What cookies do
Cookies are small values your browser sends back to the site. WormGPT uses first-party cookies for login and security checks. Local storage is separate browser storage used for appearance preferences and project references. The current website does not include advertising or audience-analytics trackers. This notice describes the app’s storage; it does not treat continued browsing as permission for optional advertising or analytics.
First-party cookies
| Name | Purpose | Lifetime |
|---|---|---|
wormgpt_telegram_login | Binds Telegram verification to the browser that started sign-in | 10 minutes; also scopes pending sign-ins in other tabs |
wormgpt_web_session | Keeps you signed in | 7 days, or until logout/revocation |
wormgpt_web_challenge | Local-development bot check | 5 minutes; cleared on sign-in |
wormgpt_owner_challenge | Owner login verification | 5 minutes |
wormgpt_admin_session | Authenticated owner dashboard | 15 minutes, or until logout |
These cookies support authentication or security. They are HttpOnly and SameSite=Strict, and use the Secure flag on HTTPS. Owner cookies are used only in the owner login/dashboard flow.
Local storage
wormgpt-appearance-… remembers an account’s selected theme and animation preference. wormgpt-website-… stores account-scoped references between a chat and saved frontend project. These values remain in that browser until removed or cleared; they have no automatic expiry. Saved chat and project content is held on the server, not solely in these references. Clearing local storage does not delete your server account or saved conversations.
Third-party requests
If the operator enables Cloudflare Turnstile, account verification loads it to process security and device signals under Cloudflare’s practices. The standard Telegram sign-in setup does not load Turnstile. Its storage behavior depends on the deployed configuration. Fonts are requested from Google Fonts. Following external Telegram or seller links takes you to a separate service with its own cookies and privacy policy. See Cloudflare’s privacy policy and Google’s privacy policy for their information.
Managing storage
You can remove or block this site’s cookies and local storage through your browser’s site settings. Blocking login cookies prevents authenticated chat from working; clearing them signs you out. Use your connected Telegram account to sign in again after clearing cookies. Keep any unlinked legacy account key private until you connect it. Clear site data and log out on shared devices. The site does not currently offer optional analytics or advertising categories to turn on.
Questions and updates
Contact @mrzxn on Telegram about this site’s storage. Read the Privacy Policy for account data, provider processing and deletion controls. This policy will be updated if the storage used by the site changes.
Temporary sign-in state
The login page uses session storage to remember its pending sign-in reference and Telegram handoff while you refresh or switch apps. This state expires after ten minutes and is cleared after successful sign-in. Your six-digit login code is never saved in browser storage. A short-lived, HTTP-only cookie binds pending sign-ins to your browser; each tab keeps its own sign-in reference.