.
Cognardo Workbench is operated under the public trade name Cognardo. For public-facing contact, Cognardo Workbench is represented by Raven Black.
This Cookie Policy applies to:
https://workbench.cognardo.com- the Cognardo Workbench Chrome extension
- Cognardo Workbench account, sync, AI, billing, and support services
- related website, account, and product features
This Cookie Policy should be read together with:
- the Privacy Policy at
/legal/privacy - the Terms of Service at
/legal/terms - the Acceptable Use Policy at
/legal/acceptable-use - the Data Processing page at
/legal/data-processing
1. What cookies and similar technologies are
Cookies are small files stored by a website in your browser.
Similar technologies include:
- localStorage
- sessionStorage
- browser storage
- Chrome extension storage
- authentication tokens
- device or installation identifiers
- cached account data
- security and performance logs
- payment-provider storage
- third-party authentication storage
These technologies help websites and extensions remember information, keep you signed in, save preferences, operate security features, support payments, provide product functionality, and improve reliability.
2. Current website cookie and storage inventory
The website currently uses the following cookies and browser storage. A provider-controlled name or duration can change when that provider updates its security or payment service.
| Name or storage | Provider and type | When it is used | Purpose | Normal duration | Optional sharing choice |
|---|---|---|---|---|---|
__Host-workbench_analytics_choice | Cognardo, secure first-party cookie | After you accept or decline optional usage sharing, or when a supported privacy signal keeps it off | Remembers and proves your privacy choice so Workbench does not repeatedly ask | Up to 180 days | Not required; this cookie only remembers the choice |
__Host-workbench_attribution_visitor | Cognardo, secure first-party cookie | Only after you choose Share usage information | Holds a random visitor identifier for product analytics and acquisition attribution | Up to 90 days | Required |
workbench.auth.session | Cognardo, localStorage | After you sign in | Keeps the requested website account session available between pages and visits | Until logout, token expiry, or browser-data clearing | Not required; authentication storage |
| Firebase authentication storage | Google Firebase, provider-managed browser storage | After account authentication | Authenticates permitted account and Firestore access | Until logout, expiry, or browser-data clearing | Not required; authentication storage |
g_state | Google Identity Services, cookie on the Workbench domain | On pages offering Google sign-in, where Google sets it | Remembers Google sign-in or sign-out state and prevents repeated or looping sign-in experiences | Google-controlled; generally up to approximately six months where set | Not used for Workbench analytics; authentication functionality |
workbench-theme | Cognardo, localStorage | When you select light or dark appearance | Applies the appearance you requested | Until changed or browser-data clearing | Not required; user-selected preference |
workbench.account.summary.<uid> | Cognardo, sessionStorage | While a signed-in account page is in use | Briefly reuses an account summary so account and billing pages appear promptly; the backend still verifies every protected action | Used for up to 15 minutes and cleared with the tab session | Not used for analytics |
workbench.billing.subscription-attempt:* and workbench.billing.topup-attempt:* | Cognardo, sessionStorage | After you request the related checkout | Prevents an accidental duplicate subscription or credit purchase attempt | Current tab session or earlier successful completion | Not required; requested checkout functionality |
workbench.checkout.discountCode | Cognardo, sessionStorage | After you enter or apply a checkout code | Carries the requested code through the current checkout | Current tab session or earlier checkout completion | Not required; requested checkout functionality |
workbench-attribution-session-v1 and workbench-attribution-touch-sent-v1 | Cognardo, sessionStorage | Only after you choose Share usage information | Groups permitted attribution activity within a tab and avoids duplicate sends | Current tab session | Required |
cf_clearance | Cloudflare, secure provider cookie | When Cloudflare verifies that a browser passed a security check | Preserves the successful security verification so the visitor can reach and continue using the website | Controlled by the active Cloudflare security configuration | Not required; essential website security |
| Paddle checkout cookies and storage | Paddle, provider-controlled cookies and browser storage | Only after you start checkout, payment-method, cancellation, or another billing-management flow that requires Paddle | Operates checkout, payment security, fraud prevention, tax calculation, transaction continuity, subscription management, and buyer support | Varies by the Paddle flow, payment method, and security check | Core payment storage is used for the payment or billing service you requested |
| Paddle Retain and ProfitWell storage | Paddle and ProfitWell, provider-controlled storage | Only for a signed-in Paddle customer who has chosen Share usage information; not on an ordinary anonymous homepage or pricing visit | Permitted subscription analytics and customer-retention messages | Provider-controlled and variable | Required before this optional initialization |
The website does not currently use cookies for third-party advertising. It also does not use a client-side advertising or marketing analytics SDK such as Google Analytics, PostHog, Plausible, or Sentry. Workbench's own optional product analytics and acquisition attribution are described below.
