Cookie Policy
Last updated: 5 October 2026 · Effective date: 5 October 2026
This Cookie Policy explains how Writford uses cookies and similar technologies on the writford.co.uk website and in the Writford web application (the “Service”). It is part of, and should be read together with, our Privacy Policy.
1. Who we are
Writford is operated by Big Berri Limited , a private limited company incorporated in England and Wales with company number 16562429 (in this Cookie Policy, “Writford”, “we”, “us”, “our”).
ICO registration number: ZC119995
Contact: info@writford.co.uk
2. What is a cookie?
A cookie is a small text file placed on your device when you visit a website. Cookies allow the website to remember information about you (such as whether you are logged in) so that you do not have to re-enter it on every page. Some cookies are set by the website you are visiting (“first-party cookies”); others are set by third parties (“third-party cookies”).
Browsers have two similar places to keep information. Local storage keeps it until it is removed. Session storage keeps it only until you close the tab. The same rules apply to all three: nothing may be stored on or read from your device without your consent, unless it is needed for a service you have asked for or another exception in the law applies.
3. Our approach
- Everything Writford keeps in your browser is listed below: what it is for, what it holds, how long it lasts and whether it is sent to us.
- In the web app we keep only what is needed to run the service you asked for, such as signing you in, keeping that sign-in safe, the live timer and a message you have typed but not sent, and the choices you make about how the screens look.
- While you use the web app we record which features are used, as our Privacy Policy explains in Section 4.4. Nothing is stored in your browser for that.
- We use cookieless website analytics on this website (Google Analytics 4, Ahrefs Analytics, and Vercel Web Analytics and Speed Insights), all configured to operate without setting any cookies on your device. These tools collect anonymous, aggregate data (page views, traffic sources, page-load timings) only.
- We do not use advertising, marketing, profiling, or third-party tracking cookies of any kind.
- We do not use Meta Pixel, LinkedIn Insight Tag, Segment, Mixpanel, Hotjar, Clarity, PostHog, or any comparable browser-based advertising or tracking service.
- We do not use device fingerprinting, behavioural profiling, or any cross-site tracking technologies for marketing.
- We do not sell, share or monetise any cookie data.
4. Cookies
| Name | What it does and holds | How long, and how it is removed | Sent to Writford? |
|---|---|---|---|
auth_tokenWeb app. Essential. | Keeps you signed in. Holds: A signed sign-in token. Scripts on the page cannot read it. | Until you sign out, or until you have not used Writford for the time you chose under Staying signed in. Removed: When you sign out. | Yes, with every request to the app. This is how Writford knows it is you. |
auth_checkWeb app. Essential. | Tells the app's pages that you are signed in, so they show the right menu. Holds: The number 1. Nothing about you. | The same as the sign-in cookie above. Removed: When you sign out. | Yes, with every request to the app. |
g_oauth_state, g_oauth_next, g_oauth_mode, g_oauth_mobile_redirect, g_oauth_link_email, ms_oauth_state, ms_oauth_next, ms_oauth_mode, ms_oauth_mobile_redirect, ms_oauth_link_email, a_oauth_state, a_oauth_nonce, a_oauth_next, a_oauth_mobile_redirect, a_oauth_link_email, ms_mail_oauth_state, ms_mail_oauth_email, ms_mail_oauth_next, ms_calendar_oauth_state, ms_calendar_oauth_email, ms_calendar_oauth_next, ms_todo_oauth_state, ms_todo_oauth_email, ms_todo_oauth_next, ms_m365_oauth_state, ms_m365_oauth_email, ms_m365_oauth_next, ms_m365_oauth_caps, wf_desktop_redirect, wf_desktop_state, wf_desktop_challenge, wf_desktop_linkWeb app. Essential. | While you sign in with Google, Microsoft or Apple, sign in to the desktop or phone app, or connect a Microsoft service, these check that the answer coming back belongs to the sign-in you started, which stops someone else slipping in a sign-in of their own. They also remember where to take you back to. Holds: A random check value, the page to return to, which service you are connecting and, for a connection, your email address. Scripts on the page cannot read them. | 10 minutes at most. Removed: As soon as the sign-in or connection finishes, or after 10 minutes. | Yes, back to Writford when the sign-in or connection finishes. |
wf_acting_asWeb app. Essential. | Only in the browser of a Writford support person who has entered a customer's account to help with it. It shows a banner on every page naming that account, so the visit cannot be mistaken for anything else. The account's own activity list shows that Writford support opened it. Holds: The email address of the account being visited. | 1 hour. Removed: When the visit ends or the support person signs out. | Yes, with requests to the app. Writford uses it only for the banner. |
wf_admin_sessionWeb app. Essential. | Only in the browser of a Writford staff member signed in to Writford's own admin console. It keeps them signed in to that console, so reloading a page or coming back from a customer's account does not ask for the password again. Holds: A signed sign-in token naming the staff member. It holds no password, and scripts on the page cannot read it. | 8 hours. Removed: When the staff member presses Logout in the console, after 8 hours, or for everyone at once when the console's password is changed. | Only with requests to the admin console's own part of the app, and never with a request another website starts. |
msal.cache.encryptionWeb app. Essential. | Set by Microsoft's sign-in software when you use the OneDrive file browser. It holds the key that locks the Microsoft sign-in details kept in local storage (see below), so they cannot be read once the key is gone. Holds: A random encryption key. | Until you close the browser. Removed: When you sign out of Writford, or when you close the browser. | Yes, with requests to the app, as every cookie is. Writford does not read it. |
Only the sign-in cookie and its companion last beyond one visit. The others last ten minutes, last until you close the browser, or are only ever set in the browser of a Writford support person.
