teaflask

Cookie & Storage Policy

Exactly which cookies and browser storage each Teaflask surface uses — including the one that matters most: the assistant embedded in our customers' products sets no cookies at all.

Last updated: August 8, 2026

This policy explains how Waffer, Inc. (doing business as “Teaflask”, “we”, “us”) uses cookies and similar browser storage. Different Teaflask surfaces behave very differently, so this policy is organized by surface: our marketing website, our dashboard and the help centers it hosts, and the Teaflask assistant embedded in our customers’ products. For what data we collect and why, see our Privacy Policy.

1. Cookies and browser storage

Cookies are small text files placed on your device that are sent automatically with every request to the site that set them. Browsers also offer localStorage and sessionStorage: key-value stores that are readable only by the website (origin) that wrote them and are never transmitted automatically with requests. The distinction matters below — where Teaflask uses browser storage instead of cookies, nothing Teaflask stores rides along with your traffic to anyone.

2. teaflask.com — no cookies

Our marketing website sets no cookies and writes nothing to localStorage. We measure aggregate site usage (page views, referrers) with our analytics provider configured in a cookieless mode: analytics state is held in memory only and is discarded when you leave, no identifier is written to your device, and visits are not joined into a profile across sessions. Because nothing is stored on your device, no cookie consent is required to browse teaflask.com.

3. app.teaflask.com — the Teaflask dashboard

The dashboard is the signed-in product for our customers. It uses a small set of first-party cookies, all set by us:

Dashboard cookies
CategoryPurposeDuration
Strictly necessaryYour sign-in session, and which of your organizations you are working in. Signing in is impossible without these.Session cookies last while you use the dashboard and are removed on sign-out; the organization cookie lasts up to 1 year
PreferencesRemember interface choices, such as whether the navigation sidebar is open.Up to 1 year
AnalyticsOne analytics cookie that distinguishes your session so we can understand how the dashboard is used and fix what isn't working.Up to 1 year

The dashboard also keeps interface preferences (theme, density, reduced motion, panel widths, collapsed sections) in localStorage and sessionStorage on your device. These hold no personal data beyond your own display choices and are never transmitted.

app.teaflask.com also serves the public help centers our customers publish (at app.teaflask.com/help/…). Reading a help center requires no account and sets none of the cookies above: there is no sign-in session, and usage analytics on help-center pages are cookieless — held in memory only, exactly as on teaflask.com.

4. The assistant embedded in our customers' products — no cookies

When you chat with a Teaflask-powered assistant inside another company’s product, the embedded assistant sets no cookies — first-party or third-party — on that site. Authentication rides in request headers with short-lived tokens held in memory, never in cookies. Everything the assistant stores lives in the browser’s localStorage and sessionStorage on that company’s own domain, namespaced under tf-assistant — open your browser’s developer tools and you can check. Those entries hold only:

  • conversation continuity — a reference to your conversation so it survives a page reload (kept until you clear site data or the host product signs you out);
  • interface preferences — such as where you docked the assistant, or that you dismissed it (kept until you clear site data);
  • safety state — short-lived, tab-scoped records that make sure an action you approve runs at most once and that suggestions are not repeated (cleared when the tab closes).

Because these entries live in browser storage rather than cookies, they are readable only on the site that set them and are never sent automatically with any request — to Teaflask, to the host company, or to anyone else. They contain identifiers and interface state, not conversation content.

Storage set by the embedded assistant lives on the host company’s domain, and that company decides how the assistant appears in its own cookie and privacy disclosures, including any consent experience it offers. If you have questions about a specific site’s practices, contact that company first; its own policies govern.

5. No advertising or cross-site tracking

No Teaflask surface uses advertising cookies, third-party tracking pixels, or cross-site tracking of any kind, and we do not sell or share personal information for advertising. There is accordingly nothing here for a Global Privacy Control signal to opt out of; if that ever changes, we will honor such signals and update this policy first.

6. Managing cookies and storage

You can clear or block cookies and site data in your browser settings at any time. Blocking the strictly necessary dashboard cookies will prevent signing in; clearing the assistant’s storage simply starts a fresh conversation. The analytics cookie on the dashboard is not required for anything to work.

7. Changes to this policy

If we add, remove, or change cookies or storage, we will update the tables above and the date at the top of this policy before the change takes effect. Material changes — for example, ever introducing a consent-gated analytics cookie on teaflask.com — will be flagged prominently on this page.

8. Contact

Questions about this policy: privacy@teaflask.com. Waffer, Inc., 2261 Market Street, STE 86804, San Francisco, CA 94114.