Last updated July 21, 2026

Cookie Policy

On this page

This policy explains how Tonning, doing business as Synci ("we", "us"), uses cookies and similar technologies on synci.io and app.synci.io. It works together with our Privacy Policy, which describes how we handle personal data more broadly.

What cookies are

Cookies are small files placed on your device when you visit a website. We use first-party cookies (set by us) and a small number of third-party cookies (set by providers whose features we use). We do not use cookies for advertising networks, and we never sell data collected through cookies.

We built our own consent system. Essential cookies are always on, because the Service cannot work without them. Everything else is off until you say yes.

You can change your choices at any time: through the cookie banner on the website, and under Settings in the app. Your choices are stored in a cookie on your device and, once you have an account, on our servers, so they follow you across devices and choices you make on the website carry over when you sign up.

Analytics also runs in a consent-independent mode: without your consent, we collect only anonymous, cookieless usage events that store nothing on your device and cannot be tied to you. Because this mode uses no cookies, it is not listed in the tables below; it is described in section 6 of our Privacy Policy, and you can object by contacting us.

The cookies we use

Essential

Strictly necessary for the Service to function. These cannot be switched off.

NamePurposeProviderExpires
XSRF-TOKENSite security, prevents cross-site request forgery attacks.synci.io2 hours
synci_sessionMaintains your session during sign-in, consent, and account flows.synci.io2 hours
__Host-synci_bffKeeps you signed in to the app. Holds only a random reference to your encrypted sign-in tokens, which are stored on our servers and never in your browserapp.synci.ioSession, or 30 days with "remember me"
synci_oauth_txSecures the sign-in handshake against tampering. Deleted as soon as sign-in completesapp.synci.io10 minutes
synci_oauth_recoveryPrevents redirect loops when your session is re-established silentlyapp.synci.io2 minutes
bff_rememberStores your "remember me" choiceapp.synci.io30 days
remember_web_*"Remember me" login functionality.synci.io30 days
userYour profile and subscription details, used to show the right pages without an extra server round trip. Readable by the app in your browser, so it is not encrypted; it never contains passwords or financial dataapp.synci.ioSession, or 30 days with "remember me"
intended_redirectReturns you to the page you asked for after signing inapp.synci.io1 hour
password_confirmedMarks the short window after you re-enter your password for sensitive settings changesapp.synci.ioA few minutes
synci_cookie_consentStores your cookie consent choices.synci.io1 year
cf_clearanceCloudflare JavaScript detection, part of our bot and abuse protection.synci.ioVaries
__cf_bmCloudflare bot management. Set when our providers' pages (for example the GoCardless consent flow) are protected by Cloudflare. Contains no user ID from our application.synci.io / .gocardless.com30 minutes

Functional

Enable optional features. Without them, the related feature is unavailable but the rest of the Service works.

NamePurposeProviderExpires
Google account cookies (SID, SAPISID, __Secure-3PSID, NID and similar)Set by Google when you use the Google Sheets picker to select a spreadsheet. They confirm your Google sign-in so the picker can load your file list. Set by Google on its own domains, not by us. If your browser blocks third-party cookies, the picker may not load, and you can paste a spreadsheet link insteadgoogle.comVaries
featurebase-*Feedback board and changelog widget: messaging, voting, and changelogs without a separate login. Anonymous IDs for guests.synci.io (Featurebase)Varies
sidebar_stateRemembers whether the app sidebar is open or collapsedapp.synci.io7 days

Analytics (only with your consent)

NamePurposeProviderExpires
ph_*_posthogProduct analytics: daily active users, page views, feature usage, heatmaps, error tracking, and session replays in which all text is masked so your financial data never appears. Data is stored exclusively in the EU (Germany, AWS eu-central-1) with IP anonymization.synci.io (PostHog EU Cloud)12 months

If you withdraw analytics consent, we stop identified tracking and unlink your identity from future events.

Marketing

We currently use no marketing cookies. We measure whether our ad campaigns work by importing aggregate campaign statistics (impressions, clicks, spend) from the ad platforms we advertise on, currently Reddit Ads, into our analytics. That data is about our campaigns, not about you, and no data about you is sent to any ad platform. Attribution of signups to campaigns happens inside our analytics using the link parameters you arrive with, under the analytics consent above. If we ever introduce marketing cookies, they will appear in this table and require your consent first.

We run no third-party advertising on the Service.

Email tracking

Some of the emails we send include standard delivery and open tracking provided by our email providers, so we can tell whether important messages (like billing notices) arrive. Unsubscribe links in product update emails always work regardless of your cookie choices.

Managing cookies in your browser

You can also control cookies through your browser settings, including deleting existing cookies and blocking new ones. Note that blocking essential cookies will prevent the Service from working, since login sessions depend on them. Consult your browser's help pages for instructions.

Changes to this policy

We update this policy when the cookies we use change. The date at the top always reflects the current version, and the tables above are reviewed as part of our regular compliance review.

Contact

Questions about cookies or this policy: support@synci.io

Tonning (Synci), Nordbø 15, 5009 Bergen, Norway