This policy explains how Tonning, doing business as Synci ("we", "us"), uses cookies and similar technologies on synci.io and app.synci.io. It works together with our Privacy Policy, which describes how we handle personal data more broadly.
What cookies are
Cookies are small files placed on your device when you visit a website. We use first-party cookies (set by us) and a small number of third-party cookies (set by providers whose features we use). We do not use cookies for advertising networks, and we never sell data collected through cookies.
How consent works at Synci
We built our own consent system. Essential cookies are always on, because the Service cannot work without them. Everything else is off until you say yes.
You can change your choices at any time: through the cookie banner on the website, and under Settings in the app. Your choices are stored in a cookie on your device and, once you have an account, on our servers, so they follow you across devices and choices you make on the website carry over when you sign up.
Analytics also runs in a consent-independent mode: without your consent, we collect only anonymous, cookieless usage events that store nothing on your device and cannot be tied to you. Because this mode uses no cookies, it is not listed in the tables below; it is described in section 6 of our Privacy Policy, and you can object by contacting us.
The cookies we use
Essential
Strictly necessary for the Service to function. These cannot be switched off.
| Name | Purpose | Provider | Expires |
|---|---|---|---|
| XSRF-TOKEN | Site security, prevents cross-site request forgery attacks | .synci.io | 2 hours |
| synci_session | Maintains your session during sign-in, consent, and account flows | .synci.io | 2 hours |
| __Host-synci_bff | Keeps you signed in to the app. Holds only a random reference to your encrypted sign-in tokens, which are stored on our servers and never in your browser | app.synci.io | Session, or 30 days with "remember me" |
| synci_oauth_tx | Secures the sign-in handshake against tampering. Deleted as soon as sign-in completes | app.synci.io | 10 minutes |
| synci_oauth_recovery | Prevents redirect loops when your session is re-established silently | app.synci.io | 2 minutes |
| bff_remember | Stores your "remember me" choice | app.synci.io | 30 days |
| remember_web_* | "Remember me" login functionality | .synci.io | 30 days |
| user | Your profile and subscription details, used to show the right pages without an extra server round trip. Readable by the app in your browser, so it is not encrypted; it never contains passwords or financial data | app.synci.io | Session, or 30 days with "remember me" |
| intended_redirect | Returns you to the page you asked for after signing in | app.synci.io | 1 hour |
| password_confirmed | Marks the short window after you re-enter your password for sensitive settings changes | app.synci.io | A few minutes |
| synci_cookie_consent | Stores your cookie consent choices | .synci.io | 1 year |
| cf_clearance | Cloudflare JavaScript detection, part of our bot and abuse protection | .synci.io | Varies |
| __cf_bm | Cloudflare bot management. Set when our providers' pages (for example the GoCardless consent flow) are protected by Cloudflare. Contains no user ID from our application | .synci.io / .gocardless.com | 30 minutes |
Functional
Enable optional features. Without them, the related feature is unavailable but the rest of the Service works.
| Name | Purpose | Provider | Expires |
|---|---|---|---|
| Google account cookies (SID, SAPISID, __Secure-3PSID, NID and similar) | Set by Google when you use the Google Sheets picker to select a spreadsheet. They confirm your Google sign-in so the picker can load your file list. Set by Google on its own domains, not by us. If your browser blocks third-party cookies, the picker may not load, and you can paste a spreadsheet link instead | google.com | Varies |
| featurebase-* | Feedback board and changelog widget: messaging, voting, and changelogs without a separate login. Anonymous IDs for guests | .synci.io (Featurebase) | Varies |
| sidebar_state | Remembers whether the app sidebar is open or collapsed | app.synci.io | 7 days |
Analytics (only with your consent)
| Name | Purpose | Provider | Expires |
|---|---|---|---|
| ph_*_posthog | Product analytics: daily active users, page views, feature usage, heatmaps, error tracking, and session replays in which all text is masked so your financial data never appears. Data is stored exclusively in the EU (Germany, AWS eu-central-1) with IP anonymization | .synci.io (PostHog EU Cloud) | 12 months |
If you withdraw analytics consent, we stop identified tracking and unlink your identity from future events.
Marketing
We currently use no marketing cookies. We measure whether our ad campaigns work by importing aggregate campaign statistics (impressions, clicks, spend) from the ad platforms we advertise on, currently Reddit Ads, into our analytics. That data is about our campaigns, not about you, and no data about you is sent to any ad platform. Attribution of signups to campaigns happens inside our analytics using the link parameters you arrive with, under the analytics consent above. If we ever introduce marketing cookies, they will appear in this table and require your consent first.
We run no third-party advertising on the Service.
Email tracking
Some of the emails we send include standard delivery and open tracking provided by our email providers, so we can tell whether important messages (like billing notices) arrive. Unsubscribe links in product update emails always work regardless of your cookie choices.
Managing cookies in your browser
You can also control cookies through your browser settings, including deleting existing cookies and blocking new ones. Note that blocking essential cookies will prevent the Service from working, since login sessions depend on them. Consult your browser's help pages for instructions.
Changes to this policy
We update this policy when the cookies we use change. The date at the top always reflects the current version, and the tables above are reviewed as part of our regular compliance review.
Contact
Questions about cookies or this policy: support@synci.io
Tonning (Synci), Nordbø 15, 5009 Bergen, Norway