// legal

Cookies and browser storage

A cookie policy for a site that mostly does not set cookies. Here is what can be written into your browser, who writes it, and what happens when you say no.

Last updated
Applies to
synapsereality.io
Goes with
Privacy policy

01 The short version

02 What can be written, by group

Cookie and storage groups
GroupWritten byWhat it is forIf you refuse
Strictly necessaryCloudflare, and this site.Blocking bots, remembering that you answered the banner, and the token that protects the forms from spam.Cannot be refused. Without these the site cannot be served safely, and you would be asked about cookies on every page.
AnalyticsGoogle Analytics 4 through Cloudflare Zaraz, Microsoft Clarity, PostHog.Counting visits, replaying sessions to find broken pages, and seeing which pages lead to an enquiry.Nothing is written and nothing is sent. The tools are not loaded.
AdvertisingNobody.This site runs no ad pixel, no remarketing tag and no cross-site identifier.Nothing to refuse.

03 Strictly necessary

Cloudflare sits in front of the site as CDN and firewall. It may set __cf_bm to tell bots from people, and cf_clearance if you were shown a challenge. Both are security cookies, both are Cloudflare's, and there is no version of this site without them.

We also store your answer to the cookie banner in your own browser so you are not asked again on the next page. The same answer is mirrored into a small sy_consent cookie so our server knows whether it may set sy_vid.

04 Analytics, and when it waits for you

Google Analytics 4 is loaded through Cloudflare Zaraz, so the tag is served from our own domain instead of googletagmanager.com. That changes where the file comes from and who writes the identifier. The measurement still ends up at Google. That is why it waits for consent in the EU, the EEA, the UK and Switzerland.

Microsoft Clarity records a replay of your session: pointer, scroll, clicks, page structure. Clarity masks text input by default, so what you type into a form is not in the recording. It needs a cookie to join the pages of one visit together, and without consent it treats every page view as a stranger.

PostHog is configured to store nothing in your browser until you accept. If you refuse, it counts you with a rotating hash that changes daily and writes no cookie or local storage at all. Its events reach us through /ingest/ on this domain, so an ad blocker sees a first-party request.

05 Measurement that stores nothing

Cloudflare Web Analytics counts page views and loading speed without a cookie and without building an identifier for you. It runs for every visitor, including in the EU, because it stores nothing in your browser and gives us no way to recognise you on a later visit.

Our own visitor_event log runs on our server. It writes a row when you send a form, run the audit tool or unsubscribe, whether or not your browser stores anything. The first row also sets sy_vid, a first-party cookie holding a random ID for 13 months. It is described in the privacy policy. A cookie banner has no effect on it. We say so here because leaving it out would be the comfortable version.

Email tracking stores nothing in your browser either. Our marketing, follow-up and acknowledgement emails record opens with a tracking pixel. Clicks are recorded as links pass through links.synapsereality.io. Blocking remote images in your mail app stops the open record, and every commercial email has a one-click unsubscribe.

06 Changing your answer

Clear this site's cookies and storage in your browser. Every browser has it under a name like "delete cookies and site data", usually behind the padlock icon in the address bar. The banner comes back on your next visit and you can answer it again.

You can also block cookies for this site permanently in browser settings, or turn on tracking protection, and nothing here will break.

07 The exact list

We measured this list on 23 September 2026 by loading the live site in a clean browser, accepting the banner and browsing several pages. It shows what the site actually wrote, not what the vendors' documentation says they might write.

Every cookie and storage key, as measured
NameKindWritten byKept forNeeds consent
sy_consentCookieThis site. It records whether you accepted analytics.365 daysNo
synapse.consent.v1Local storageThis site. The same answer, so the banner stays closed.Until you clear itNo
sy_vidCookieThis site. A random visitor id, set only after you accept and then send a form or run the audit tool.397 daysYes
_clckCookieMicrosoft Clarity. Recognises a returning browser.365 daysYes
_clskCookieMicrosoft Clarity. Joins page views into one session.1 dayYes
_cltkSession storageMicrosoft Clarity. Tracks the current tab.Until the tab closesYes
cf_zaraz_clientCookieCloudflare Zaraz, which loads Google Analytics from our own domain. A random client id.365 daysYes
cfz_google-analytics_v4CookieCloudflare Zaraz, on behalf of Google Analytics. Recognises a returning browser.365 daysYes
cfzs_google-analytics_v4CookieCloudflare Zaraz, on behalf of Google Analytics. Joins page views into one visit.Until the browser closesYes

PostHog keeps its identity in memory only, so it writes no cookie and no storage. Google Analytics runs through Cloudflare Zaraz on this domain, so its cookies are set by synapsereality.io and none come from google.com.

Visitors in the EU, the EEA, the UK and Switzerland see the consent banner. Until they accept, nothing loads for them beyond our own server log and Cloudflare's cookieless page count. Accepting stores your answer in a cookie called sy_consent for a year, so we do not ask on every page.

Something looks wrong

If you find a cookie on this site that is not in this page, that is a bug in our build and we want to know. Tell us through the contact page, or use the privacy contact inthe privacy policy.