Cookie Policy
This Cookie Policy names every cookie and every other piece of browser storage WorkSell uses: what it is for and how long it lasts.
1. What are Cookies?
Cookies are small text files a website stores on your device. Your browser's sessionStorage, localStorage and IndexedDB work in a similar way. WorkSell uses them only to make the site work — not for advertising, and not to track what you do.
What We Use Them For
- Keeping you signed in
- Protecting sign-in and the Stripe connection against forgery
- Stopping a retried refund from being sent twice
- Counting how many visits come from AI answer engines — as daily totals only
2. Cookies We Set
WorkSell sets exactly these three cookies, all for worksell.app only:
__sessionStrictly necessary · HttpOnlyKeeps you signed in to your dashboard and your purchases. Set when you sign in; scripts on the page cannot read it.
Kept for: 5 days, or until you sign out
worksell_auth_hintFunctional · no identifierHolds only the value “1”, meaning “someone has signed in on this browser”. The Buy button reads it to load the sign-in library only when you might be signed in. It grants no access and is readable by scripts.
Kept for: 1 year, or until you sign out
stripe_connect_stateStrictly necessary · HttpOnly · sellers onlyA one-time value that protects the hand-off to Stripe when you connect your Stripe account, so no one else can complete the connection for you. Only sent to /api/stripe.
Kept for: 1 hour, or until the connection completes
3. Other Storage in Your Browser
These are not cookies and are never sent to our server automatically:
Firebase Authentication (IndexedDB “firebaseLocalStorageDb”)Strictly necessaryKeeps you signed in between visits and refreshes your sign-in token. If your browser blocks IndexedDB, Firebase uses localStorage instead.
Kept for: Until you sign out
aeo_source (sessionStorage)Aggregate measurementOnly when you arrive from an AI answer engine (ChatGPT, Perplexity, Claude, Gemini or Copilot): which one, so a signup or purchase in the same tab can be counted in our daily totals.
Kept for: Until you close the tab
ws_session_sync_attempt (sessionStorage)Strictly necessaryThe time of the last attempt to set up your session before a redirect, so a failing sign-in cannot loop.
Kept for: Until you close the tab
worksell.productRefundOp.…, worksell.invoiceRefundOp.…, worksell.invoiceRefundUnconfirmed.… (sessionStorage)Strictly necessary · sellers onlyRemembers a refund you have started, so retrying it after a network error cannot refund the buyer twice.
Kept for: Until the refund is confirmed, or you close the tab
Analytics
No analytics or marketing cookies
- • We set no optional analytics or marketing cookies, and we use no third-party analytics service.
- • We do measure how many visits arrive from AI answer engines such as ChatGPT, Perplexity, Claude, Gemini or Copilot. This is stored in your browser's sessionStorage (see aeo_source above) rather than in a cookie, and it is discarded when you close the tab.
- • Only daily totals are kept — a count per referral source and page. There is no profile, no identifier, and no record of any individual visit. Totals are retained for two years.
Aggregate counts only — no cookies, no identifiers
4. Managing Your Cookies
You can control cookies and site storage through your browser settings. Most browsers allow you to:
- View and delete existing cookies and site data
- Block cookies from specific websites
- Block third-party cookies
- Set preferences for cookie acceptance
Without the strictly necessary entries, sign-in, account management and refunds do not work. Without worksell_auth_hint everything works, but the Buy button will not recognise an existing buyer account.
5. Third-Party Services
These services process data for WorkSell. Only Stripe and Google set cookies, and only on their own sites:
Firebase (Google)
Used for sign-in, database, and file storage (product files, cover images, profile photos, buyer downloads). Your browser loads images directly from Google's servers (firebasestorage.googleapis.com). The sign-in storage above belongs to Firebase. Signing in with Google opens Google's sign-in window, where Google sets its own cookies.
Google Privacy Policy →Stripe
Used for payment processing via Stripe Connect. You pay on Stripe's own checkout page (checkout.stripe.com), and sellers connect their account on connect.stripe.com. Stripe sets its own cookies there, for example for fraud prevention. WorkSell's own pages load no Stripe scripts.
Stripe Privacy Policy →Resend
Used to deliver transactional email (login codes, invoices, download links, contact-form messages). Resend sets no cookies on this site; we list it here because recipient names and email addresses pass through it.
Resend Privacy Policy →6. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Cookie Policy on this page.
Last updated: 26 September 2026