Cookie Policy
This page lists everything GPUwerk stores in your browser. It is short, because there is not much, and the part that is optional is genuinely optional: nothing in the analytics or marketing categories is downloaded at all until you say yes.
The short version
- Necessary storage keeps you signed in and remembers your cookie choice. It cannot be switched off, and it is not used to profile you.
- Analytics and marketing are off by default. Not "loaded but disabled": not fetched at all.
- Refusing is one click, in the same place and the same size as accepting.
- You can change your mind at any time: . Turning a category off deletes the cookies it set.
- Your choice is remembered for twelve months, then we ask again.
- None of this touches your instances. Nothing on this page can see a workload, a model, a prompt or a file on a rented machine.
Necessary
Set on the basis of Article 6(1)(f) GDPR and the corresponding national implementation of the ePrivacy Directive. These are what "strictly necessary" actually means: without them the thing you asked for does not work.
| Name | Purpose | Expires |
gpuwerk.consent.v1 | Your choice, covering gpuwerk.com and console.gpuwerk.com, so the banner does not ask again on every visit. Stored in local storage, not sent anywhere except once, as described under "Proving we asked" below. | 12 months |
gpuwerk_consent | Your cookie choice, as a cookie on gpuwerk.com and its subdomains, so the console honours the same decision. | 1 year |
gpuwerk.cid | A random string with no meaning outside our consent log. It exists so a withdrawal can be matched to the consent it withdraws. It is not an advertising identifier and is never joined to your account. | 12 months |
sb-…-auth-token | Keeps you signed in to the console after you authenticate, whether that was through GitHub, through Google, or with your email address. | Session |
sy.* | Console interface state: which view you had open, your saved preferences. Local storage, never transmitted. | Until cleared |
Analytics: optional, off unless you accept
Article 6(1)(a) GDPR, your consent. We use this to find out which pages people actually read and where the documentation loses them. It is aggregate: we are looking at which page fails, not at who you are.
| Name | Set by | Purpose | Expires |
_ga, _ga_* | Google Analytics 4 | Distinguishes one visit from another so a session is counted once. IP anonymisation is on. | 2 years |
ph_* | PostHog (EU region) | Which pages a visit moved through, so a drop-off in signup can be located. Configured without session recording and without autocapture, and PostHog is told to discard the IP at ingest. | 12 months |
Marketing: optional, off unless you accept
Article 6(1)(a) GDPR, your consent. This is the category that attributes a signup back to the advert or link that produced it. It is also the category that involves Google and Meta, and it is the one to leave off if you would rather they did not learn you were here. Leaving it off has no effect on the service.
| Name | Set by | Purpose | Expires |
_fbp, _fbc | Meta pixel | Attributes a signup or a contact request to the Meta advert it came from. Fires page views, content views, contact-form leads and the first sign-in in the console, never names or emails. | 3 months |
_gcl_* | Google Ads | The same attribution, for Google’s advertising. | 3 months |
Accepting this category is a transfer of personal data to the United States. Google and Meta are both established there. Our Privacy Policy sets out the Chapter V GDPR mechanism this rests on. Rejecting it means no such transfer happens, because the scripts are never fetched.
Error reporting, which is not a cookie
We run Sentry to catch JavaScript errors, so that a broken signup page is noticed by us rather than only by the person it broke for. It sets no cookie and stores no identifier in your browser, so there is no cookie choice attached to it. It is configured with personal data collection off, IP capture off and no session replay, and it runs in Sentry’s EU region. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a service that works.
What we deliberately do not do
- No cross-site tracking, no data brokers, no audience lists sold or bought.
- No fingerprinting, and no attempt to identify you if you refuse cookies.
- No third-party fonts. The typeface on this page is served from our own servers precisely so that loading it does not tell anyone else you were here.
- No consent wall. Refusing gets you the entire site; there is no content behind an "accept to continue".
- Nothing in any category is applied to a rented instance. Cookies are a website matter and stop at the website.
Proving we asked
Article 7(1) GDPR requires us to be able to demonstrate that consent was given. A record that lives only in your own browser proves nothing, so when you make a choice here we store one copy on our server: the random gpuwerk.cid, the time, the version of this policy you were shown, and which categories you allowed. No name, no email address and no IP address is in that record. It is append-only, so a withdrawal is written as a new entry rather than by editing the old one.
Changing your mind
Use , here or in the footer of any page. Withdrawal takes effect immediately: the tools are silenced on the page you are on, and the cookies they set are deleted rather than left to expire. Withdrawal does not affect processing that already happened, which is why it is worth deciding before rather than after.
You can also block or delete cookies in your browser directly, and browser-level "do not track" or global privacy control signals are respected where your browser sends them.
Related documents
The full picture of what we process and why is in our Privacy Policy. Company details are in the Imprint, and the contract is the Terms of Service.