// LEGAL / COOKIE_POLICY
// COOKIE_POLICY
Effective 26 July 2026. No advertising or cross-site tracking.
1. Current policy
Syphio uses cookies only where they are required for sign-in, security and authenticated workspace state. It does not currently use advertising cookies, cross-site tracking or a consent-based marketing tracker. For that reason, Syphio does not display a consent banner that would have no settings to control.
2. Strictly necessary cookies
better-auth.session_token
Keeps an authenticated session active. Duration: 30 days
better-auth OAuth state and verification cookies
Protects short-lived sign-in and callback flows. Duration: Short-lived; magic-link verification expires after 10 minutes.
syphio_active_workspace
Remembers the active workspace inside the authenticated app. Duration: 1 year
Production security prefixes or short-lived cookie variants may alter the exact name shown by your browser without changing the purpose described above.
3. Cookieless public telemetry
Vercel Web Analytics and Speed Insights measure aggregate public page use and performance without setting an analytics cookie. Syphio blocks these events on login, authentication, authenticated application, unsubscribe and public-report routes so identifiers and report URLs are not sent through this telemetry.
Telemetry is used only to understand public page performance and navigation. It is not used for advertising or cross-site profiles.
4. Browser controls
You can inspect, delete or block cookies in your browser. Blocking strictly necessary cookies may prevent sign-in or workspace selection from working. Because current public telemetry is cookieless, deleting cookies does not change that telemetry.
5. Changes and contact
If Syphio introduces a non-essential tracker, it will update this policy and obtain consent before activation where required.
Questions: contact@syphio.io. See the Privacy Policy for processing purposes, recipients, retention and your rights.