Skip to main content
Back to Homepage

Cookie Policy

This Cookie Policy names every cookie and every other piece of browser storage WorkSell uses: what it is for and how long it lasts.

1. What are Cookies?

Cookies are small text files a website stores on your device. Your browser's sessionStorage, localStorage and IndexedDB work in a similar way. WorkSell uses them only to make the site work — not for advertising, and not to track what you do.

What We Use Them For

  • Keeping you signed in
  • Protecting sign-in and the Stripe connection against forgery
  • Stopping a retried refund from being sent twice
  • Counting how many visits come from AI answer engines — as daily totals only

2. Cookies We Set

WorkSell sets exactly these three cookies, all for worksell.app only:

  • __sessionStrictly necessary · HttpOnly

    Keeps you signed in to your dashboard and your purchases. Set when you sign in; scripts on the page cannot read it.

    Kept for: 5 days, or until you sign out

  • worksell_auth_hintFunctional · no identifier

    Holds only the value “1”, meaning “someone has signed in on this browser”. The Buy button reads it to load the sign-in library only when you might be signed in. It grants no access and is readable by scripts.

    Kept for: 1 year, or until you sign out

  • stripe_connect_stateStrictly necessary · HttpOnly · sellers only

    A one-time value that protects the hand-off to Stripe when you connect your Stripe account, so no one else can complete the connection for you. Only sent to /api/stripe.

    Kept for: 1 hour, or until the connection completes

3. Other Storage in Your Browser

These are not cookies and are never sent to our server automatically:

  • Firebase Authentication (IndexedDB “firebaseLocalStorageDb”)Strictly necessary

    Keeps you signed in between visits and refreshes your sign-in token. If your browser blocks IndexedDB, Firebase uses localStorage instead.

    Kept for: Until you sign out

  • aeo_source (sessionStorage)Aggregate measurement

    Only when you arrive from an AI answer engine (ChatGPT, Perplexity, Claude, Gemini or Copilot): which one, so a signup or purchase in the same tab can be counted in our daily totals.

    Kept for: Until you close the tab

  • ws_session_sync_attempt (sessionStorage)Strictly necessary

    The time of the last attempt to set up your session before a redirect, so a failing sign-in cannot loop.

    Kept for: Until you close the tab

  • worksell.productRefundOp.…, worksell.invoiceRefundOp.…, worksell.invoiceRefundUnconfirmed.… (sessionStorage)Strictly necessary · sellers only

    Remembers a refund you have started, so retrying it after a network error cannot refund the buyer twice.

    Kept for: Until the refund is confirmed, or you close the tab

Analytics

No analytics or marketing cookies

  • • We set no optional analytics or marketing cookies, and we use no third-party analytics service.
  • • We do measure how many visits arrive from AI answer engines such as ChatGPT, Perplexity, Claude, Gemini or Copilot. This is stored in your browser's sessionStorage (see aeo_source above) rather than in a cookie, and it is discarded when you close the tab.
  • • Only daily totals are kept — a count per referral source and page. There is no profile, no identifier, and no record of any individual visit. Totals are retained for two years.

Aggregate counts only — no cookies, no identifiers

4. Managing Your Cookies

You can control cookies and site storage through your browser settings. Most browsers allow you to:

  • View and delete existing cookies and site data
  • Block cookies from specific websites
  • Block third-party cookies
  • Set preferences for cookie acceptance

Without the strictly necessary entries, sign-in, account management and refunds do not work. Without worksell_auth_hint everything works, but the Buy button will not recognise an existing buyer account.

5. Third-Party Services

These services process data for WorkSell. Only Stripe and Google set cookies, and only on their own sites:

Vercel

Used for hosting and deployment of the website.

Vercel Privacy Policy →

Firebase (Google)

Used for sign-in, database, and file storage (product files, cover images, profile photos, buyer downloads). Your browser loads images directly from Google's servers (firebasestorage.googleapis.com). The sign-in storage above belongs to Firebase. Signing in with Google opens Google's sign-in window, where Google sets its own cookies.

Google Privacy Policy →

Stripe

Used for payment processing via Stripe Connect. You pay on Stripe's own checkout page (checkout.stripe.com), and sellers connect their account on connect.stripe.com. Stripe sets its own cookies there, for example for fraud prevention. WorkSell's own pages load no Stripe scripts.

Stripe Privacy Policy →

Resend

Used to deliver transactional email (login codes, invoices, download links, contact-form messages). Resend sets no cookies on this site; we list it here because recipient names and email addresses pass through it.

Resend Privacy Policy →

6. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Cookie Policy on this page.

Last updated: 26 September 2026