Bespoke AI
Cookie Policy
How Bespoke AI uses cookies, browser storage, and offline caches to keep the service secure and useful.
- Version
- 2026.09.1
- Effective
- 27 September 2026
What this policy covers
This policy covers cookies and similar browser technologies used by the Bespoke AI website and installable web application. A cookie is a small value a website asks your browser to keep. Similar technologies include local storage and Cache Storage.
These technologies serve different purposes and may have different controls in your browser. Our Privacy Policy explains the wider handling of personal information.
Essential sign-in and security storage
Our authentication system uses secure, same-site cookies to maintain your session, protect account flows, and reduce repeated session checks. These cookies are necessary for signed-in features to work. The current session may last for up to 30 days and is refreshed during active use; a short-lived session cookie cache may last for up to five minutes.
Security and rate-limit controls may also use request and account signals on the server. Blocking essential cookies can prevent sign-in, account verification, and the private workspace from working.
Preferences on your device
Bespoke AI uses local storage to remember settings on the device, including your selected light or dark appearance, whether onboarding has been completed, and your cookie choice itself. These values improve continuity and are not used to identify you.
Product analytics
Product analytics runs only after you allow it in Cookie preferences. Until you choose, and whenever you choose not to, PostHog is not loaded and no product events are sent. When you allow it, PostHog uses local storage to keep limited analytics state. Our configuration disables automatic capture, page-view and page-leave capture, heatmaps, surveys, experiments, exception capture, and session recording. We allow only named product events and remove private URL properties and IP enrichment before sending them. If you later take the permission back, analytics stops and its storage is cleared from the device.
We use this information to understand whether product actions work, not to read workspace content. Prompts, responses, uploaded files, and complete private URLs are outside the approved product-event contract.
Offline and installable-app storage
The installable web application uses browser Cache Storage for the application shell and selected brand assets. It can also keep eligible project and conversation responses in a separate private-history cache so recently accessed information may remain available when the network is unavailable.
The private-history cache is cleared when the application receives its private-data clearing instruction, including through the signed-out product flow. Clearing site data in your browser also removes locally cached copies. Do not rely on offline copies as your only record.
Third-party services
If you choose Google sign-in, visit a payment provider, follow an external support link, or use another connected service, that provider may set or read technology under its own policy. Bespoke AI does not control storage placed on an independent provider's domain.
Your choices
- Open Cookie preferences from the footer of any public page, or from Settings → General inside Bespoke AI, to allow or refuse product analytics. Your choice is kept on this device and applies until you change it or clear site data.
- Use your browser settings to inspect, block, or delete cookies and site data. Blocking essential cookies will limit signed-in features.
- Clear local storage and Cache Storage through your browser or device controls to remove preferences, analytics state, and offline copies from that device.
- Use the product sign-out flow before leaving a shared device, then clear site data if another person may have access to the browser profile.
- Browser privacy signals may affect third-party behavior, but Bespoke AI does not currently rely on a universal Do Not Track standard as a substitute for these controls.
How long storage remains
Duration depends on purpose, browser settings, and whether you clear site data. Authentication cookies follow the session periods described above. Preference and analytics values can remain until reset or deleted. Cached application files may remain until replaced, invalidated, or cleared.
Changes and version history
We update this policy when a material storage purpose, provider, or choice changes. A change that materially alters legal meaning receives a new calendar version and preserves the prior version.
Contact
Questions about browser storage or privacy can be submitted through the Bespoke Technologies contact page.