5. Local storage and session storage
Local storage
| Name | What it does and holds | How long, and how it is removed | Sent to Writford? |
|---|---|---|---|
wf_chat_draft_*Web app. Essential. | Keeps a message you have typed to the assistant but not sent, so it is still there if you open another chat and come back. Holds: The words you typed. The entry's name includes your email address, so a message is only ever offered back to the person who typed it. | Until you send it or clear it. Removed: When you send or clear it, and when you sign out. | No, not until you press Send. |
wf_timer_device_idWeb app. Essential. | Lets the live timer recognise this browser as the one your timer was started on, even after you reload the page, so it keeps counting here and pauses on its own when this computer sleeps. Holds: A random number for this browser. Nothing about you. | Until you clear this site's data in your browser. Removed: When you clear this site's data in your browser. A new number is made the next time you use the timer. | Yes, with timer requests while a timer runs. |
msal.*Web app. Essential. | Set by Microsoft's sign-in software when you use the OneDrive file browser, so you do not have to sign in to Microsoft again each time you open it. Holds: Which Microsoft account you chose and the short-lived access keys Microsoft gave for it, locked with the key in the cookie above. | Microsoft's access keys stop working after about an hour. The entries cannot be read once the browser is closed. Removed: When you sign out of Writford. | No. They go only to Microsoft, when the file browser asks it for access. |
msal.*Outlook add-in. Essential. | Set by Microsoft's sign-in software inside Outlook when the Writford add-in signs you in with the Microsoft account Outlook already uses, so you are not asked to sign in again. Holds: Which Microsoft account Outlook uses and a short-lived access key that lets Writford check who you are. | The access key stops working after about an hour. The entries stay until Microsoft's software replaces them. Removed: When Outlook's stored data for add-ins is cleared. | Only the short-lived access key, once as you sign in, so Writford can check who you are. Writford does not keep it. |
writford_outlook_tokenOutlook add-in. Essential. | Keeps you signed in to the Writford for Outlook add-in inside Outlook. Holds: A sign-in token for the add-in. It holds no Microsoft password or Microsoft token. | The token stops working after 12 hours, or at once if you sign out of Writford on all devices. Removed: When you sign out of the add-in, or when the add-in finds it has stopped working. | Yes, with each request the add-in makes to Writford. |
writford_outlook_switch_accountOutlook add-in. Essential. | Remembers that you asked the add-in to sign in as someone else, so it does not sign you straight back in to the old account. Holds: The number 1. | Until you next sign in to the add-in. Removed: When you next sign in to the add-in. | No. |
wf_open_in_desktop_apps:*Web app. Remembers your choice. | Remembers whether you want files to open in the Writford desktop apps on this computer. Holds: On or off. The entry's name includes your email address, so each person who uses this computer keeps their own choice. | Until you change it or clear this site's data. Removed: When you clear this site's data in your browser. It is kept when you sign out, so your choice is there when you come back. | No. |
dashboard_dark_mode, admin_dark_mode, matters_view_mode, wf_clients_view, wf:files-view:*, wf.timeFees.printOrientation, wf.bundle.listView, wf.tasks.table.columns.v1, pinned_conversationsWeb app. Remembers your choice. | Remember how you like the screens: dark or light, lists or tiles for matters, clients and a matter's files, the columns shown on the task list, portrait or landscape for the time printout, the bundle screen's list view and the chats you pinned. Holds: The choices themselves. The entry for a matter's files and the pinned chats hold Writford's reference numbers for those matters and chats, not their names. | Until you change them or clear this site's data. Removed: When you clear this site's data in your browser. They are kept when you sign out, because they belong to the computer and hold nothing confidential. | No. |
writford_pane_themeOutlook add-in. Remembers your choice. | Remembers whether you chose light or dark colours for the Writford for Outlook add-in. Holds: Light or dark. | Until you change it. Removed: When Outlook's stored data for add-ins is cleared. | No. |
