No advertising, no profiling and no cross-site tracking. Your preferences and the items you choose to save locally remain on your device. This page lists the browser mechanisms actually used by WebPion.
WebPion 4.7.7.8Updated: 1 September 2026
Privacy, simply
Public WebPion pages contain no behavioural advertising, commercial profiling or cross-site tracking mechanism.
The first-party preferences and local saves described below remain in the browser until deleted by the user, browser policy or WebPion controls.
Cookies
Public pages set no advertising, marketing or profiling cookie.
Restricted GPTO administration uses a separate WEBPION_GPTO session cookie containing a random session identifier. It is configured with HttpOnly, SameSite=Strict, strict session mode, rotation and expiry; Secure is required under HTTPS. It contains neither Contact messages nor detailed statistics.
localStorage
WebPion uses localStorage for webpion-theme, saved Flow outputs in webpion_flow, saved Prompt outputs in webpion_saved_prompts and the local webpion_clean_counted marker.
Flow and Prompt saves are capped by application logic to the latest 50 entries and are not automatically synchronised to WebPion.
sessionStorage
The V4.7.4 code audit found no current WebPion application feature relying on sessionStorage.
If introduced later, this page must be updated before presenting it as current behaviour.
IndexedDB and local transfer workspace
WebPion uses the local WebPionTransferDB IndexedDB database for some cross-tool transfer and workspace functions, including transferFiles and workspaceFiles records.
IndexedDB is not a cookie. Its local data can be removed with the WebPion control or browser settings.
Aggregate operational measurement
First-party measurement may include tool/operation category, broad file family, input/output byte totals, accepted/success/error state, duration when available, interface language and broad browser family when supplied.
It is not designed for advertising profiles or cross-site tracking and does not add file content or a reusable user identity. Sensitive admin detail remains separate from public aggregate counters.
Erase WebPion local data
The erase button removes only enumerated WebPion localStorage keys and WebPionTransferDB. It does not call localStorage.clear() and does not intentionally remove unrelated application data.
The restricted GPTO cookie is not part of this public action; it is invalidated by administrator logout or expiry.
Technical logs and limits
No advertising cookie and no IP field in the WebPion application statistics database do not mean that hosting or server infrastructure can never process technical logs required for operation and security.
This page describes application storage delivered in WebPion V4.7.4. Effective production settings still require deployment verification.
W
Privacy, simply
No advertising, no profiling and no cross-site tracking. Your preferences and the items you choose to save remain on your device.