Draft pending legal review

Cookie policy | Weform

Which cookies and browser storage Weform uses, what they are for and how to change your choice.

Draft prepared on 26 August 2026

1. Scope of this document

This policy describes the cookies and browser storage used by the Weform website and platform, what they are for, how long they last and how to change your choice. It complements the privacy policy, which explains who processes the data, for what purpose and on what legal basis. This document is a draft and must be checked against the production configuration before it can be considered final.

2. Cookies and other technologies

A cookie is a small file that the site stores in your browser and that travels back with every request, so the server can read it without running JavaScript. Weform uses cookies for the session and for the preferences the server already needs to know about, such as language or theme. Two other technologies also store data on your device without being cookies: local storage (localStorage), which holds interface preferences such as the media library view and, only if you accept, the analytics data; and IndexedDB, where Firebase Auth keeps your session so you do not have to sign in on every visit.

3. Necessary cookies

Without them the platform cannot be provided: they keep you signed in, preserve your settings and remember the choice you make about analytics. They therefore require no consent and cannot be switched off from the notice, although you can always delete them from your browser. All of them are Weform first-party cookies, with Path=/, SameSite=Lax and the Secure flag when the connection is HTTPS.

  • __session: keeps you signed in and lets the server authorise access to private areas. It lasts five days and is deleted when you sign out or when the server finds it is no longer valid.
  • NEXT_LOCALE: remembers the language you chose so it is not negotiated again on every visit. It lasts one year.
  • weform-theme: remembers whether you prefer the light or dark theme and allows it to be applied before the first render, with no flash. It lasts one year.
  • weform-sidebar-collapsed: remembers whether you left the workspace sidebar collapsed. It lasts one year.
  • weform_analytics_consent: stores your decision about analytics, accepted or rejected, along with the version of the notice you answered, so you are not asked again. It lasts one year.

4. Product analytics

Product analytics is the only non-necessary purpose and it stays off until you accept it explicitly: until then the provider is not loaded, nothing is stored in your browser and no request leaves your device. The provider is PostHog, in its European region, processing the data on Weform's behalf. It exists to show which parts of the product are used and where something breaks. It is not used for advertising or profiling, and it is not shared with third parties for commercial purposes.

  • Where it is stored: PostHog uses the browser's local storage, not its own cookies. It keeps a device identifier (ph_ keys) and the record of your acceptance (weform_posthog_consent). Withdrawing your permission clears that storage.
  • What is measured: page views with the canonical route —for example /workspace/organization/projects/[id], never the real identifier—, a closed catalogue of product events with enumerated values, the language and the area of the application. If you are signed in, the technical identifier of your account and the active organisation as a group are added.
  • What is not measured: there is no session recording, heatmaps, automatic click capture or surveys. What you type, your email and your name are never sent. Only the canonical path of a URL is kept, and advertising click identifiers such as gclid, fbclid, msclkid, ttclid or li_fat_id are discarded.

5. How your consent is asked for and stored

The first time you visit, a notice appears with three options at the same level: accept, reject and configure. Rejecting costs exactly as much as accepting and does not limit your use of the platform. Until you answer, analytics stays off. Your decision is stored for one year in the weform_analytics_consent cookie, together with a version number. If the purposes or the provider change, that version is raised and you are asked again, instead of silently inheriting a permission granted for something else.

6. Changing or withdrawing your choice

You can review your choice at any time from Cookie preferences, available in the footer and at the end of this document. Withdrawing your permission stops the capture and deletes the identifier analytics kept in your browser. You can also delete or block cookies from your browser. If you delete the consent cookie you will be asked again; if you delete or block the necessary ones, you will lose your language and theme and will have to sign in again.

7. Third parties

Weform carries no advertising and no tracking networks. The only third parties that may store data in your browser are the providers required to run the service and, when you accept it, the analytics provider.

  • PostHog, in its European region, as the product analytics provider. It only receives data if you accept, and only on Weform's own surfaces.
  • Firebase, by Google, for authentication and platform operation. It keeps your session in the browser and is essential in order to reach your account.
  • Stripe when a plan is purchased. Its payment flow may set its own cookies, needed to complete the transaction and prevent fraud, under its own policies.
  • External video providers such as YouTube, when an organisation chooses to host its video there. Playback involves a direct connection with that provider, which applies its own cookies and policies.

8. Published experiences and embeds

The experience player, the embedded versions running on another site and the public organisation pages neither show this notice nor enable Weform's product analytics. What happens inside an experience belongs to the organisation that published it and is measured in its own space, with whatever technical storage the experience requires to work. That organisation is responsible for informing its participants and, where applicable, for collecting consent on the site where it embeds the experience. The same applies under a partner's domain: their brand and their cookie policy govern there, not Weform's.

9. Updates to this policy

This policy will be reviewed whenever the cookies in use, the analytics provider, the purposes or the applicable law change. Changes affecting analytics require consent to be requested again. The final version must show an effective date and a review date.