Legal

Cookie Policy

What we store on your device, and what you can switch off · Last updated September 5, 2026

This page lists everything GPUwerk stores in your browser. It is short, because there is not much, and the part that is optional is genuinely optional: nothing in the analytics or marketing categories is downloaded at all until you say yes.

The short version

Necessary

Set on the basis of Article 6(1)(f) GDPR and the corresponding national implementation of the ePrivacy Directive. These are what "strictly necessary" actually means: without them the thing you asked for does not work.

NamePurposeExpires
gpuwerk.consent.v1Your choice, covering gpuwerk.com and console.gpuwerk.com, so the banner does not ask again on every visit. Stored in local storage, not sent anywhere except once, as described under "Proving we asked" below.12 months
gpuwerk_consentYour cookie choice, as a cookie on gpuwerk.com and its subdomains, so the console honours the same decision.1 year
gpuwerk.cidA random string with no meaning outside our consent log. It exists so a withdrawal can be matched to the consent it withdraws. It is not an advertising identifier and is never joined to your account.12 months
sb-…-auth-tokenKeeps you signed in to the console after you authenticate, whether that was through GitHub, through Google, or with your email address.Session
sy.*Console interface state: which view you had open, your saved preferences. Local storage, never transmitted.Until cleared

Analytics: optional, off unless you accept

Article 6(1)(a) GDPR, your consent. We use this to find out which pages people actually read and where the documentation loses them. It is aggregate: we are looking at which page fails, not at who you are.

NameSet byPurposeExpires
_ga, _ga_*Google Analytics 4Distinguishes one visit from another so a session is counted once. IP anonymisation is on.2 years
ph_*PostHog (EU region)Which pages a visit moved through, so a drop-off in signup can be located. Configured without session recording and without autocapture, and PostHog is told to discard the IP at ingest.12 months

Marketing: optional, off unless you accept

Article 6(1)(a) GDPR, your consent. This is the category that attributes a signup back to the advert or link that produced it. It is also the category that involves Google and Meta, and it is the one to leave off if you would rather they did not learn you were here. Leaving it off has no effect on the service.

NameSet byPurposeExpires
_fbp, _fbcMeta pixelAttributes a signup or a contact request to the Meta advert it came from. Fires page views, content views, contact-form leads and the first sign-in in the console, never names or emails.3 months
_gcl_*Google AdsThe same attribution, for Google’s advertising.3 months

Accepting this category is a transfer of personal data to the United States. Google and Meta are both established there. Our Privacy Policy sets out the Chapter V GDPR mechanism this rests on. Rejecting it means no such transfer happens, because the scripts are never fetched.

Error reporting, which is not a cookie

We run Sentry to catch JavaScript errors, so that a broken signup page is noticed by us rather than only by the person it broke for. It sets no cookie and stores no identifier in your browser, so there is no cookie choice attached to it. It is configured with personal data collection off, IP capture off and no session replay, and it runs in Sentry’s EU region. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a service that works.

What we deliberately do not do

Proving we asked

Article 7(1) GDPR requires us to be able to demonstrate that consent was given. A record that lives only in your own browser proves nothing, so when you make a choice here we store one copy on our server: the random gpuwerk.cid, the time, the version of this policy you were shown, and which categories you allowed. No name, no email address and no IP address is in that record. It is append-only, so a withdrawal is written as a new entry rather than by editing the old one.

Changing your mind

Use , here or in the footer of any page. Withdrawal takes effect immediately: the tools are silenced on the page you are on, and the cookies they set are deleted rather than left to expire. Withdrawal does not affect processing that already happened, which is why it is worth deciding before rather than after.

You can also block or delete cookies in your browser directly, and browser-level "do not track" or global privacy control signals are respected where your browser sends them.

Related documents

The full picture of what we process and why is in our Privacy Policy. Company details are in the Imprint, and the contract is the Terms of Service.