3. Chrome extension storage is not the same as website cookies
The Cognardo Workbench Chrome extension uses Chrome extension storage. This is different from normal website cookies.
The extension may use Chrome extension local or session storage to store:
- authentication state
- account cache
- local prompts, conversations, scratchpads, and library data
- prompt indexes
- chat title edits
- sync metadata
- retry queues
- analytics queues
- device or installation IDs
- settings and toggles
- permitted origins for optional site access
- copy formatting settings
- extension enabled or disabled state
- Cloud Sync & Intelligence settings
- other product state needed to operate the extension
This storage allows the extension to provide features such as local saving, sidebar behavior, prompt insertion, conversation tracking, copy settings, sync queues, permitted site access, and account-based functionality.
Removing the Cognardo Workbench Chrome extension from your browser clears local extension data from that browser.
4. Necessary and user-requested storage
Necessary storage is used only to deliver or secure a service you request, remember your privacy choice, authenticate an account, or complete a payment or other action you start. It is not controlled by the optional usage-sharing choice.
Necessary or user-requested storage may be used to:
- keep you signed in
- authenticate account sessions
- operate website account pages
- operate extension features
- remember a setting or appearance you select
- remember extension state
- manage Cloud Sync & Intelligence status
- save permitted origins
- preserve local workspace state
- provide security and abuse-prevention controls
- support backend communication
- prevent repeated authentication or session failures
Without this storage, the related security, account, preference, checkout, or extension function may not work properly. It is not repurposed for Workbench advertising or optional acquisition attribution.
4.1 Why some storage works without the optional sharing choice
The rule that determines whether browser storage needs advance permission is separate from the data-protection rule that requires a lawful reason to process personal information. Workbench applies both tests.
| Activity | Why it can operate without the optional sharing choice | Main data-protection reason |
|---|---|---|
| Remembering an accept or decline choice | Needed to remember and demonstrate the privacy instruction | Compliance with privacy obligations and legitimate interests in respecting and documenting the choice |
| Account authentication, Firebase authentication, and Google sign-in | Needed to provide the sign-in or account service the person requests | Performing the requested account service and legitimate interests in account security |
| Cloudflare security checks | Needed to protect the website and avoid repeating a completed challenge | Legitimate interests in service security, fraud prevention, and availability; legal obligations where applicable |
| A theme or functional preference selected by the person | Needed to provide the setting the person expressly requests | Performing the requested service and legitimate interests in providing a consistent product experience |
| Checkout, payment, tax, fraud prevention, and subscription actions started by the buyer | Needed to complete or administer the payment or billing service requested | Steps requested before or under a contract, legitimate interests in payment security, and tax, accounting, or other legal obligations |
| Optional Workbench attribution, product analytics, and Paddle Retain or ProfitWell initialization | Not necessary to use Workbench | Consent; these activities remain off unless Share usage information is chosen |
Where consent is the basis, it is optional, can be refused without losing the core service, and can be withdrawn from Privacy Settings. A provider name alone does not make storage necessary: analytics, marketing, or customer-retention storage remains optional even when the provider also supplies payments or security.
5. Authentication storage
Cognardo Workbench may use authentication-related storage to support:
- email/password login
- Google sign-in
- backend sessions
- Firebase authentication
- account verification
- account settings
- profile management
- session refresh
- account security
The website stores its account session in workbench.auth.session localStorage rather than a first-party login cookie. Firebase uses provider-managed authentication storage after login. Google Identity Services may set g_state on signup and sign-in pages to remember Google sign-in or sign-out state. The Google button uses the browser-mediated FedCM flow where supported.
If you disable or clear authentication storage, you may be signed out or unable to access account-based features.
6. Preference storage
We may use browser or extension storage to remember preferences such as:
- theme preference
- sidebar position
- sidebar width
- sidebar mode
- floater button settings
- copy settings
- shortcut settings
- active instruction profile setting
- Cloud Sync & Intelligence setting
- approved site access
- product layout preferences
On the website, workbench-theme is written only when you choose an appearance. Preference storage helps Cognardo Workbench behave the way you configured it and is not used for acquisition attribution.
7. Product functionality storage
Cognardo Workbench may use local browser or extension storage to support product functionality, including:
- local workspace history
- prompt libraries
- prompt sequences
- scratchpads
- instruction profiles
- conversation metadata
- pinned prompts or responses
- export settings
- import state
- copy formatting settings
- sync metadata
- retry queues
- feature state
- AI action history where stored locally
- citation-related feature state
The website's account-summary performance cache uses sessionStorage rather than persistent localStorage, is considered fresh for no more than 15 minutes, and is not trusted for protected account or billing actions. Some extension product functionality storage may be local-only. Other product data may sync to cloud infrastructure when Cloud Sync & Intelligence is enabled or when a feature requires cloud processing.
