1. What we store
The following items are first-party and are set by WorkTogether in your browser.
- wt_refresh: an HttpOnly authentication cookie, normally kept for up to 14 days, rotated during refresh and removed or revoked on logout.
- wt_locale: your interface language, kept for up to one year.
- theme in localStorage: your light, dark or system appearance choice, kept until you clear it.
- Versioned project, application and message drafts in localStorage: kept for up to 30 days, removed after a successful submission or explicit discard. Files are never stored in these drafts.
- wt_privacy_choice_v1 in localStorage: records whether this browser accepted or rejected optional analytics, together with the choice time and policy version. It prevents us from asking on every page and remains until you change it or clear site data.
- A push subscription: created only after you enable notifications; it is stored by the browser, push provider and WorkTogether until you disable or revoke it.
2. Optional anonymous device analytics
The first time you visit, a banner offers an equal choice between necessary storage only and optional analytics. Analytics remains off until you actively allow it.
After opt-in, one event is sent per browser session. The server immediately classifies the request and stores only the event time, broad device category (desktop, phone, tablet or other), operating system, browser family and consent-policy version.
- We do not store the IP address, raw user-agent string, account ID, advertising ID or a persistent analytics visitor ID in these events.
- The statistics are used only to prioritise browser, device and responsive-layout testing.
- Events are retained for up to 180 days and administrators can access only aggregate charts.
3. Your choice and withdrawal
Accepting and rejecting are available on the first banner with the same number of steps. You can change the choice at any time with the controls on this page.
Withdrawing stops future analytics events and does not affect login or other core features. Because past events contain no visitor or account identifier, they cannot be linked back to you for individual deletion.
4. Necessary storage and browser controls
You can sign out to revoke the active refresh session, disable push in your profile or browser, discard individual drafts, or clear WorkTogether site data in browser settings.
Blocking all necessary cookies can prevent login and other requested features from working.
5. Changes and contact
We update this page when storage purposes, providers or retention periods change. Questions can be sent to support@worktogether.app.