Small cookies.
Clear intentions.
Replywell does not run ads or use advertising cookies. This prototype also has no analytics trackers, marketing pixels or embedded social-media trackers.
What this application stores
This first-party cookie is written only when you select the button. It is used to respect your choice and is not used to track you. If your browser blocks it, the site still works; the notice may reappear on your next visit.
Essential access and security
Account forms load Cloudflare Turnstile for bot protection. Its verification token is short-lived and is sent to Supabase with the account request. The widget has no pre-clearance cookie enabled and is used for security, not advertising or analytics.
When account storage is connected, Replywell uses HttpOnly rw_access (up to one hour) and rw_refresh (seven days) cookies for your account session. Google authorisation uses an encrypted rw_google_state cookie for up to ten minutes. Signing out clears account cookies; the Google callback clears its authorisation cookie. Secure is used over HTTPS; local loopback development uses HTTP.
The setup form uses the tab’s rw_setup session-storage entry only after Continue to account. It holds business preferences until saved or the browser session ends; it contains no password or provider token.
The hosting service may use its own session or security cookies to protect a private site and authenticate access. These are managed by the hosting service. They are separate from the application preference listed above.
Reports and saved work
Review research uses replywell-browser-research-v1 in this browser profile’s local storage after you confirm permission and collect a sample. It contains the latest research sample and drafts you save, not passwords or provider keys. It remains until replaced by a successful new sample, removed using the research page or cleared in your browser’s site-storage settings. Anyone using this browser profile can read it; removing it clears the device copy only. Collection jobs and successful service samples are also stored in the account backend, and Apify retains its own runs and datasets.
Preparation-mode reports, unsaved public-test edits and any preparation key are held in page memory; reloading clears them. Signed-in workspace reviews, preferences and drafts are instead saved in the configured local PostgreSQL or hosted Supabase backend. Read our privacy and data notice for processing details.
Your choice stays yours
There are no optional cookies to switch on in this version. You can reopen the notice using “Cookies” in the footer, or remove the preference using your browser’s cookie settings. If we introduce optional tracking, we will update this notice and provide the appropriate choice before activating it.
Last updated: 4 October 2026.