Version dated 6 September 2026.
This Policy explains how Watbot, LLC uses cookies and similar technologies on https://watbot.org/ and in your account. It forms part of our Privacy Policy, which describes everything else we do with personal data.
1.1. A cookie is a small text file that a website asks your browser to store on your device and sends back on your next visit. Cookies let a site remember that you signed in, which language you chose and whether you have already answered the cookie banner.
1.2. We also use technologies that work like cookies: local storage in the browser, where your account keeps interface preferences, and pixels in a few pages, which are tiny images that report that a page was opened. Everything said here about cookies applies to those technologies too.
1.3. A first-party cookie is set by our site. A third-party cookie is set by another company whose code runs on the page — for us, only the web analytics service.
2.1. Some cookies are strictly necessary: without them you cannot sign in, the site cannot protect your session and it cannot even remember that you declined the others. The law lets us use those without consent, and they are listed in Section 3.
2.2. Everything else is optional and falls into two categories, analytics and marketing, described in Sections 4 and 5.
2.3. Where the law requires a separate choice for each category — in the European Economic Area, the United Kingdom and Switzerland — we open a dialog on your first visit that lists the categories with a short description of each and lets you switch them on one by one. Nothing outside the strictly necessary group is loaded, and no analytics or marketing cookie is written, until you answer. "Reject all" sits next to "Accept all", is exactly one click, and looks the same: refusing must be no harder than agreeing.
2.4. In other countries we show a short banner with "Accept" and "Decline", and your answer applies to both optional categories at once.
2.5. Your answer is stored for one year in a cookie called cookie_consent, which records which categories you allowed. Nothing else is stored with it: no identifier of you, no history of your visits.
2.6. To change your mind at any time, use the "Cookie settings" link in the footer of any page. It reopens the same dialog with your current choice, and saving it applies immediately — withdrawing consent is as easy as giving it. Deleting the cookie_consent cookie in your browser settings and reloading the page has the same effect.
2.7. Consent is not a condition of using the site. Refusing costs you nothing: no feature is withheld, no content is hidden and no price changes.
These are always set, because the site cannot work without them.
cookie_consent — remembers whether you accepted or declined analytics cookies. First party. Lifetime: 1 year.lang — the language you selected, so that the site opens in it next time. First party. Lifetime: 1 year.wb_sid, wb_rt — your signed-in session in the account: a short-lived access token and the refresh token that keeps you signed in. These are HttpOnly (unreadable by scripts), Secure and SameSite=Lax. First party. Lifetime: the refresh period of the session, after which you sign in again. Set only after you sign in, never for a visitor who is not logged in.Signing out deletes the session cookies.
4.1. If you arrive by a campaign link that carries UTM parameters, we store those parameters — utm_source, utm_medium, utm_campaign, utm_term, utm_content — in first-party cookies so that a registration completed later can be attributed to the campaign that brought you.
4.2. If you open a registration link from one of our partners, the partner's identifier is stored the same way in a first-party cookie called ref_id, so that the partner receives credit for your registration under our affiliate programme.
4.3. These cookies are set only when you actually follow such a link. They hold a campaign or partner label, not a profile of you; they are not read by any third party, are not used for advertising to you elsewhere and are not combined with data from other sites.
4.4. They belong to the marketing category. Where we ask for a separate choice (clause 2.3), they are not written until you allow marketing: the campaign parameters stay in the page you are looking at and are discarded if you refuse or simply leave. Where the short banner is shown, they follow your answer to it.
4.5. They are deleted as soon as you register, because their only purpose is over at that point. If you never register, they expire on their own — ref_id after a year, the UTM cookies after five. You can delete them at any time in your browser settings (Section 6), and blocking them has no effect on how the site works for you.
5.1. The analytics category covers the services that count visits and show which pages people read and where they lose their way. We use the results in aggregate, to improve the site; we do not use them to make decisions about you individually.
5.2. Yandex Metrica sets its own third-party cookies, typically _ym_uid (a visitor identifier, up to 1 year), _ym_d (the date of the first visit, up to 1 year), _ym_isad (whether an ad blocker is present, up to 2 days) and _ym_visorc (session recording, about 30 minutes). The service processes visit data under its own terms and may store and process it outside your country, including in the Russian Federation. Besides refusing it here, you can install Yandex's opt-out browser add-on, which blocks the service on every site.
5.3. The Google tag (gtag.js) measures visits and the effectiveness of our advertising. It sets Google's own first-party cookies, typically _ga and _ga_<id> (a visitor and session identifier, up to 2 years), and, once you allow marketing, cookies used for advertising measurement. We run it in consent mode: the advertising storages (ad_storage, ad_user_data, ad_personalization) stay denied until you allow the marketing category, and the tag is not loaded at all until you allow analytics. Google processes the data under its own terms, including in the United States.
5.4. The marketing category covers the VK advertising pixel, where it is used on the site you are reading, the advertising features of the Google tag, and the attribution cookies in Section 4. It never gives anyone the content of what you typed into the site.
5.5. Where a service is unavailable in your country — for example where a regulator has blocked it — we do not load it at all, whatever you answer here, because a blocked script only makes the page wait. In that case the category simply has fewer services in it.
5.6. The exact set of services differs between our sites: this page describes the site you are reading now.
6.1. Every browser lets you see the cookies stored for a site, delete them, block third-party cookies or block all cookies. The settings are usually under Privacy or Site settings:
6.2. Blocking the strictly necessary cookies will break sign-in and the consent dialog itself, so the site will keep asking about cookies on every page.
6.3. Private or incognito windows delete cookies when you close them, which means your consent choice is forgotten each time.
6.4. Global Privacy Control. If your browser sends a GPC signal, we treat it as a refusal of the analytics and marketing categories for that browser.
6.5. Do Not Track. There is no agreed standard for what a site must do with a DNT header, so we do not act on it. Use the consent dialog or GPC instead.
7.1. Inside your account we keep a few preferences in the browser's local storage rather than in cookies, because they never need to reach our servers: the light or dark theme, the blocks you recently used in the flow editor, and the contents of the editor clipboard.
7.2. That data stays on your device, is not sent to us and is not read by anyone else. Clearing the site data in your browser removes it.
8.1. Where one of our customers runs an online school on their own domain, a mini app or a widget on their site, the cookies set there serve that customer's service. For those cookies the customer is the controller: their own cookie notice applies, and requests about them go to them.
8.2. We provide the technical means and do not use those cookies for our own purposes.
9.1. When we add or remove a cookie, we update this Policy and change the version date at the top.
9.2. If we ever add a service to a category, or introduce a new category, we will ask for your consent again before setting the cookies it needs.
Watbot, LLC.
Questions about cookies and privacy: support@watbot.org.
Your rights, including the right to complain to a supervisory authority, are described in Section 13 of the Privacy Policy.