Security and compliance
Cookie policy
This policy explains how Beyond Work uses cookies and similar browser storage on beyondwork.ai. It sits alongside our Privacy Policy, which explains how we handle personal data more generally.
Last updated 22 September 2026.
What these technologies are
A cookie is a small file a website asks your browser to keep. We also use local storage, which works in a similar way but holds the information in your browser rather than sending it back with every request. Where this policy says cookies, it means both.
What we use, and why
Strictly necessary. These keep the site working: page delivery, security, and load balancing. They cannot be switched off and we do not ask consent for them, because the site cannot function without them.
Functional. These remember choices you make so the site behaves consistently: your theme preference and any draft content you have started in an interactive tool on the site. They stay in your browser and are not sent to us for analysis.
Analytics. We use PostHog to understand how the site is used, which pages people find, and where they get stuck. PostHog is configured on European infrastructure. We set these only if you agree, and nothing is stored in your browser until you do. If you later change your mind, we clear what was stored.
Where analytics data goes. Analytics events are held by PostHog and copied into our own data warehouse. If you sign in to a restricted area of this site, we connect your activity to your account using a one-way hash of your email address rather than the address itself, together with your organisation's domain. We do not send your email address to PostHog from this site.
We do not record your screen, we do not use advertising or cross-site tracking cookies, and we do not sell or share what we collect with advertising networks.
The cookies and storage we set
Strictly necessary
Functional
Analytics, set only after you accept
- __Host-bw_session · Keeps you signed in. Lasts until you sign out or the session expires. The __Host- prefix means it is only ever sent back to this site.
- __Host-bw_oidc_state · Protects the sign-in exchange while it is happening. Short-lived, and removed once sign-in completes.
- bw-consent · Remembers your analytics choice. Without it we would have to ask you again on every page, including when you have declined.
- bw-theme · Remembers your light or dark preference. Kept in your browser and never sent to us.
- ph_phc_…_posthog (cookie and browser storage) · PostHog. Distinguishes visitors and groups page views into a session. 365 days from your last visit, renewed each time you return.
Your choices
You can change your mind at any time using Cookie settings in the footer of any page. You can also block or delete cookies in your browser settings, though the site may not work as well if you do.
Contact
Questions about this policy: privacy@beyondwork.ai.