8. Analytics and diagnostics storage
Cognardo Workbench may use local or extension storage to support product analytics, diagnostics, performance monitoring, and reliability.
This may include:
- analytics queue storage
- event IDs
- device or installation IDs
- session IDs
- timestamps
- extension version
- feature usage events
- setting toggles
- plan state
- diagnostic or runtime telemetry
- error or performance metadata
This information helps us understand whether features work, troubleshoot issues, improve reliability, prevent abuse, and improve Cognardo Workbench.
Search-related analytics are designed not to include raw search query text. Search analytics may include metadata such as query length instead.
We do not use analytics storage for third-party advertising.
8.1 Optional Workbench analytics and acquisition attribution
Workbench asks before creating its optional first-party analytics visitor identifier or storing acquisition information. If you choose Share usage information, we may use a secure first-party cookie to remember a random visitor identifier for up to 90 days. We remember either acceptance or refusal in the separate __Host-workbench_analytics_choice cookie for up to 180 days so that we do not repeatedly ask you.
With this permission, Workbench may collect limited information such as:
- the Workbench landing page path, without unrelated query parameters
- campaign fields you followed, such as approved UTM fields, an affiliate code, or approved advertising click identifiers
- the referring website's hostname, without the full referring URL
- a random visitor, session, event, or extension-installation identifier
- browser family, extension version, distribution store, and Workbench feature events
- signup, activation, and payment milestones derived from Workbench's own account and billing systems
We do not use this information for third-party advertising and do not sell it. We do not include raw search text, prompts, chats, scratchpad content, email addresses, passwords, authentication tokens, full URLs, or full IP addresses in acquisition attribution records.
Website permission controls website analytics, attribution, visitor-to-account linking, and optional Paddle/ProfitWell tracking. Accepting also enables extension product analytics through a short-lived setup handoff or after sign-in. The extension does not read website cookies. Each surface keeps its own protected receipt or cookie, and the account stores the website choice. Cloud Sync can independently enable extension product analytics, but it cannot enable website cookies or tracking. Workspace uploads depend only on the extension Cloud Sync setting.
If you choose Continue without sharing, we remember the website choice and do not create the optional website visitor identifier. Change this choice at /privacy-settings. Extension product analytics can continue if Cloud Sync is enabled; to stop it, both website sharing and extension Cloud Sync must be off. Turning off Cloud Sync does not change your website choice. Updated website choices reach signed-in extensions when they next start, open, or refresh. Private chats, prompts, and scratchpads are not used for attribution or affiliate commissions.
Browser or infrastructure signals such as Global Privacy Control may be used to keep optional sharing off where applicable. Essential security, authentication, fraud-prevention, and service-delivery processing remains separate from this optional choice.
9. Cloudflare and hosting-related storage
The Cognardo Workbench website may be served through Cloudflare Workers or related Cloudflare infrastructure.
The live website can set cf_clearance after Cloudflare verifies a browser. It proves that the security check was completed and prevents the same visitor from being challenged on every request. It is necessary security storage and is not part of optional Workbench analytics.
Cloudflare may also process request metadata and, where the corresponding protection is enabled, use security cookies or similar technologies for purposes such as:
- website delivery
- routing
- security
- performance
- abuse prevention
- bot detection
- traffic management
- edge logging
Names and durations for additional Cloudflare security cookies depend on the protection active at the time you access the website. They are disclosed here as provider-controlled security storage, not as advertising or attribution cookies.
10. Google and Firebase storage
Cognardo Workbench uses Google and Firebase services for authentication, Google sign-in, database access, custom tokens, profile data, and backend connectivity.
Google or Firebase may use cookies, browser storage, tokens, or similar technologies to:
- authenticate you
- verify your Google sign-in
- maintain Firebase sessions
- connect the website to backend account services
- protect account security
- support cloud database access
On the current signup and sign-in pages, Google Identity Services may set g_state to remember Google sign-in or sign-out state. Cognardo does not read that cookie for analytics. Google or the browser controls the Google account chooser and identity flow, and Google sign-in is subject to Google's own terms and privacy practices.
11. Payment-provider cookies and storage
Payments are processed by Paddle.
Paddle.js is not loaded on an ordinary anonymous homepage or pricing visit. It loads when a visitor starts checkout or when an authenticated customer opens a payment, cancellation, or billing function that requires Paddle. Paddle may then use provider-controlled cookies, an embedded checkout frame, and browser storage to:
- operate checkout
- process payments
- prevent fraud
- calculate taxes
- generate invoices
- manage subscriptions
- provide buyer support
- verify transaction status
- manage billing portals or payment confirmation flows
Paddle cookie names and durations can vary by checkout, payment method, country, fraud check, and provider update. Core checkout, security, fraud-prevention, tax, and transaction-continuity storage is used only for the payment or billing flow the buyer requested.