cookie_banner_dismissedWeb app and this website. Remembers your choice. | Remembers that you closed the cookie notice, so it is not shown again. Holds: The word true. | Until you clear this site's data. Removed: When you clear this site's data in your browser. | No. |
wf_blog_draft_*Web app. Essential. | Keeps unsaved article writing in the staff blog editor so it can be recovered after a page closes. Holds: Article fields typed by the staff member. The name includes their operator address, so recovery is offered only to that operator. | Until the draft is saved online or for seven days. Removed: After a successful save, when the staff member signs out, or when an expired copy is next opened. | To Writford through the admin API when the draft is saved. |
Session storage
| Name | What it does and holds | How long, and how it is removed | Sent to Writford? |
|---|---|---|---|
wf_firm_scopeWeb app. Remembers your choice. | Remembers, while the tab is open, whether a list shows your own work or the whole firm's. Holds: Own or firm. | Until you close the tab. Removed: When you close the tab. | No. |
wf_m365_lost_notice_hiddenWeb app. Remembers your choice. | Remembers that you hid the notice saying your Microsoft connection has stopped, so it does not reappear on every page in this tab. Holds: Which connections the notice was about. | Until you close the tab. Removed: When you close the tab. | No. |
Most of these never leave your device. Two are sent to Writford: the timer’s device number, with timer requests while a timer runs, and the add-in’s sign-in token, with each request the add-in makes. Microsoft’s sign-in details go only to Microsoft.
When you pick files from Google Drive, Google gives your browser an access key that lasts an hour. Writford keeps it in the open page’s memory only, never in storage, so it is gone when you close the tab. The Google Drive and OneDrive file pickers open windows run by Google and Microsoft, and their own cookie policies apply inside those windows.
6. How to remove them
- Sign out. Signing out removes the sign-in cookies, any message you typed to the assistant but did not send, and the Microsoft sign-in details kept for the OneDrive file browser. Sign out when you finish on a shared or borrowed computer.
- Close the tab. Session storage is emptied when you close the tab.
- Clear this site’s data. Your browser’s settings remove everything else, including your display choices and the timer’s device number. See the help pages for Chrome, Safari, Firefox and Edge.
Blocking cookies stops you signing in. There is no way to use the web app without the sign-in cookies.
7. Consent
We do not ask for consent for anything listed above, because each item is either needed for something you asked Writford to do, such as signing in or running the timer, or remembers a choice you made on the screen. Our website analytics store nothing on your device. If we ever want to keep something in your browser for another reason, we will ask you first, and you will be free to say no. We provide this Cookie Policy for transparency, in line with Information Commissioner’s Office (“ICO”) guidance.
8. Changes to this Cookie Policy
We may update this Cookie Policy from time to time, for example if we add a new strictly necessary cookie, change the lifetime of an existing one, or correct an error. The current version is always available at https://app.writford.co.uk/cookies. We will update the “Last updated” date at the top of this page when we make a change. We will not introduce non-essential cookies without first obtaining your express, freely-given, specific, informed, unambiguous opt-in consent in line with PECR and the UK GDPR.
9. Your rights and how to complain
Cookies that store personal data are subject to the UK GDPR. You have the same rights in relation to cookie data as you do in relation to any other personal data we hold about you. See Section 12 of our Privacy Policy for the full list of rights and how to exercise them.
If you are not satisfied with how we handle your personal data, you have the right to complain to the ICO:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113
10. Contact
If you have any questions about this Cookie Policy, please contact:
Big Berri Limited
(Company Number 16562429
)
Trading as: Writford
ICO registration number: ZC119995
Email: info@writford.co.uk
See also: Privacy Policy · Terms of Service · AI Policy · Sub-Processors