WithinBench / Workshop notes
Privacy Policy
Short version: your documents and files never leave your device. There are no accounts; only feedback and optional public supporter notes are deliberately submitted.
Last updated: August 13, 2026
The core principle
WithinBench's benches and document makers run inside your web browser. The text and supported files you use in those benches, and the documents you create, are processed on your own device and are never uploaded to any server. Information you deliberately send through the feedback or public supporter-note forms is the limited exception described below.
Data we store
- On your device only. Documents, drafts and settings are saved in your browser's
localStorageso your work is still there when you come back. This data stays on your device, is not transmitted to us, and you can clear it any time from the app or your browser settings. - No accounts or document database. There is no sign-up, account profile or password collection. If you voluntarily include an email address with feedback, it is handled only as part of that feedback message.
- Optional supporter notes. If you generate a Binance payment note, we store your chosen public name or Anonymous label, optional country, message, amount-display preference, consent time and random payment-note code in Cloudflare D1. If you provide the optional email, it is normalized and converted into a protected one-way identifier so repeat support can be counted; the address itself is not stored or published. This is separate from every bench and never contains your documents or tool inputs.
Analytics
When enabled, we use Cloudflare Web Analytics, a privacy-friendly, cookieless service, to understand aggregate traffic (for example, how many people visit and which tools are popular). It is configured without cross-site advertising identifiers or tracking cookies. Whether a notice or consent is legally required can depend on local law and the final production configuration. We do not sell personal information.
Feedback and abuse protection
When you submit the feedback form, we receive the message, its category, the relevant bench or page, and any reply email you choose to provide. Basic technical information, including your IP address and browser user agent, is processed to prevent abuse and troubleshoot reports. Feedback is delivered to our private email inbox; it is not added to an account or a public profile.
The feedback and supporter-note forms use Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. Cloudflare processes the technical information needed to provide that security check. Turnstile is loaded only where a protected form is shown and does not prevent anyone from reading the page.
To enforce feedback and supporter-note generation limits, Cloudflare keeps a temporary rate-limit bucket for an IP address or IPv6 network prefix. The bucket contains request types and timestamps, not the feedback message. Each entry stops being used after 24 hours, then its stored data is automatically deleted shortly after the retention window ends.
Feedback retention and deletion
Feedback emails are reviewed at least annually and deleted when they are no longer needed for a reply, an active investigation or an open product task. We do not retain resolved feedback indefinitely. If you included an email address and want a feedback message removed sooner, contact us from that address so we can locate and delete it.
Supporter-note publication and retention
Generating a note does not make it public. It remains pending while a Binance payment is manually verified. Pending notes expire after 30 days. Expired or rejected private records are deleted after approximately 30 days. A verified public entry may show the submitted name or Anonymous label, country, message, payment date, original amount and currency when permitted, and a maker-entered estimated USD value used for consistent display and sorting, plus an optional reply from WithinBench. Exact payment times, transaction identifiers and the private payment-note code are never published. When an optional email identifier links multiple verified payments, the public entry may also show how many times that supporter has contributed.
The USD value is an administrative estimate recorded when the payment is verified; it is not a live exchange rate, financial statement or promise of conversion value. The original paid quantity and currency remain the primary payment record when the supporter permits them to be shown.
Published supporter notes remain visible until removed or no longer useful. To request removal, contact us and include the private payment-note code so we can locate the entry. We may reject or remove abusive, misleading or inappropriate submissions.
Cookies
WithinBench does not use tracking cookies. Should we introduce advertising or additional analytics in the future, this policy will be updated and, where required, you will be asked for consent.
Third-party services
Cloudflare provides site delivery, aggregate analytics, Turnstile abuse protection, the feedback and supporter Workers, D1 supporter-note storage, the private steward application and email routing. It may process normal connection data such as an IP address, request time, browser information and the page requested. Fonts and bench libraries are served with the site; your document and file contents are not sent to those services.
Children
WithinBench is a general-purpose utility and is not directed at children under 13.
Your choices and requests
You can clear browser-local work through WithinBench or your browser's storage controls. For information deliberately submitted to the feedback or supporter systems, you may ask whether it is held, request correction or deletion, or object to continued publication by contacting us. We may need enough information to locate the record and confirm that the request comes from the person connected to it. Applicable privacy law may provide additional rights depending on where you live.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the "last updated" date above.
Contact
Questions about privacy? Email [email protected] or use the contact page.