Paddle also operates ProfitWell and may offer analytics and customer-retention features. Workbench treats that separate initialization as optional: it runs only for a signed-in Paddle customer who has chosen Share usage information. It does not run for an anonymous homepage or pricing visitor. Refusing or leaving the Workbench choice unanswered does not prevent checkout, payment-method management, or cancellation; Paddle can still load when the customer deliberately starts that billing action.
Cookies with analytics or marketing names on .paddle.com or .profitwell.com—for example _ga, _gcl_au, _clck, _hjSessionUser_*, __hstc, hubspotutk, or ajs_*—are not classified by Workbench as necessary payment cookies merely because they appear on a Paddle-owned domain. They may already exist in a browser after a person visits or uses a Paddle-owned service. After an ordinary Workbench page stops requesting those domains, existing provider cookies may remain visible in browser settings until they expire or are cleared, but Workbench does not read them.
Paddle's own checkout, buyer, privacy, and cookie notices apply inside Paddle-controlled payment surfaces. Paddle is responsible for any separate choices it presents within those surfaces. Cognardo does not use Paddle-domain cookies for its own acquisition attribution.
12. AI provider and third-party service storage
When you use Cognardo Workbench, some features may interact with third-party services such as AI providers, search providers, authentication providers, hosting providers, payment providers, or browser platform services.
These third parties may use their own cookies, storage, logs, tokens, or similar technologies when you interact with their services directly or indirectly.
This Cookie Policy does not control third-party websites or services. Their own policies apply.
13. Advertising cookies
Cognardo Workbench does not currently use cookies or extension storage for third-party advertising.
We do not use your user content for third-party advertising.
We do not create third-party advertising profiles from your workspace content.
If this changes in the future, we will update this Cookie Policy and related privacy disclosures as required.
14. Managing website cookies and browser storage
You can manage website cookies and browser storage through your browser settings.
Depending on your browser, you may be able to:
- block cookies
- delete cookies
- clear localStorage
- clear sessionStorage
- clear site data
- block third-party cookies
- manage stored passwords or tokens
- clear cached data
If you block or delete cookies and browser storage, some Cognardo Workbench website features may not work properly. You may be signed out, lose preferences, or be unable to access account features.
15. Managing Chrome extension storage
Chrome extension storage is managed differently from website cookies.
To manage Cognardo Workbench extension storage, you may be able to:
- change settings inside Cognardo Workbench
- disable Cloud Sync & Intelligence
- revoke optional site permissions
- sign out
- delete saved items
- delete your account
- remove the Cognardo Workbench Chrome extension from Chrome
- clear extension data through Chrome controls where available
Removing the Cognardo Workbench Chrome extension from your browser clears local extension data from that browser.
Account deletion clears cloud account data through the account deletion process, but it may not remove local extension data from every browser or device where the extension remains installed.
16. Consequences of disabling cookies or storage
If you disable, block, or clear cookies, local storage, browser storage, or extension storage, Cognardo Workbench may not function correctly.
You may lose access to:
- account sessions
- login state
- theme preference
- saved settings
- local workspace data
- local prompts
- local conversations
- scratchpads
- sync queues
- permitted site access
- extension configuration
- billing or account pages
- cloud-backed features
- AI features
- citation analysis
- cross-device sync
- account restore
Some features require storage to work. Others may require Cloud Sync & Intelligence or backend processing.
17. Do Not Track
Some browsers offer “Do Not Track” signals.
There is no universally accepted standard for how websites should respond to Do Not Track signals. Cognardo Workbench does not currently respond to Do Not Track signals in a separate or automated way.
You can still manage cookies, browser storage, extension permissions, and local data through your browser, Chrome extension controls, and Cognardo Workbench settings.
18. Changes to this Cookie Policy
We may update this Cookie Policy from time to time.
When we make material changes, we may notify you by updating the date at the top of this page, posting a notice on the website, sending an email, showing an in-product notice, or using another reasonable method.
Your continued use of Cognardo Workbench after an updated Cookie Policy becomes effective means you accept the updated policy to the extent permitted by law.
19. Contact
For questions about this Cookie Policy, contact:
- Product support and privacy requests:
support@workbench.cognardo.com - General contact:
contact@workbench.cognardo.com - Billing, account, refund, and subscription questions:
accounts@workbench.cognardo.com - Security and abuse reports:
security@workbench.cognardo.com
Public contact name: Raven Black Public trade name: Cognardo Product: Cognardo Workbench