I agree, but its not my project.

I explained that to the project "owner" and it seems that the data that is being stored in the cookie, encrypted, is not all that sensitive anyway.

It's just a marketing thing....."Our app encrypts all stored info, bla, bla, bla...."