Cookie Policy

Version ⁨1⁩ · last updated ⁨September 19, 2026⁩

On this page

Cookie Policy

This page lists everything ideamaker stores in your browser – cookies and local storage alike – what each item is for, how long it lives, and how to refuse or withdraw it.

Everything below is first-party: it is set by https://ideamakerbusiness.bob-the-worker.com itself. There is no advertising network, no marketing tag, no external analytics vendor and no third-party content delivery script.

These are required for the service to work at all. Without them you cannot sign in.

NameTypeLifetimePurpose
refresh_tokenCookie (HttpOnly, Secure, SameSite=Strict)7 daysKeeps you signed in without re-entering your password
oauth_stateCookie (HttpOnly, Secure)10 minutesProtects the Google sign-in exchange against cross-site request forgery
oauth_access_token, oauth_expires_inCookie (Secure)60 secondsOne-shot handover of the session token immediately after a Google sign-in
access_tokenLocal storageUntil you sign outThe session token sent with each request
last_activity, token_expires_at, session_timeout_msLocal storageUntil you sign outIdle-timeout bookkeeping
pending_verification_emailLocal storageUntil the address is verifiedCarries the address awaiting verification across the sign-up steps
chat_session_id, chat_session_secretLocal storageUntil the chat is closedIdentifies your conversation with the assistant when you are not signed in
ibm_tracking_consent, ibm_replay_consentLocal storageUntil you change your choiceThe record of your consent choice itself. Kept even when you refuse – that is how we remember not to ask again

2. Preferences – no tracking, no profiling

NameTypeLifetimePurpose
themeLocal storageUntil clearedLight or dark theme
preferred_languageLocal storageUntil clearedThe language you chose
sidebar_collapsedLocal storageUntil clearedWhether the sidebar is collapsed

Nothing in this section is created before you consent. If you refuse, no identifier is generated and no event leaves your browser.

NameTypeLifetimePurpose
ibm_anonymous_idCookie + local storage mirror400 daysDistinguishes returning visitors from new ones, without naming them
ibm_session_id, ibm_session_tsLocal storageThe visit (30 minutes of inactivity ends it)Groups the pages of one visit together

What is measured: pages viewed, clicks on instrumented elements, time on page, form submissions (the fact of them, never the values you typed), device type, browser, operating system, country, the site you arrived from and any campaign parameters. Administration pages are never measured. The data is kept for 30 days.

Session replay reconstructs what a page looked like as you used it, so that we can diagnose a bug or a confusing screen. It is asked for separately from audience measurement, and refusing it costs you nothing.

  • What it records: the structure of the pages you visit and your interactions with them.
  • What it never records: the content of form fields (all inputs are masked) and passwords (never captured under any configuration).
  • Where it goes: our own servers. The recording engine is bundled with the application; no third-party replay vendor receives anything.
  • How long: 30 days, after which the recording is deleted automatically.
  • Administration pages are never recorded.

5. Accepting, refusing, withdrawing

The banner shown on your first visit offers three equally reachable choices: decline everything, accept audience measurement only, or accept measurement and session replay. Refusing is one click, exactly like accepting, and the service remains fully usable.

You can change your mind at any time through the “Privacy settings” link, which reopens the same banner. Withdrawing stops the collection immediately and discards anything buffered but not yet sent.

6. Changes

When this policy is republished, the consent it refers to is renewed: you are asked again, so that your choice always relates to a text you have actually been shown.

Questions: contact@bob-the-worker.com.